Achieve ENS compliance with ManageEngine

Spain's Esquema Nacional de Seguridad (ENS), regulated by Royal Decree 311/2022, sets binding obligations on public-sector bodies and the private-sector suppliers that serve them. It requires organizations to categorize their systems as BÁSICA, MEDIA, or ALTA, protect information and services across five security dimensions (confidentiality, integrity, traceability, authenticity, and availability), apply the Annex II security measures in proportion to each system's risk, prove conformity through self-assessment or a certification audit, and maintain the ability to detect, investigate, and report security incidents.

Compliance

How can ManageEngine support ENS compliance?

With ManageEngine Log360, organizations can align with ENS requirements through centralized log collection and correlation across the systems in scope, continuous auditing of who accessed which records and when, real-time intrusion and breach detection with automated alerting to support incident notification to CCN-CERT, file integrity monitoring over sensitive repositories, and secure, tamper-evident log retention with synchronized clocks. These capabilities help implement the operational and monitoring measures of Annex II, enforce accountability, and produce the audit evidence expected during a certification audit.

Security governance frameworkMarco organizativo [org] — Security governance framework

Clause Functionality Explanation
[org.4] Proceso de autorización. A formal authorization process shall cover all system elements: use of facilities, entry of equipment and applications into production, communication links, use of media and mobile devices, and use of third-party services. Log360 - Change auditing, authorization-event tracking Log360 records who authorized and who performed each change, evidencing the authorization trail. Authorization for physical facilities and equipment entry into production ([org.4.1]–[org.4.2]) is an organizational process outside both suites.

Operational planningPlanificación [op.pl] — Operational planning

Clause Functionality Explanation
[op.pl.1] Análisis de riesgos. A risk analysis shall identify the most valuable assets, the most probable threats, the safeguards protecting against them and the principal residual risks; higher categories require semi-formal and formal methods. Log360 - UEBA risk scoring, threat intelligence, security posture reporting AD360 and Log360 supply risk inputs the analysis requires: AD360 assesses identity and access risk such as stale accounts and excessive privileges, while Log360 quantifies threat exposure through UEBA risk scores and threat-intelligence correlation. The formal risk-analysis methodology and residual-risk acceptance ([op.pl.1.r1]/[op.pl.1.r2]) remain the entity's documented process.
[op.pl.2] Arquitectura de seguridad. The security architecture shall document installations, the system, the lines of defense, and the user identification and authentication subsystem, including credentials, tokens, biometrics and directory-based access rights. Log360 - Defense-in-depth monitoring, cross-layer correlation Log360 instruments the lines of defense ([op.pl.2.3]) by correlating events across perimeter, network and host layers. Documentation of installations and network topology ([op.pl.2.1]–[op.pl.2.2]) is produced by the entity.
[op.pl.4] Dimensionamiento / gestión de la capacidad. Processing, storage and communication needs shall be studied before deployment, and capacity shall be forecast and monitored throughout the system life cycle (availability dimension). Log360 - Capacity monitoring, performance metrics, dashboards Log360 supplies the monitoring tools ([op.pl.4.r1.2]) that track processing, storage and communication load across monitored systems, supporting the continuous capacity forecasting the reinforcement requires. Determination of personnel and facility needs ([op.pl.4.4]–[op.pl.4.5]) is a planning activity outside the suite.

Access controlControl de acceso [op.acc] — Access control

Clause Functionality Explanation
[op.acc.1] Identificación. Every entity, user and process shall hold a singular identifier; users with several roles shall receive distinct identifiers per role; accounts shall be disabled on departure or role change and retained only for the traceability retention period. Log360 - Per-identity activity logging Log360 retains per-identity activity records for the traceability retention period the clause defines.
[op.acc.2] Requisitos de acceso. Resources shall be protected so only entities with sufficient rights can use them; rights are set by the resource owner; access to operating-system components and configuration files shall be controlled, with individually maintained privileges. Log360 - Audit of OS and configuration-file access Log360 audits every access to those operating-system components and configuration records.
[op.acc.3] Segregación de funciones y tareas. The access-control system shall require the concurrence of two or more people for critical tasks; development and operation, and authorization and control, shall be separated; audit accounts shall be controlled and personalized. Log360 - Dedicated audit accounts, privileged user monitoring Log360 provides the strictly controlled, personalized audit accounts ([op.acc.3.r2]) and monitors privileged users so audit and supervision functions stay independent of any other role ([op.acc.3.r1]).
[op.acc.5] Mecanismo de autenticación (usuarios externos). External users shall authenticate using passwords, one-time passwords, or qualified certificates; the credential life cycle shall be managed; access shall be locked after a limited number of failed attempts; accesses shall be logged. Log360 - Successful and failed access logging Log360 records successful and failed accesses and last-access notification ([R5]). Identity proofing via a Qualified Trust Service Provider ([op.acc.5.1]) is external to both suites.
[op.acc.6] Mecanismo de autenticación (usuarios de la organización). Internal users shall use a second authentication factor; double-factor authentication is required for access from uncontrolled zones such as the internet; remote access shall be authorized, encrypted and audited, with session renewal and inactivity suspension. Log360 - Access logging, remote-connection audit Log360 records successful and failed accesses ([R5]) and audit trails for remote connections ([op.acc.6.r9.2]).

