---
title: "The National Security Scheme (ENS) and the Onesait Platform"
canonical: "https://onesaitplatform.refined.site/space/DOCT/3630268427/The%20National%20Security%20Scheme%20(ENS)%20and%20the%20Onesait%20Platform"
format: markdown
---
> Macro (toc)

# Introduction

The purpose of Spain’s National Security Scheme (hereinafter ENS after the acronym in Spanish) is the creation of **measures to guarantee the security of systems, data, communications, and electronic services.**

In this context, network and information security is understood as the ability of networks or information systems to resist, with a certain level of confidence, accidents and illicit or malicious actions that compromise the availability, authenticity, integrity and confidentiality of the data, either stored or transmitted, and of the services that said networks and systems offer or make accessible.

To comply with the foregoing, the **security dimensions and their levels, the category of the systems, the appropriate security measures and the periodic security audit **are determined.

# System Categories

## Dimensions

The determination of the category of a system is based on the assessment of the impact that an incident affecting the security of the information or systems would have on the organization.

In order to be able to determine the impact that an incident affecting the security of information or systems would have on the organization, and to be able to establish the category of the system, the following dimensions of security will be taken into account, which will be identified by their corresponding initials in capital letters in Spanish:

- **Disponibilidad – Availability**
- **Autenticidad – Authenticity**
- **Integridad – Integrity**
- **Confidencialidad – Confidentiality**
- **Trazabilidad – Traceability**

## Levels of a security dimension

Information or services may be affected in one or more of its security dimensions. Each security dimension affected will be assigned to one of the following levels: **LOW, MEDIUM or HIGH**. If a security dimension is not affected, it will not be assigned to any level.

- **LOW level: **it will be used when the consequences of a security incident that affects any of the security dimensions entail a **limited damage **on the functions of the organization, on its assets or on the affected individuals.
- **MEDIUM level: **it will be used when the consequences of a security incident that affects any of the security dimensions entail **serious damage **to the organization’s functions, on its assets or on the affected individuals.
- **HIGH level: **it will be used when the consequences of a security incident that affects any of the security dimensions entail a **very serious damage **on the functions of the organization, on its assets or on the affected individuals.

| **Limited damage** | **Serious damage** | **Very serious damage** |
| --- | --- | --- |
| - The appreciable reduction in the organization’s capacity to effectively meet its current obligations, even though it continues to perform them.<br>- Suffering minor damage to the organization’s assets.<br>- The formal breach of any law or regulation, which is rectifiable.<br>- Causing minor damage to some individual, which, even being annoying, can be easily repaired.<br>-Others of a similar nature. | The significant reduction in the organization’s ability to effectively meet its fundamental obligations, even though it continues to perform them.<br>- Suffering significant harm to the organization’s assets.<br>- Material non-compliance with any law or regulation, or formal non-compliance that is not rectifiable.<br>- Cause significant damage to an individual, which is difficult to repair.<br>-Others of a similar nature. | The annulment of the capacity of the organization to attend to any of its fundamental obligations and that these can continue to be performed.<br>- Suffering of very serious, and even irreparable, damage to the assets of the organization.<br>- Serious breach of any law or regulation.<br>- Causing serious damage to an individual, which is difficult or impossible to repair.<br>-Others of a similar nature. |

When **a system handles different information and provides different services, the level of the system in each dimension will be the highest of those established **for each information and each service.

## Category of an Information System

Three categories are defined: BASIC, MEDIUM and HIGH.

- An information system will be **of HIGH category if any of its security dimensions reaches the HIGH level.**
- An information system will be **of MEDIUM category if any of its security dimensions reaches the MEDIUM level,** and none reaches a higher level.
- An information system will be **of BASIC category if any of its security dimensions reaches the LOW level,** and none reaches a higher level.

# Security measures

## Measurement Frameworks

Security measures are divided into three groups:

- **Organizational framework [org]: **made up by the set of measures related to the global organization of security.
- **Operational framework [op]: **made up by the measures to be taken to protect the operation of the system as an integral set of components for a given purpose.
- **Protection measures [mp]: **they focus on protecting specific assets, according to their nature and the quality required by the security level of the affected dimensions.

## Selection of security measures

For the selection of security measures, the following steps will be followed:

1. Identification of the types of assets present.
2. Determination of relevant security dimensions.
3. Determination of the level corresponding to each security dimension.
4. Determination of the category of the system.
5. Selection of the appropriate security measures from among those contained in the following point.

