Security planning
Risk analysis, security architecture, and personnel management as part of system planning.
Access control
Identity management, authentication, and segregation of duties for access to system resources.
Service continuity
Availability measures and continuity plans for incidents affecting the service.
What an auditor usually asks for
- System security plan documented
- Access control policy implemented
- Access provisioning and deprovisioning log
- Service continuity plan available
How to cover this block in Kimobox
- 1Log the security plan and access policy in Kimobox.
- 2Manage role-based permissions from the employee portal.
- 3Document the continuity plan as a version-controlled record.
Role-based permissions and access control are managed from the same portal, with full traceability.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Royal Decree 311/2022 regulating the National Security Framework BOE-A-2022-7191 · 4 May 2022
- National Cryptologic Centre — CCN-STIC guides CCN-CERT · ENS guide series
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024