Bidda Sovereign Intelligence · 10,108 Verified Nodes · 39 Sovereign Pillars

Spain ENS - Real Decreto 311/2022 Esquema Nacional de Seguridad (National Security Scheme)

Real Decreto 311/2022, de 3 de mayo, regulates the Esquema Nacional de Seguridad (ENS), the Spanish National Security Scheme established in Article 156.2…

What Spain ENS - Real Decreto 311/2022 Esquema Nacional de Seguridad (National Security Scheme) requires

Real Decreto 311/2022, de 3 de mayo, regulates the Esquema Nacional de Seguridad (ENS), the Spanish National Security Scheme established in Article 156.2 of Ley 40/2015, and lays down the principios basicos y requisitos minimos (basic principles and minimum requirements) for the protection of information and services handled by public sector information systems. Published in BOE numero 106 of 4 May 2022 and in force from 5 May 2022, the ENS applies to the entire Spanish public sector as defined in Article 2 of Ley 40/2015 and also applies to the information systems of private sector entities when they provide services to public entities for the exercise of their administrative competences and powers; contracts with such suppliers must include all requirements necessary to ensure conformity with the ENS. Article 5 sets seven basic principles: seguridad como proceso integral (security as an integral process); gestion de la seguridad basada en los riesgos (risk-based security management); prevencion, deteccion, respuesta y conservacion (prevention, detection, response and preservation); existencia de lineas de defensa (existence of lines of defence); vigilancia continua (continuous monitoring); reevaluacion periodica (periodic re-evaluation); and diferenciacion de responsabilidades (differentiation of responsibilities). Systems are categorized under Article 40 and Annex I into the categories BASICA, MEDIA and ALTA based on the impact of security incidents on the organization objectives, assets and service continuity, and the security measures of Annex II are organized into the marco organizativo (organizational framework), marco operacional (operational framework) and medidas de proteccion (protection measures). Under Article 38, systems in categories MEDIA and ALTA require an audit for certification of conformity, while BASICA systems require a self-assessment for the declaration of conformity, and conformity declarations and certifications must be published. ENS conformity has become the gate for supplying cloud and IT services to Spanish public administrations.

Pillar: Cybersecurity · Authority: Gobierno de Espana; Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad, BOE numero 106 de 4 de mayo de 2022 (BOE-A-2022-7191), in force 5 May 2022; established under articulo 156.2 de la Ley 40/2015; supervised by the Centro Criptologico Nacional (CCN) · Version: 1.0.0 · Last updated:

Primary source: https://www.boe.es/buscar/act.php?id=BOE-A-2022-7191

SHA-256 integrity: b90d534ea6fac036f5d27e1a9d8978df57fc3a6da7649ea1e5bb1c2611b91eb8

Primary Citations — 6 traced to source

  • Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad, BOE numero 106 de 4 de mayo de 2022, referencia BOE-A-2022-7191, at https://www.boe.es/buscar/act.php?id=BOE-A-2022-7191, in force 5 May 2022; Articulo 1 (objeto: regulates the ENS established in articulo 156.2 de la Ley 40/2015 and sets the principios basicos y requisitos minimos)
  • Real Decreto 311/2022, Articulo 2 (ambito de aplicacion): applies to the whole public sector and to los sistemas de informacion de las entidades del sector privado when they provide services to public entities for the exercise of administrative competences and powers; contracts must include todos aquellos requisitos necesarios para asegurar la conformidad con el ENS

+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.