Our own servers in Europe · GDPR · Support in your language

Module 2 of 5 · ENS · Block 2

Organizational framework

The organizational framework is the set of documents that govern the organization's security, from policy down to operational procedures.

Content reviewed on

Security policy

A document approved by leadership that sets the organization's security objectives and responsibilities.

Security regulations

A set of rules that develop the policy for specific matters: equipment use, remote access, mobile devices.

Authorization process

A procedure to authorize system components going into production before they're used.

What an auditor usually asks for

  • Security policy approved by leadership
  • Security regulations documented and communicated
  • Operational security procedures defined
  • Component authorization process active

How to cover this block in Kimobox

  1. 1Document the security policy and regulations as controlled documents.
  2. 2Log the component authorization process as an approval workflow in Kimobox.
  3. 3Communicate the regulations to all involved staff from the employee portal.

The security policy and regulations stay version-controlled with evidence they were communicated to the team.

See Kimobox's document control

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Royal Decree 311/2022 regulating the National Security Framework BOE-A-2022-7191 · 4 May 2022
  2. National Cryptologic Centre — CCN-STIC guides CCN-CERT · ENS guide series
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024