The list of selected measures will be formalized in a document called Declaration of Applicability, signed by the person responsible for system security.

## Table of Security Policies

The correspondence between the security levels required in each dimension and the security measures is specified in the following table (Links lead to information in Spanish):

|  |  |
| --- | --- |
| **DIMENSIONS** | **SECURITY MEASURES** |
| **AFFECTED** | **L (LOW)** | **M (MEDIUM)** | **H (HIGH)** | <span style="color: #ffffff">**org**</span> | <span style="color: #ffffff">**Organizational framework**</span> |
| category | applies | = | = | <u>[[org.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1075.htm#org.1)</u> | Security policy |
| category | applies | = | = | <u>[[org.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1076.htm#org.2)</u> | Safety regulations |
| category | applies | = | = | <u>[[org.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1077.htm#org.3)</u> | Security procedures |
| category | applies | = | = | <u>[[org.4]](https://www.ccn-cert.cni.es/publico/ens/ens/1078.htm#org.4)</u> | Authorization process |

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
|  |  |  |  | <span style="color: #ffffff">**op**</span> | <span style="color: #ffffff">**Operational framework**</span> |
|  |  |  |  | <u>[[op.pl]](https://www.ccn-cert.cni.es/publico/ens/ens/1080.htm#op.pl)</u> | **Planning** |
| category | applies | + | ++ | <u>[[op.pl.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1081.htm#op.pl.1)</u> | Risk analysis |
| category | applies | + | ++ | <u>[[op.pl.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1082.htm#op.pl.2)</u> | Architecture of security |
| category | applies | = | = | <u>[[op.pl.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1083.htm#op.pl.3)</u> | Acquisition of new components |
| D | n.a. | applies | = | <u>[[op.pl.4]](https://www.ccn-cert.cni.es/publico/ens/ens/1084.htm#op.pl.4)</u> | Sizing / Capacity management |
| category | n.a. | n.a. | applies | <u>[[op.pl.5]](https://www.ccn-cert.cni.es/publico/ens/ens/1085.htm#op.pl.5)</u> | Certified components |
|  |  |  |  | <u>[[op.acc]](https://www.ccn-cert.cni.es/publico/ens/ens/1086.htm#op.acc)</u> | **Access control** |
| A T | applies | = | = | <u>[[op.acc.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1087.htm#op.acc.1)</u> | Identification |
| I C A T | applies | = | = | <u>[[op.acc.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1088.htm#op.acc.2)</u> | Access requirements |
| I C A T | n.a. | applies | = | <u>[[op.acc.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1089.htm#op.acc.3)</u> | Segregation of duties and tasks |
| I C A T | applies | = | = | <u>[[op.acc.4]](https://www.ccn-cert.cni.es/publico/ens/ens/1090.htm#op.acc.4)</u> | Access rights management process |
| I C A T | applies | + | ++ | <u>[[op.acc.5]](https://www.ccn-cert.cni.es/publico/ens/ens/1091.htm#op.acc.5)</u> | Authentication mechanism |
| I C A T | applies | + | ++ | <u>[[op.acc.6]](https://www.ccn-cert.cni.es/publico/ens/ens/1092.htm#op.acc.6)</u> | Local login |
| I C A T | applies | + | = | <u>[[op.acc.7]](https://www.ccn-cert.cni.es/publico/ens/ens/1093.htm#op.acc.7)</u> | Remote login |
|  |  |  |  | <u>[[op.exp]](https://www.ccn-cert.cni.es/publico/ens/ens/1094.htm#op.exp)</u> | **Exploitation** |
| category | applies | = | = | <u>[[op.exp.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1095.htm#op.exp.1)</u> | Inventory of assets |
| category | applies | = | = | <u>[[op.exp.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1096.htm#op.exp.2)</u> | Security configuration |
| category | n.a. | applies | = | <u>[[op.exp.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1097.htm#op.exp.3)</u> | Configuration management |
| category | applies | = | = | <u>[[op.exp.4]](https://www.ccn-cert.cni.es/publico/ens/ens/1098.htm#op.exp.4)</u> | Maintenance |
| category | n.a. | applies | = | <u>[[op.exp.5]](https://www.ccn-cert.cni.es/publico/ens/ens/1099.htm#op.exp.5)</u> | Change management |
| category | applies | = | = | <u>[[op.exp.6]](https://www.ccn-cert.cni.es/publico/ens/ens/1100.htm#op.exp.6)</u> | Protection against malicious code |
| category | n.a. | applies | = | <u>[[op.exp.7]](https://www.ccn-cert.cni.es/publico/ens/ens/1101.htm#op.exp.7)</u> | Incident management |
| T | applies | + | ++ | <u>[[op.exp.8]](https://www.ccn-cert.cni.es/publico/ens/ens/1102.htm#op.exp.8)</u> | User activity log |
| category | n.a. | applies | = | <u>[[op.exp.9]](https://www.ccn-cert.cni.es/publico/ens/ens/1103.htm#op.exp.9)</u> | Incident management log |
| T | n.a. | n.a. | applies | <u>[[op.exp.10]](https://www.ccn-cert.cni.es/publico/ens/ens/1104.htm#op.exp.10)</u> | Protection of activity logs |
| category | applies | + | = | <u>[[op.exp.11]](https://www.ccn-cert.cni.es/publico/ens/ens/1105.htm#op.exp.11)</u> | Protection of cryptographic keys |
|  |  |  |  | <u>[[op.ext]](https://www.ccn-cert.cni.es/publico/ens/ens/1106.htm#op.ext)</u> | **External services** |
| category | n.a. | applies | = | <u>[[op.ext.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1107.htm#op.ext.1)</u> | Hiring and service level agreements |
| category | n.a. | applies | = | <u>[[op.ext.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1108.htm#op.ext.2)</u> | Daily management |
| D | n.a. | n.a. | applies | <u>[[op.ext.9]](https://www.ccn-cert.cni.es/publico/ens/ens/1109.htm#op.ext.9)</u> | Alternative means |
|  |  |  |  | <u>[[op.cont]](https://www.ccn-cert.cni.es/publico/ens/ens/1110.htm#op.cont)</u> | **Service continuity** |
| D | n.a. | applies | = | <u>[[op.cont.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1111.htm#op.cont.1)</u> | Impact analysis |
| D | n.a. | n.a. | applies | <u>[[op.cont.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1112.htm#op.cont.2)</u> | Continuity plan |
| D | n.a. | n.a. | applies | <u>[[op.cont.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1113.htm#op.cont.3)</u> | Periodic tests |
|  |  |  |  | <u>[[op.mon]](https://www.ccn-cert.cni.es/publico/ens/ens/1114.htm#op.mon)</u> | **System monitoring** |
| category | n.a. | applies | = | <u>[[op.mon.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1115.htm#op.mon.1)</u> | Intrusion detection |
| category | applies | + | ++ | <u>[[op.mon.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1116.htm#op.mon.2)</u> | Metrics system |

