Our own servers in Europe · GDPR · Support in your language

Module 2 of 5 · ENS · Block 2

Organizational framework

The organizational framework is the set of four documents that govern the organization's security: the policy leadership approves, the regulations that make it concrete, the procedures that carry it into daily work, and the process that authorizes whatever goes into service.

Content reviewed on

The four required measures

Annex II of Royal Decree 311/2022 groups four measures under the organizational framework: security policy (org.1), security regulations (org.2), security procedures (org.3) and authorization process (org.4).

Unlike most ENS measures, these four do not scale with the level: they apply equally to basic, medium and high categories. That makes this the first block worth closing, and the one an auditor assumes is already in place before moving on to anything technical.

Security policy

This is the document everything else hangs from, and the only one whose minimum content the royal decree sets out itself: article 12, «Security policy and minimum security requirements», lists what cannot be missing.

Those minimums are the organization's objectives or mission, the regulatory framework its activities operate under, the security roles or functions with each one's duties and responsibilities, the structure and composition of the committee or committees that manage and coordinate security, the guidelines for structuring the system's security documentation, and the risks arising from the processing of personal data.

Two points account for most audit findings. First, approval: a policy with no record of who approved it and when does not evidence the leadership backing the ENS assumes it has. Second, roles: the royal decree devotes a separate article to the differentiation of responsibilities, so naming one person for everything is precisely what it sets out to prevent.

Security regulations

The regulations bring the policy down to the specific matters people actually ask about: use of equipment and email, remote access, mobile and personal devices, removable media, passwords, remote work.

The difference from a procedure is the difference between a rule and an instruction: regulations say what is allowed, what is not and what happens if someone breaks them; a procedure says how the work is done and who does it. Blurring the two produces long documents nobody applies, and it is a common source of findings.

Security procedures

Procedures describe security activities step by step: who takes part, in what order, which record provides the evidence, and who it escalates to when something departs from the plan.

The test for which ones you need is a practical one: if a security task recurs and its outcome has to be demonstrable — granting and revoking user accounts, incident handling, backups and their restoration, disposal of media — it needs a written procedure, and the team's habits are not enough.

Authorization process

The last measure in the block closes the way in: nothing joins the system without prior, traceable authorization. It covers facilities, equipment and applications entering production, information media, communication links, and services contracted from third parties.

What turns this measure into something more than paperwork is writing down who authorizes what, and on what grounds. If authorization is a stray email, the evidence is lost; if it is a workflow with an owner, a criterion and a record, that authorization can still be audited years later.

What an auditor usually asks for

  • Security policy approved by leadership, dated and with a record of the approval
  • All six minimum contents of article 12 covered in the policy
  • Security committee constituted, with its composition and duties in writing
  • Security roles assigned to different people, with duties and responsibilities
  • Security regulations documented, circulated and with evidence they were communicated
  • Written security procedures for the activities that have to be demonstrable
  • Authorization process active for facilities, equipment, applications, media and third-party services

How to cover this block in Kimobox

  1. 1Document the security policy and regulations as controlled documents.
  2. 2Log the component authorization process as an approval workflow in Kimobox.
  3. 3Communicate the regulations to all involved staff from the employee portal.

The security policy and regulations stay version-controlled with evidence they were communicated to the team.

See Kimobox's document control

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Royal Decree 311/2022 regulating the National Security Framework BOE-A-2022-7191 · 4 May 2022
  2. National Cryptologic Centre — CCN-STIC guides CCN-CERT · ENS guide series
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024