Cybersecurity and compliance

ENS in Valladolid: regional government headquarters and local procurement, two circuits with two different requirements

Valladolid is home to the headquarters of the Junta de Castilla y León, which publishes on its electronic site the ENS conformity certificates of the different bodies of the regional administration. One of them illustrates the level involved: the Consejería de Agricultura y Ganadería, as Paying Body for Common Agricultural Policy aid, publishes an ENS conformity certificate in the medium category issued on 10 December 2018, alongside ISO 27001 certification held since September 2016. No validity window or later renewal is published, so it is worth confirming its current status before relying on it. Around that regional seat lies a territory with a very high density of municipalities, where technology procurement is spread across hundreds of small local entities. These are two different markets with two different requirements, and Summum Sistemas works both from the technical side.

RegulationRD 311/2022 · BOE-A-2022-7191
ContextSeat of the Junta de Castilla y León · highly municipalised territory
Technical focusMixed categories · op.exp · scaling to many entities

It is worth keeping the two circuits separate, because the technical answer is not the same for both. In the regional circuit, the supplier integrates with Junta systems that in some cases are certified in the medium category, and that pulls the conformity route with it: Article 38.1 of RD 311/2022 establishes that medium- or high-category systems require an audit for certification of their conformity, as against the self-assessment that suffices for basic category — without prejudice to a basic-category system also undergoing a certification audit if it chooses to. In the local circuit, by contrast, the counterparty is usually a small town council with no systems team of its own, supported by regional programmes for municipal e-government; there the system is normally basic category, and what is needed is a solution that can be replicated across many entities without redoing the case file each time.

What does not change between the two circuits is the regulation itself. Article 2.1 of RD 311/2022 applies the royal decree to the whole public sector in the terms of Article 2 of Law 40/2015, and Article 2.3 extends it to the systems of private-sector entities — including the obligation to hold the security policy required by Article 12 — when they provide services or supply solutions to those entities, under a contractual relationship, for the exercise by the latter of their administrative competences and powers. The same article requires tender specifications to include the requirements needed to ensure conformity, «such as the presentation of the corresponding ENS Conformity Declarations or Certificates», and extends that caution to the contractor's supply chain. And Article 38.2 requires those declarations and certificates to be published on the relevant websites or electronic sites: that is why the Junta's certificates can be consulted.

Technically, a product that is going to be deployed across many local entities stakes the whole project on the op.exp family of the operational framework: asset inventory, security configuration, change management, protection against malicious code and activity logging. If those measures are solved once and reproducibly, deployment at the fortieth entity costs the same as at the first; if they are solved by hand, there is no margin left. On top of that sits categorisation under Annex I, assessing impact across the five dimensions of Article 40.2, risk analysis with MAGERIT modelled in PILAR — the methodology and tool of the Centro Criptológico Nacional (CCN) — and cryptographic configuration under CCN-STIC-807. Annex II brings together 73 controls across 16 families and three frameworks; which ones apply, and with what reinforcements, is decided by the category, not by the size of the client.

The ENS in Valladolid process.

The process · four stages
01

Splitting the circuits: regional and local

We map which circuit each part of the business falls under, because the conformity route differs. Integrating with regional systems certified in the medium category tends to raise your own category owing to the impact of the information you handle, or the tender may require it outright; if you reach medium category, you need a certification audit. Deployment across local entities usually sits at basic category with a declaration of conformity.

02

Categorisation under Annex I

We set the category of each system by assessing impact on the five dimensions of Article 40.2, following the Annex I procedure, with the justification documented so it holds up under both regional review and an auditor's review.

03

Reproducible implementation of Annex II controls

We implement the controls — weighted towards op.exp: inventory, security configuration, change management, malicious code and activity logging — in a way that is automatable and reproducible, so that multi-entity deployment does not multiply the cost.

04

Conformity route and evidence

We prepare the self-assessment and declaration of conformity where the system is basic category, and the certification audit where it is medium or high, both under Article 31 and Annex III, with the evidence package that supports them.

What is included

What ENS in Valladolid includes.

The operational detail: what we deliver as part of the work and what we keep alive afterwards.

  • Map of circuits and categories

    Analysis of which administrations you serve and which category corresponds to each system, distinguishing the regional circuit from the local one because the conformity route is not the same.

  • Categorisation report under Annex I

    Justification of the category with the impact assessment on availability, authenticity, integrity, confidentiality and traceability, in accordance with Article 40.2.

  • MAGERIT risk analysis modelled in PILAR

    With MAGERIT and PILAR, the CCN's methodology and tool: assets, dependencies, threats and safeguards, updated at least annually or after significant changes.

  • Automated operational measures (op.exp)

    Asset inventory, security configuration, change management, protection against malicious code and activity logging, implemented reproducibly for deployment across many entities.

  • Cryptography and communications protection

    Configuration in accordance with CCN-STIC-807 — TLS 1.2 as the minimum version, AES-256, SHA-256 or higher — and mp.com family measures proportionate to the system's category.

  • Conformity file through the appropriate route

    Self-assessment and declaration of conformity in basic category, or preparation for the certification audit in medium and high, with a prior review against Annex III.

Frequently asked questions about ENS in Valladolid.

Can I see the Junta de Castilla y León's ENS certificates?

Yes. Article 38.2 of RD 311/2022 requires the parties responsible for the systems to publish, on the relevant websites or electronic sites, their ENS conformity declarations and certificates. The Junta de Castilla y León publishes on its electronic site the certificates relating to ENS compliance of the different bodies of the regional administration.

I sell the same software to many small town councils. Do I need a separate ENS file for each one?

Not necessarily. Conformity relates to your information systems, not to each individual contract. If the product and its infrastructure are the same, the scope can be defined once and cover deployments that share the same architecture. What does vary by client is the tender clauses, which under Article 2.3 must include the requirements needed to ensure conformity, and the category of the town council's own system.

What category does a small town council usually have?

There is no default answer, and giving one would be a mistake: the category is determined case by case under Annex I of RD 311/2022, assessing the impact an incident would have on the five dimensions listed in Article 40.2 — availability, authenticity, integrity, confidentiality and traceability. What is true is that basic category is common in small local entities, and that in that category Article 38.1 only requires a self-assessment for the declaration of conformity, without prejudice to it also undergoing a certification audit.

I'm integrating with a regional system certified in medium category. What does that involve?

Above all, it means anticipating the conformity route. Article 38.1 of RD 311/2022 establishes that medium- or high-category systems require an audit for certification, and a self-assessment is not enough. If your system moves up to medium category because of the impact of the information it handles, the project's timeline and cost change, and it is worth knowing that before committing deadlines to the client.

How many controls does Annex II contain?

Annex II of RD 311/2022 contains 73 controls organised into 16 families and three frameworks: organisational, operational and protection. Each control carries its required level according to the system's category, which can range from «not applicable» to application with reinforcements, numbered from R1 onwards. How many apply to you depends on your category and scope, and comes out of the risk analysis.

Does Summum Sistemas certify the ENS?

No. We carry out the technical implementation and prepare the case file: categorisation, risk analysis, Annex II controls and the evidence package. Certification is issued by a third party, and Article 38.1 refers to the corresponding Security Technical Instruction for the requirements applicable to certification bodies.