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
|  |  |  |  | <span style="color: #ffffff">**mp**</span> | <span style="color: #ffffff">**Protection measures**</span> |
|  |  |  |  | <u>[[mp.if]](https://www.ccn-cert.cni.es/publico/ens/ens/1118.htm#mp.if)</u> | **Protection of installations and infrastructures** |
| category | applies | = | = | <u>[[mp.if.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1119.htm#mp.if.1)</u> | Separate areas with access control |
| category | applies | = | = | <u>[[mp.if.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1120.htm#mp.if.2)</u> | Identification of people |
| category | applies | = | = | <u>[[mp.if.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1121.htm#mp.if.3)</u> | Conditioning of the premises |
| D | applies | + | = | <u>[[mp.if.4]](https://www.ccn-cert.cni.es/publico/ens/ens/1122.htm#mp.if.4)</u> | Electrical energy |
| D | applies | = | = | <u>[[mp.if.5]](https://www.ccn-cert.cni.es/publico/ens/ens/1123.htm#mp.if.5)</u> | Fire protection |
| D | n.a. | applies | = | <u>[[mp.if.6]](https://www.ccn-cert.cni.es/publico/ens/ens/1124.htm#mp.if.6)</u> | Protection against floods |
| category | applies | = | = | <u>[[mp.if.7]](https://www.ccn-cert.cni.es/publico/ens/ens/1125.htm#mp.if.7)</u> | Equipment entry and exit registration |
| D | n.a. | n.a. | applies | <u>[[mp.if.9]](https://www.ccn-cert.cni.es/publico/ens/ens/1126.htm#mp.if.9)</u> | Alternative installations |
|  |  |  |  | <u>[[mp.per]](https://www.ccn-cert.cni.es/publico/ens/ens/1127.htm#mp.per)</u> | **Personnel management** |
| category | n.a. | applies | = | <u>[[mp.per.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1128.htm#mp.per.1)</u> | Job description |
| category | applies | = | = | <u>[[mp.per.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1129.htm#mp.per.2)</u> | Duties and obligations |
| category | applies | = | = | <u>[[mp.per.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1130.htm#mp.per.3)</u> | Awareness |
| category | applies | = | = | <u>[[mp.per.4]](https://www.ccn-cert.cni.es/publico/ens/ens/1131.htm#mp.per.4)</u> | Training |
| D | n.a. | n.a. | applies | <u>[[mp.per.9]](https://www.ccn-cert.cni.es/publico/ens/ens/1132.htm#mp.per.9)</u> | Alternate staff |
|  |  |  |  | <u>[[mp.eq]](https://www.ccn-cert.cni.es/publico/ens/ens/1133.htm#mp.eq)</u> | **Protection of equipment** |
| category | applies | + | = | <u>[[mp.eq.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1134.htm#mp.eq.1)</u> | Job station clearing |
| A | n.a. | applies | + | <u>[[mp.eq.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1135.htm#mp.eq.2)</u> | Job station blocking |
| category | applies | = | + | <u>[[mp.eq.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1136.htm#mp.eq.3)</u> | Protection of portable devices |
| D | n.a. | applies | = | <u>[[mp.eq.9]](https://www.ccn-cert.cni.es/publico/ens/ens/1137.htm#mp.eq.9)</u> | Alternative means |
|  |  |  |  | <u>[[mp.com]](https://www.ccn-cert.cni.es/publico/ens/ens/1138.htm#mp.com)</u> | **Protection of communications** |
| category | applies | = | + | <u>[[mp.com.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1139.htm#mp.com.1)</u> | Secure perimeter |
| C | n.a. | applies | + | <u>[[mp.com.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1140.htm#mp.com.2)</u> | Confidentiality protection |
