Our own servers in Europe · GDPR · Support in your language

Module 3 of 5 · ENS · Block 3

Operational framework

The operational framework covers how the system is planned, run, and controlled day to day to maintain security.

Content reviewed on

Security planning

Risk analysis, security architecture, and personnel management as part of system planning.

Access control

Identity management, authentication, and segregation of duties for access to system resources.

Service continuity

Availability measures and continuity plans for incidents affecting the service.

What an auditor usually asks for

  • System security plan documented
  • Access control policy implemented
  • Access provisioning and deprovisioning log
  • Service continuity plan available

How to cover this block in Kimobox

  1. 1Log the security plan and access policy in Kimobox.
  2. 2Manage role-based permissions from the employee portal.
  3. 3Document the continuity plan as a version-controlled record.

Role-based permissions and access control are managed from the same portal, with full traceability.

See Kimobox's technology architecture

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Royal Decree 311/2022 regulating the National Security Framework BOE-A-2022-7191 · 4 May 2022
  2. National Cryptologic Centre — CCN-STIC guides CCN-CERT · ENS guide series
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024