---
title: "ENS: controls supported by Noraina"
description: "Which ENS controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit."
url: https://www.noraina.cloud/compliance/ens/
language: en
---
# ENS: controls supported by Noraina

Public bodies in Spain and any supplier providing them with ICT services.

> Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

## Esquema Nacional de Seguridad (Real Decreto 311/2022)

Spain's mandatory security framework for the public sector and the companies that supply it. References are measures from Annex II of RD 311/2022.

14 controls supported.

### Efficient Cloud Instances with replication

- Control: op.cont.2 (Continuity plan); op.cont.3 (Periodic continuity tests); op.cont.4 (Alternative means)
- How we help: Provides the alternative means of processing your continuity plan relies on, and the periodic failover tests the plan has to include.
- Evidence you get: Continuity architecture document, failover test reports with dates and results.
- Status: Mapping under review

### Efficient Cloud Backup

- Control: mp.info.6 (Backups)
- How we help: Off-site, encrypted and immutable copies that can be restored when the original data is lost or encrypted by ransomware.
- Evidence you get: Backup scope and retention configuration, restore test records.
- Status: Mapping under review

### Efficient Cloud DNS (NorainaDNS)

- Control: op.cont.2 (Continuity plan); op.cont.4 (Alternative means); mp.s.4 (Denial-of-service protection)
- How we help: On the Enterprise plan, a second authoritative DNS network is an alternative means for a service every application depends on, and keeps your domains resolving if one provider is under a denial-of-service attack or has an outage.
- Evidence you get: NS delegation showing both networks (Enterprise), failover configuration, health-check and failover event history.
- Status: Mapping under review

### Complete edge logging

- Control: op.exp.8 (Activity logging); op.mon.3 (Surveillance)
- How we help: Records user and system activity at the edge and feeds continuous monitoring.
- Evidence you get: Log retention configuration and sample activity reports.
- Status: Mapping under review

### Application and DDoS protection

- Control: mp.s.2 (Protection of web services and applications); mp.s.4 (Denial-of-service protection); op.mon.1 (Intrusion detection)
- How we help: Protects web services and applications, mitigates denial-of-service attacks and detects intrusion attempts.
- Evidence you get: Security configuration export and monthly threat reports.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: op.acc.2 (Access requirements); op.acc.4 (Access rights management); op.acc.6 (Authentication of internal users); mp.s.3 (Web browsing protection); mp.com.1 (Secure perimeter)
- How we help: Identity-based access to each application, strong authentication, web browsing protection and a secure perimeter without VPNs.
- Evidence you get: Access and Gateway policy exports, authentication logs.
- Status: Mapping under review


We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/ens/#assessment