| I A | applies | + | ++ | <u>[[mp.com.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1141.htm#mp.com.3)</u> | Authenticity and integrity protection |
| category | n.a. | n.a. | applies | <u>[[mp.com.4]](https://www.ccn-cert.cni.es/publico/ens/ens/1142.htm#mp.com.4)</u> | Network segregation |
| D | n.a. | n.a. | applies | <u>[[mp.com.9]](https://www.ccn-cert.cni.es/publico/ens/ens/1143.htm#mp.com.9)</u> | Alternative means |
|  |  |  |  | <u>[[mp.si]](https://www.ccn-cert.cni.es/publico/ens/ens/1144.htm#mp.si)</u> | **Protection of information carriers** |
| C | applies | = | = | <u>[[mp.si.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1145.htm#mp.si.1)</u> | Labelling |
| I C | n.a. | applies | + | <u>[[mp.si.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1146.htm#mp.si.2)</u> | Cryptography |
| category | applies | = | = | <u>[[mp.si.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1147.htm#mp.si.3)</u> | Custody |
| category | applies | = | = | <u>[[mp.si.4]](https://www.ccn-cert.cni.es/publico/ens/ens/1148.htm#mp.si.4)</u> | Transportation |
| C | applies | + | = | <u>[[mp.si.5]](https://www.ccn-cert.cni.es/publico/ens/ens/1149.htm#mp.si.5)</u> | Deletion and destruction |
|  |  |  |  | <u>[[mp.sw]](https://www.ccn-cert.cni.es/publico/ens/ens/1150.htm#mp.sw)</u> | **Protection of software** |
| category | n.a. | applies | = | <u>[[mp.sw.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1151.htm#mp.sw.1)</u> | Development |
| category | applies | + | ++ | <u>[[mp.sw.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1152.htm#mp.sw.2)</u> | Acceptance and commissioning |
|  |  |  |  | <u>[[mp.info]](https://www.ccn-cert.cni.es/publico/ens/ens/1153.htm#mp.info)</u> | **Protection of Information** |
| category | applies | = | = | <u>[[mp.info.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1154.htm#mp.info.1)</u> | Personal data |
| C | applies | + | = | <u>[[mp.info.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1155.htm#mp.info.2)</u> | Information rating |
| C | n.a. | n.a. | applies | <u>[[mp.info.3]](https://www.ccn-cert.cni.es/publico/ens/ens/1156.htm#mp.info.3)</u> | Encryption |
| I A | applies | + | ++ | <u>[[mp.info.4]](https://www.ccn-cert.cni.es/publico/ens/ens/1157.htm#mp.info.4)</u> | Electronic signature |
| T | n.a. | n.a. | applies | <u>[[mp.info.5]](https://www.ccn-cert.cni.es/publico/ens/ens/1158.htm#mp.info.5)</u> | Time stamps |
| C | applies | = | = | <u>[[mp.info.6]](https://www.ccn-cert.cni.es/publico/ens/ens/1159.htm#mp.info.6)</u> | Document cleanup |
| D | applies | = | = | <u>[[mp.info.9]](https://www.ccn-cert.cni.es/publico/ens/ens/1160.htm#mp.info.9)</u> | Backup copies |
|  |  |  |  | <u>[[mp.s]](https://www.ccn-cert.cni.es/publico/ens/ens/1161.htm#mp.s)</u> | **Protection of services** |
| category | applies | = | = | <u>[[mp.s.1]](https://www.ccn-cert.cni.es/publico/ens/ens/1162.htm#mp.s.1)</u> | Protection of e-mail |
| category | applies | = | + | <u>[[mp.s.2]](https://www.ccn-cert.cni.es/publico/ens/ens/1163.htm#mp.s.2)</u> | Protection of services and web applications |
| D | n.a. | applies | + | <u>[[mp.s.8]](https://www.ccn-cert.cni.es/publico/ens/ens/1164.htm#mp.s.8)</u> | Protection against denial of service |
| D | n.a. | n.a. | applies | <u>[[mp.s.9]](https://www.ccn-cert.cni.es/publico/ens/ens/1165.htm#mp.s.9)</u> | Alternative means |

