Protecting facilities and equipment
Physical security measures for data processing centers and workstations.
Protecting communications and media
Encryption, network segmentation, and secure handling of information media.
Protecting information and applications
A secure application development lifecycle and protection of the data handled.
What an auditor usually asks for
- Asset and facility inventory documented
- Encryption and secure communications measures applied
- Media handling procedure defined
- Security measures in application development
How to cover this block in Kimobox
- 1Log the asset inventory as a version-controlled record in Kimobox.
- 2Document the protective measures applied to each type of asset.
- 3Link security incidents to the system's nonconformities.
The asset inventory and its protective measures stay documented in one place.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Royal Decree 311/2022 regulating the National Security Framework BOE-A-2022-7191 · 4 May 2022
- National Cryptologic Centre — CCN-STIC guides CCN-CERT · ENS guide series
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024