Esquema Nacional de Seguridad (Real Decreto 311/2022)
Spain's mandatory security framework for the public sector and the companies that supply it. Public bodies in Spain and any supplier providing them with ICT services.
14 controls supported. References are measures from Annex II of RD 311/2022.
Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.
Mapping under review
- Control
- op.cont.2Continuity plan
- op.cont.3Periodic continuity tests
- op.cont.4Alternative means
- How we help
- Provides the alternative means of processing your continuity plan relies on, and the periodic failover tests the plan has to include.
- Evidence you get
- Continuity architecture document, failover test reports with dates and results.
Mapping under review
- Control
- mp.info.6Backups
- How we help
- Off-site, encrypted and immutable copies that can be restored when the original data is lost or encrypted by ransomware.
- Evidence you get
- Backup scope and retention configuration, restore test records.
Mapping under review
- Control
- op.cont.2Continuity plan
- op.cont.4Alternative means
- mp.s.4Denial-of-service protection
- How we help
- On the Enterprise plan, a second authoritative DNS network is an alternative means for a service every application depends on, and keeps your domains resolving if one provider is under a denial-of-service attack or has an outage.
- Evidence you get
- NS delegation showing both networks (Enterprise), failover configuration, health-check and failover event history.
Mapping under review
- Control
- op.exp.8Activity logging
- op.mon.3Surveillance
- How we help
- Records user and system activity at the edge and feeds continuous monitoring.
- Evidence you get
- Log retention configuration and sample activity reports.
Mapping under review
- Control
- mp.s.2Protection of web services and applications
- mp.s.4Denial-of-service protection
- op.mon.1Intrusion detection
- How we help
- Protects web services and applications, mitigates denial-of-service attacks and detects intrusion attempts.
- Evidence you get
- Security configuration export and monthly threat reports.
Mapping under review
- Control
- op.acc.2Access requirements
- op.acc.4Access rights management
- op.acc.6Authentication of internal users
- mp.s.3Web browsing protection
- mp.com.1Secure perimeter
- How we help
- Identity-based access to each application, strong authentication, web browsing protection and a secure perimeter without VPNs.
- Evidence you get
- Access and Gateway policy exports, authentication logs.
Tell us what you are preparing for
We reply with the controls we can cover, what stays on your side, and a realistic timeline.