Spain ENS
Spanish National Security Framework (Esquema Nacional de Seguridad)
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Access Control
| Code | Title |
|---|---|
| ENS-05 | Access Control and Identity Management |
Acquisition and Development
| Code | Title |
|---|---|
| ENS-09 | System Acquisition and Secure Development |
Audit
| Code | Title |
|---|---|
| ENS-16 | Compliance Audit and Certification |
Awareness
| Code | Title |
|---|---|
| ENS-18 | Awareness, Communication and Reporting |
Compliance
| Code | Title |
|---|---|
| ENS-04 | Statement of Applicability of Measures |
Cryptography
| Code | Title |
|---|---|
| ENS-06 | Cryptographic Protection |
Data Protection
| Code | Title |
|---|---|
| ENS-14 | Information Classification and Handling |
| ENS-19 | Data Protection Alignment with GDPR and LOPDGDD |
Detection
| Code | Title |
|---|---|
| ENS-11 | Monitoring, Logging and Traceability |
Framework
| Code | Title |
|---|---|
| ENS-01 | System Categorisation (Low, Medium, High) |
Governance
| Code | Title |
|---|---|
| ENS-02 | Security Policy and Governance Framework |
Incident Response
| Code | Title |
|---|---|
| ENS-12 | Incident Management |
Monitoring
| Code | Title |
|---|---|
| ENS-17 | Continuous Monitoring and Compliance Evidence |
Operations
| Code | Title |
|---|---|
| ENS-10 | Configuration and Vulnerability Management |
Personnel Security
| Code | Title |
|---|---|
| ENS-07 | Personnel Security and Training |
Physical Security
| Code | Title |
|---|---|
| ENS-08 | Physical and Environmental Security |
Procurement
| Code | Title |
|---|---|
| ENS-20 | Use of CCN Approved Products and Services |
Resilience
| Code | Title |
|---|---|
| ENS-13 | Continuity of Service |
Risk Management
| Code | Title |
|---|---|
| ENS-03 | Risk Analysis and Management |
Spain ENS: Access Control & Identity
Managing access to information systems (Spain ENS)
| Code | Title |
|---|---|
| ES-ENS-01 | Account management and provisioning |
| ES-ENS-02 | Access enforcement and least privilege |
| ES-ENS-03 | Multi-factor authentication requirements |
| ES-ENS-04 | Remote access controls |
| ES-ENS-05 | Wireless access restrictions |
| ES-ENS-06 | Identity proofing and verification |
Spain ENS: Audit & Accountability
Audit logging and accountability measures (Spain ENS)
| Code | Title |
|---|---|
| ES-ENS-28 | Audit event logging and storage |
| ES-ENS-29 | Audit record review and analysis |
| ES-ENS-30 | Time synchronization |
| ES-ENS-31 | Audit log protection and retention |
| ES-ENS-32 | Accountability and non-repudiation |
Spain ENS: Configuration Management
Managing system configurations securely (Spain ENS)
| Code | Title |
|---|---|
| ES-ENS-23 | Baseline configuration establishment |
| ES-ENS-24 | Configuration change control |
| ES-ENS-25 | Security impact analysis |
| ES-ENS-26 | System component inventory |
| ES-ENS-27 | Software usage restrictions |
Spain ENS: Incident Response
Detecting and responding to security incidents (Spain ENS)
| Code | Title |
|---|---|
| ES-ENS-18 | Incident response planning and testing |
| ES-ENS-19 | Incident handling and containment |
| ES-ENS-20 | Incident reporting and notification |
| ES-ENS-21 | Forensic analysis capabilities |
| ES-ENS-22 | Lessons learned and improvement |
Spain ENS: Risk Assessment & Management
Identifying and managing cybersecurity risks (Spain ENS)
| Code | Title |
|---|---|
| ES-ENS-13 | Risk assessment procedures |
| ES-ENS-14 | Vulnerability scanning and management |
| ES-ENS-15 | Security categorization |
| ES-ENS-16 | Threat intelligence integration |
| ES-ENS-17 | Continuous monitoring strategy |
Spain ENS: System & Communications Protection
Protecting systems and communications (Spain ENS)
| Code | Title |
|---|---|
| ES-ENS-07 | Boundary protection and segmentation |
| ES-ENS-08 | Cryptographic protection of data |
| ES-ENS-09 | Denial-of-service protection |
| ES-ENS-10 | Transmission confidentiality and integrity |
| ES-ENS-11 | Session management controls |
| ES-ENS-12 | Network monitoring and defense |
Third Party
| Code | Title |
|---|---|
| ENS-15 | Cloud Services and Outsourcing |
Your Compliance Coverage
If you comply with Spain ENS, you already cover:
Cyber Essentials Plus
38%
20 controls mapped
Compare →ANSSI Cybersecurity Framework
38%
20 controls mapped
Compare →DoD Zero Trust Reference Architecture
38%
20 controls mapped
Compare →+ 534 more: Belgium CyberFundamentals (38%), BSI IT-Grundschutz (38%)
See all 537 mapped frameworks ↓Maps to 537 other frameworks
Frequently Asked Questions
What is Spain ENS?
Spain ENS is a compliance framework from Spain with 25 domains and 52 controls. Spanish National Security Framework (Esquema Nacional de Seguridad) It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Spain ENS have?
Spain ENS has 52 controls organised across 25 domains. The largest domains are Spain ENS: Access Control & Identity (6 controls), Spain ENS: System & Communications Protection (6 controls), Spain ENS: Audit & Accountability (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Spain ENS map to?
Spain ENS maps to 537 other compliance frameworks. The top mapping partners are Cyber Essentials Plus (38% coverage), ANSSI Cybersecurity Framework (38% coverage), DoD Zero Trust Reference Architecture (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Spain ENS compliance?
Start your Spain ENS compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Spain ENS requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 52 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required