The four required measures
Annex II of Royal Decree 311/2022 groups four measures under the organizational framework: security policy (org.1), security regulations (org.2), security procedures (org.3) and authorization process (org.4).
Unlike most ENS measures, these four do not scale with the level: they apply equally to basic, medium and high categories. That makes this the first block worth closing, and the one an auditor assumes is already in place before moving on to anything technical.
Security policy
This is the document everything else hangs from, and the only one whose minimum content the royal decree sets out itself: article 12, «Security policy and minimum security requirements», lists what cannot be missing.
Those minimums are the organization's objectives or mission, the regulatory framework its activities operate under, the security roles or functions with each one's duties and responsibilities, the structure and composition of the committee or committees that manage and coordinate security, the guidelines for structuring the system's security documentation, and the risks arising from the processing of personal data.
Two points account for most audit findings. First, approval: a policy with no record of who approved it and when does not evidence the leadership backing the ENS assumes it has. Second, roles: the royal decree devotes a separate article to the differentiation of responsibilities, so naming one person for everything is precisely what it sets out to prevent.
Security regulations
The regulations bring the policy down to the specific matters people actually ask about: use of equipment and email, remote access, mobile and personal devices, removable media, passwords, remote work.
The difference from a procedure is the difference between a rule and an instruction: regulations say what is allowed, what is not and what happens if someone breaks them; a procedure says how the work is done and who does it. Blurring the two produces long documents nobody applies, and it is a common source of findings.
Security procedures
Procedures describe security activities step by step: who takes part, in what order, which record provides the evidence, and who it escalates to when something departs from the plan.
The test for which ones you need is a practical one: if a security task recurs and its outcome has to be demonstrable — granting and revoking user accounts, incident handling, backups and their restoration, disposal of media — it needs a written procedure, and the team's habits are not enough.
Authorization process
The last measure in the block closes the way in: nothing joins the system without prior, traceable authorization. It covers facilities, equipment and applications entering production, information media, communication links, and services contracted from third parties.
What turns this measure into something more than paperwork is writing down who authorizes what, and on what grounds. If authorization is a stray email, the evidence is lost; if it is a workflow with an owner, a criterion and a record, that authorization can still be audited years later.
What an auditor usually asks for
- Security policy approved by leadership, dated and with a record of the approval
- All six minimum contents of article 12 covered in the policy
- Security committee constituted, with its composition and duties in writing
- Security roles assigned to different people, with duties and responsibilities
- Security regulations documented, circulated and with evidence they were communicated
- Written security procedures for the activities that have to be demonstrable
- Authorization process active for facilities, equipment, applications, media and third-party services
How to cover this block in Kimobox
- 1Document the security policy and regulations as controlled documents.
- 2Log the component authorization process as an approval workflow in Kimobox.
- 3Communicate the regulations to all involved staff from the employee portal.
The security policy and regulations stay version-controlled with evidence they were communicated to the team.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Royal Decree 311/2022 regulating the National Security Framework BOE-A-2022-7191 · 4 May 2022
- National Cryptologic Centre — CCN-STIC guides CCN-CERT · ENS guide series
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024