Our own servers in Europe · GDPR · Support in your language

Module 1 of 5 · ENS · Block 1

System categorization

The first step of the ENS is categorizing the information system based on the impact a security incident would have on the services provided.

Content reviewed on

Security dimensions

Assessing the availability, integrity, confidentiality, authenticity, and traceability of the information handled.

Basic, medium, or high level

Assigning an overall category to the system (basic, medium, or high) based on the maximum impact assessed.

Risk analysis

Identifying threats and vulnerabilities in the system to justify the security measures applied.

What an auditor usually asks for

  • Assessment of the five security dimensions carried out
  • System category (basic/medium/high) documented
  • Risk analysis kept up to date
  • Information system scope defined

How to cover this block in Kimobox

  1. 1Document the security dimensions assessment as a version-controlled record in Kimobox.
  2. 2Log the category assigned to the system along with its justification.
  3. 3Link the risk analysis to the information system's process map.

System categorization stays documented and traceable, ready to justify to the auditor.

See information security management in Kimobox

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Royal Decree 311/2022 regulating the National Security Framework BOE-A-2022-7191 · 4 May 2022
  2. National Cryptologic Centre — CCN-STIC guides CCN-CERT · ENS guide series
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024