Cybersecurity and compliance

ENS in Las Palmas: island cabildos, not diputaciones, and why that changes the procurement map

The Canary Islands have no diputaciones provinciales: island-level administration is exercised by the cabildos, and in the province of Las Palmas that means three separate island public buyers — Gran Canaria, Lanzarote and Fuerteventura — on top of the Gobierno de Canarias, the town councils, the Universidad de Las Palmas de Gran Canaria and the Servicio Canario de la Salud. For a technology company, the procurement map does not look like the mainland's. The Cabildo de Gran Canaria's electronic site is expressly governed by RD 311/2022, which regulates the Esquema Nacional de Seguridad, and that royal decree, under Article 2.3, also reaches the systems of private companies that provide services or supply solutions to those entities for the exercise by these of their administrative competences and powers. Summum Sistemas technically implements what the regulation requires.

RegulationRD 311/2022 · BOE-A-2022-7191
StructureIsland cabildos (no diputación provincial in the Canary Islands)
Technical focusop.nub · op.cont · continuity in an island setting

The first practical consequence of the island structure is that there is no single province-wide counterpart. A supplier wanting to work in the province of Las Palmas finds cabildos that procure separately, town councils that are often small, and the regional and health administration above them. All are public-sector entities within the meaning of Article 2.1 of RD 311/2022, which refers to Article 2 of Law 40/2015, and all are required to include in their tender specifications the requirements needed to ensure ENS conformity of the systems underpinning contractors' services: Article 2.3 imposes this, expressly mentioning the presentation of Conformity Declarations or Certificates and extending that caution to the supply chain. More counterparts means more tenders, but it does not mean more regulations: there is only one ENS.

The second consequence is technical and has to do with where the service lives. In an archipelago, the infrastructure supporting applications is often hosted off the island or directly on public cloud. That takes the project squarely into two Annex II families. The first is op.nub, «Cloud services», whose op.nub.1 control, «Protection of cloud services», applies from basic category and is reinforced in medium and high: you have to demonstrate how the cloud service is protected, not just state it. The second is op.cont, service continuity, with its impact-analysis, continuity-plan, periodic-testing and alternative-means controls. It is worth being precise: Annex II grades those controls by category, and in the lower categories several of them are not required. What determines applicability is not geography, it is the category and the risk analysis.

The third point is the most overlooked and it is not about infrastructure. Article 2.3 of RD 311/2022 requires the private entity to hold the security policy required by Article 12, and specifies that for these entities it «shall be approved […] by the body holding the highest executive authority». Alongside that, Article 38.2 requires those responsible to publish, on their websites or electronic sites, their ENS conformity declarations and certificates: in other words, the conformity status of the administrations you want to work with is public and can be checked. Summum Sistemas' job is to get your side of that equation technically resolved: categorisation under Annex I, risk analysis with MAGERIT and PILAR, the methodology and tool of the Centro Criptológico Nacional, and verifiable implementation of the Annex II controls.

The ENS in Las Palmas process.

The process · four stages
01

Island procurement map and scope

We define which entities you are going to serve — cabildos, town councils, Gobierno de Canarias, ULPGC, Servicio Canario de la Salud — and which of your systems fall within the ENS scope. In a map with several island buyers, defining the scope well avoids over-categorising and overpaying.

02

Categorisation under Annex I

We set the system's category by assessing the impact an incident would have across the five dimensions listed in Article 40.2: availability, authenticity, integrity, confidentiality and traceability. The category decides which Annex II controls are required and with what reinforcements, and also the Article 38 conformity route.

03

Cloud and continuity: op.nub and op.cont

We work on the two families that matter most when the service is hosted off the island. In op.nub, protection of the cloud service and verification of the contractual conditions with the provider. In op.cont, impact analysis and — where the category requires it — the continuity plan, periodic tests and alternative means.

04

Evidence and conformity route

We compile the technical evidence package and prepare the appropriate route: self-assessment for the declaration of conformity if the system is basic category — which may also undergo a certification audit —, or a certification audit if it is medium or high, under Article 38.1.

What is included

What ENS in Las Palmas includes.

The operational detail: what we deliver as part of the work and what we keep alive afterwards.

  • Documented scope and categorisation

    Delimitation of the ENS perimeter and justification of the category with the impact assessment across the five dimensions of Article 40.2, service by service.

  • MAGERIT risk analysis modelled in PILAR

    With MAGERIT and PILAR, from the Centro Criptológico Nacional: assets, dependencies, threats, safeguards and residual risk, with treatment decisions documented and reviewable.

  • Cloud-layer compliance (op.nub)

    Verification of the cloud provider's fit with op.nub.1 and of the inherited contractual conditions, including what is transferred to you under the shared-responsibility model.

  • Service continuity (op.cont) proportionate to the category

    Impact analysis and, where the category requires it, continuity plan, periodic tests and alternative means, with the records that prove the tests were genuinely carried out.

  • Hardening, cryptography and activity logging

    System and service hardening, cryptographic configuration under CCN-STIC-807 and tuning of activity logging and monitoring, which are the evidence any review asks for first.

  • Article 12 security policy and evidence

    Preparation of the policy Article 2.3 requires of the private entity, with the note that it must be approved by the body holding the highest executive authority, and of the technical evidence package for the appropriate conformity route.

Frequently asked questions about ENS in Las Palmas.

There is no diputación provincial in the Canary Islands. Who is my public counterpart, then?

Island-level administration is exercised by the cabildos insulares. In the province of Las Palmas that means three cabildos — Gran Canaria, Lanzarote and Fuerteventura — that procure independently, on top of the Gobierno de Canarias, the town councils, the Universidad de Las Palmas de Gran Canaria and the Servicio Canario de la Salud. All are public-sector entities for the purposes of Article 2.1 of RD 311/2022, so the ENS applies the same way; what changes is the number of counterparts.

My application is hosted on the mainland or on public cloud. Is that a problem for the ENS?

It is not a problem in itself, but it does activate specific requirements. Annex II of RD 311/2022 includes the op.nub «Cloud services» family, and its op.nub.1 control, «Protection of cloud services», applies from basic category, with reinforcements in medium and high. You have to document how those requirements are covered on the contracted infrastructure and what part of the shared-responsibility model you take on.

Does being an island make a continuity plan and alternative means mandatory?

The obligation does not come from geography, it comes from the category. Annex II grades the op.cont family controls — impact analysis, continuity plan, periodic tests and alternative means — according to the system's category, and in the lower categories several of them are not required. That said, the risk analysis is the instrument that translates operational reality into decisions, and a service whose recovery depends on a single connection tends to stand out in that analysis.

Can I check whether the administration I want to sell to is conformant?

Yes, and it is a useful source of information before preparing an offer. Article 38.2 of RD 311/2022 requires those responsible to publish, on the relevant websites or electronic sites, their ENS conformity declarations and certificates. The Cabildo de Gran Canaria's electronic site, for example, is expressly governed by that royal decree and publishes its regulatory information.

What do I need to prepare before bidding for a tender?

The minimum defensible position is: a defined scope, a category justified under Annex I, a completed risk analysis, Annex II controls implemented in proportion to that category, the Article 12 security policy approved by the body holding the highest executive authority, and the Article 38 conformity route resolved: self-assessment in basic category, certification audit in medium or high.

Does Summum Sistemas certify?

No. We carry out the technical implementation and prepare the evidence. Conformity certification is issued by a third party; Article 38.1 of RD 311/2022 refers to the corresponding Security Technical Instruction for the requirements applicable to certification bodies.