GlossaryENS

CCN-STIC

Short answer

The CCN-STIC guides are the series of security standards, procedures and recommendations published by the CCN (Centro Criptológico Nacional). The 800 series explains how to apply the ENS in practice and is the main reference for ENS implementation and audits.

The 800 series

The guides most relevant to companies are in the 800 series, dedicated to the ENS. Some of the most used are CCN-STIC 803 (how to value systems and set their category), 804 (how to implement each measure), 806 (Plan de adecuación), 808 (verifying compliance), 809 (declaration and certification of conformity), 817 (incident management) and 825 (how to use an ISO 27001 certification in an ENS project).

How they are used

The ENS itself, set out in Royal Decree 311/2022, defines what must be done. The CCN-STIC guides explain how. Auditors use them as reference, so following them makes an audit more predictable.

Other series

Other series cover policies, procedures and technical hardening guides for specific products and operating systems.

Where to find them

The guides are published by the CCN on the CCN-CERT portal, some publicly and others restricted to the public sector.

Related terms

Keep reading on this topic

The Esquema Nacional de Seguridad (RD 311/2022): categorisation, security levels, required controls and what public-sector contracting demands.

Go to the topic hub