GlossaryENS

ENS categories

Short answer

Under the ENS (Esquema Nacional de Seguridad), every information system is assigned a category, básica, media or alta, according to the impact a security incident would have. The category determines which security measures apply and whether the system needs a self declaration or an audited certification.

How the category is set

Each system is assessed on five security dimensions: confidentiality, integrity, traceability, authenticity and availability. For each dimension, the impact of an incident is rated as low, medium or high. The system takes the category of its highest rating: if any dimension is high, the category is alta; if the highest is medium, it is media; otherwise it is básica.

What changes with each category

The category determines which of the security measures in Annex II of Royal Decree 311/2022 apply and how demanding they are. A media or alta system has more measures and stricter requirements than a básica one.

How conformity is shown

Básica systems can show conformity through a Declaración de Conformidad based on an internal assessment. Media and alta systems need a Certificación de Conformidad after an audit by an accredited certification body.

Who decides

The categorisation is made by the organisation that owns the system, with the roles defined by the ENS. The CCN-STIC 803 guide explains how to value each dimension.

Related terms

Keep reading on this topic

The Esquema Nacional de Seguridad (RD 311/2022): categorisation, security levels, required controls and what public-sector contracting demands.

Go to the topic hub