Security dimensions
Assessing the availability, integrity, confidentiality, authenticity, and traceability of the information handled.
Basic, medium, or high level
Assigning an overall category to the system (basic, medium, or high) based on the maximum impact assessed.
Risk analysis
Identifying threats and vulnerabilities in the system to justify the security measures applied.
What an auditor usually asks for
- Assessment of the five security dimensions carried out
- System category (basic/medium/high) documented
- Risk analysis kept up to date
- Information system scope defined
How to cover this block in Kimobox
- 1Document the security dimensions assessment as a version-controlled record in Kimobox.
- 2Log the category assigned to the system along with its justification.
- 3Link the risk analysis to the information system's process map.
System categorization stays documented and traceable, ready to justify to the auditor.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Royal Decree 311/2022 regulating the National Security Framework BOE-A-2022-7191 · 4 May 2022
- National Cryptologic Centre — CCN-STIC guides CCN-CERT · ENS guide series
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024