Where the following conventions are used:

- Color code:
  - **Green color specifies that a certain measure is applied in systems of BASIC category or higher.**
  - **Yellow to indicate the measures that are beginning to be applied in the MEDIUM category or higher.**
  - **Pink to indicate the measures that are only applicable in the HIGH category.**
- To indicate that a given security measure must be applied to one or more security dimensions at a given level, the term 'applies' is used.
- ‘n.a.' means 'not applicable’.
- To indicate that the requirements of a level are equal to those of the lower level, the **== **sign is used.
- To indicate the increase in requirements graduated according to the level of the security dimension, the signs **“+”** and **“++”** are used.
- To indicate that a measure specifically protects a certain security dimension, it is made explicit by its initial in Spanish **(Availability/Disponibilidad [D], Authenticity/Autenticidad [A], Integrity/Integridad [I], Confidentiality/Confidencialidad [C] and Traceability/Trazabilidad [T]).**

# Security Audit

The audit levels that are carried out on the information systems will be as follows:

## Audit of BASIC category systems

BASIC category information systems, or lower, **will not need to perform an audit**. A self-assessment carried out by the same personnel that manages the information system, or whomever she delegates, will suffice.

The result of the self-assessment must be documented, indicating whether each security measure is implemented and subject to regular review and the evidence that supports the previous assessment.

The self-assessment reports will be analyzed by the competent security manager, who will submit the conclusions to the person in charge of the system so that the appropriate corrective measures can be taken.

## Audit of MEDIUM OR HIGH category systems.

The audit report will rule on the degree of compliance with the ENS,** identify its deficiencies and suggest the possible corrective or complementary measures that are necessary, as well as the recommendations that are considered appropriate.**

It must also include the methodological audit criteria used, the scope and objective of the audit, and the data, facts and observations on which the conclusions drawn are based.

The audit reports will be analyzed by the competent security manager, who will then present her conclusions to the system manager so that the appropriate corrective measures can be taken.

# Compliance with the ENS on the Platform

In this entry you can see how the Platform complies with ENS: [https://onesaitplatform.atlassian.net/wiki/spaces/DOCT/pages/3630268620](https://onesaitplatform.atlassian.net/wiki/spaces/DOCT/pages/3630268620).

# Glossary

- **Activo.** Componente o funcionalidad de un sistema de información susceptible de ser atacado deliberada o accidentalmente con consecuencias para la organización. Incluye: información, datos, servicios, aplicaciones (software), equipos (hardware), comunicaciones, recursos administrativos, recursos físicos y recursos humanos.
- **Análisis de riesgos. **Utilización sistemática de la información disponible para identificar peligros y estimar los riesgos.
- **Auditoría de la seguridad. **Revisión y examen independientes de los registros y actividades del sistema para verificar la idoneidad de los controles del sistema, asegurar que se cumplen la política de seguridad y los procedimientos operativos establecidos, detectar las infracciones de la seguridad y recomendar modificaciones apropiadas de los controles, de la política y de los procedimientos.
- **Autenticidad. **Propiedad o característica consistente en que una entidad es quien dice ser o bien que garantiza la fuente de la que proceden los datos.
- **Categoría de un sistema. **Es un nivel, dentro de la escala Básica-Media-Alta, con el que se adjetiva un sistema a fin de seleccionar las medidas de seguridad necesarias para el mismo. La categoría del sistema recoge la visión holística del conjunto de activos como un todo armónico, orientado a la prestación de unos servicios.
- **Confidencialidad. **Propiedad o característica consistente en que la información ni se pone a disposición, ni se revela a individuos, entidades o procesos no autorizados.
- **Disponibilidad. **Propiedad o característica de los activos consistente en que las entidades o procesos autorizados tienen acceso a los mismos cuando lo requieren.
- **Firma electrónica. **Conjunto de datos en forma electrónica, consignados junto a otros o asociados con ellos, que pueden ser utilizados como medio de identificación del firmante.
- **Gestión de incidentes. **Plan de acción para atender a los incidentes que se den. Además de resolverlos debe incorporar medidas de desempeño que permitan conocer la calidad del sistema de protección y detectar tendencias antes de que se conviertan en grandes problemas.
- **Gestión de riesgos. **Actividades coordinadas para dirigir y controlar una organización con respecto a los riesgos.
- **Incidente de seguridad. **Suceso inesperado o no deseado con consecuencias en detrimento de la seguridad del sistema de información.
- **Integridad. **Propiedad o característica consistente en que el activo de información no ha sido alterado de manera no autorizada.
- **Medidas de seguridad. **Conjunto de disposiciones encaminadas a protegerse de los riesgos posibles sobre el sistema de información, con el fin de asegurar sus objetivos de seguridad. Puede tratarse de medidas de prevención, de disuasión, de protección, de detección y reacción, o de recuperación.
- **Política de firma electrónica. **Conjunto de normas de seguridad, de organización, técnicas y legales para determinar cómo se generan, verifican y gestionan firmas electrónicas, incluyendo las características exigibles a los certificados de firma.
- **Política de seguridad. **Conjunto de directrices plasmadas en documento escrito, que rigen la forma en que una organización gestiona y protege la información y los servicios que considera críticos.
- **Principios básicos de seguridad. **Fundamentos que deben regir toda acción orientada a asegurar la información y los servicios.
- **Proceso. **Conjunto organizado de actividades que se llevan a cabo para producir a un producto o servicio; tiene un principio y fin delimitado, implica recursos y da lugar a un resultado.
- **Proceso de seguridad. **Método que se sigue para alcanzar los objetivos de seguridad de la organización. El proceso se diseña para identificar, medir, gestionar y mantener bajo control los riesgos a que se enfrenta el sistema en materia de seguridad.
- **Requisitos mínimos de seguridad. **Exigencias necesarias para asegurar la información y los servicios.
- **Riesgo.** Estimación del grado de exposición a que una amenaza se materialice sobre uno o más activos causando daños o perjuicios a la organización.
- **Seguridad de las redes y de la información. **Es la capacidad de las redes o de los sistemas de información de resistir, con un determinado nivel de confianza, los accidentes o acciones ilícitas o malintencionadas que comprometan la disponibilidad, autenticidad, integridad y confidencialidad de los datos almacenados o transmitidos y de los servicios que dichas redes y sistemas ofrecen o hacen accesibles.
- **Servicios acreditados. **Servicios prestados por un sistema con autorización concedida por la autoridad responsable, para tratar un tipo de información determinada, en unas condiciones precisas de las dimensiones de seguridad, con arreglo a su concepto de operación.
- **Sistema de gestión de la seguridad de la información (SGSI). **Sistema de gestión que, basado en el estudio de los riesgos, se establece para crear, implementar, hacer funcionar, supervisar, revisar, mantener y mejorar la seguridad de la información. El sistema de gestión incluye la estructura organizativa, las políticas, las actividades de planificación, las responsabilidades, las prácticas, los procedimientos, los procesos y los recursos.
- **Sistema de información. **Conjunto organizado de recursos para que la información se pueda recoger, almacenar, procesar o tratar, mantener, usar, compartir, distribuir, poner a disposición, presentar o transmitir.
- **Trazabilidad. **Propiedad o característica consistente en que las actuaciones de una entidad pueden ser imputadas exclusivamente a dicha entidad.
- **Vulnerabilidad. **Una debilidad que puede ser aprovechada por una amenaza.

[More information (in Spanish)](https://www.ccn-cert.cni.es/publico/ens/ens/index.html#!1001)