OperationExplotación [op.exp] — Operation

Clause Functionality Explanation
[op.exp.1] Inventario de activos. An updated inventory of all system elements shall be maintained with their nature and responsible owner; tools shall continuously visualize the state of all networked equipment and categorize critical assets. Log360 - Asset inventory, continuous device discovery, software-component listing Log360 maintains an updated inventory of systems and provides the tools that continuously visualize the state of all networked equipment, servers and network devices ([op.exp.1.r2]) and categorize critical assets ([op.exp.1.r3]). A complete configuration-management database spanning every asset type is broader than either suite.
[op.exp.2] Configuración de seguridad. Equipment shall be configured before production so that default accounts and passwords are removed, minimum functionality is applied, secure-by-default settings hold, and virtual machines are hardened. Log360 - Configuration monitoring, security-state reporting Log360 monitors configuration state to confirm secure-by-default settings hold ([op.exp.2.3]). Hardening of virtual-machine and host images ([op.exp.2.4]) is applied through the entity's build process.
[op.exp.3] Gestión de la configuración de seguridad. Configuration shall be managed continuously so minimum functionality and least privilege are preserved, only authorized personnel edit it, baselines are maintained, configuration is backed up, and the security state of devices is known. Log360 - Configuration change monitoring, security-state assessment, configuration backup Log360 continuously monitors configuration, reports the security state of devices for correction where deficient ([op.exp.3.r5]), and backs up configuration for post-incident reconstruction ([op.exp.3.r3]).
[op.exp.4] Mantenimiento y actualizaciones de seguridad. A procedure shall analyze, prioritize and apply security updates and patches; firmware integrity shall be checked; a continuous threat-and-vulnerability monitoring strategy shall be deployed at ALTA. Log360 - Vulnerability and threat monitoring, firmware-integrity alerting, continuous-monitoring strategy Log360 delivers the continuous threat-and-vulnerability monitoring strategy the ALTA reinforcement requires ([op.exp.4.r4]), tracking defect and vulnerability announcements and alerting on firmware or configuration integrity changes ([op.exp.4.r3]). Patch deployment, pre-production testing and rollback ([op.exp.4.1]/[R1]/[R2]) are performed by the entity's patch-management tooling, outside AD360 and Log360.
[op.exp.5] Gestión de cambios. Changes shall be controlled through registered change requests with reference numbers; a risk analysis shall determine security relevance; HIGH-risk changes require prior explicit approval by the security officer. Log360 - Change auditing with before/after values, real-time change alerts Log360 audits every change with old and new values and raises real-time alerts, evidencing the traceability the change process requires. Formal change-request registration and impact analysis ([op.exp.5.1]–[op.exp.5.2]) are governed by the entity's change-management procedure.
[op.exp.6] Protección frente a código dañino. Prevention and reaction mechanisms against malicious code shall run on all endpoints, servers and perimeter elements; EDR tooling shall detect, investigate and resolve suspicious activity; application whitelisting is required at ALTA. Log360 - Malware detection and correlation, EDR alert integration, ransomware response, application-execution monitoring Log360 detects and correlates malicious-code indicators across endpoints, servers and perimeter, ingests EDR telemetry for the detect-investigate-respond capability the ALTA reinforcement requires ([op.exp.6.r4]), and automatically responds to ransomware. Anti-malware agent deployment and application-whitelisting enforcement ([op.exp.6.2]/[R3]) are endpoint-protection controls outside the suite.
[op.exp.7] Gestión de incidentes. An integral incident process shall include event reporting, classification and escalation; urgent containment through system isolation and evidence collection; single-window notification to CCN-CERT; dynamic reconfiguration; and automated prevention and response. Log360 - Incident management console, SOAR playbooks, automated containment, dynamic response Log360 provides the integral incident process the clause requires: detection, classification and escalation ([op.exp.7.1]); urgent containment through system isolation, evidence collection and log protection ([op.exp.7.r2]); dynamic reconfiguration of firewall, IPS and access rules to limit attacks ([op.exp.7.r3]); and automated prevention and response ([op.exp.7.r4]). Federated single-window notification to CCN-CERT ([op.exp.7.r1]) is supported through incident export.
[op.exp.8] Registro de la actividad. An audit record shall capture at least the identifier of the user or entity associated with each event, date and time, the information acted on, and the outcome; logs shall be protected, clocks synchronized and records retained (traceability dimension). Log360 - Comprehensive audit trail, time-stamped logs, tamper-evident storage, retention, clock synchronization Log360 generates the audit record the clause specifies — user or entity identifier, date and time, affected information and success or failure of each event ([op.exp.8.1]) — protects the logs against alteration, synchronizes clocks and retains the trail for the defined period across all reinforcement levels.
[op.exp.9] Registro de la gestión de incidentes. The handling of security incidents shall be recorded and used for the continuous improvement of system security. Log360 - Incident management records, resolution tracking, searchable incident history Log360 records the handling of every security incident in its incident-management console, retaining classification, actions taken and resolution so the record supports the continuous-improvement use the clause mandates.

External resourcesRecursos externos [op.ext] — External resources

Clause Functionality Explanation
[op.ext.4] Interconexión de sistemas. The risks of interconnecting the system with others shall be analyzed and the union point controlled; where interconnected systems operate in different security domains, local measures shall be accompanied by collaboration agreements. Log360 - Interconnection-point monitoring, perimeter traffic analysis Log360 monitors the union point between interconnected systems and analyzes traffic crossing it, supporting control of the interconnection the clause requires. Formal interconnection agreements follow the applicable Security Technical Instruction.

Cloud servicesServicios en la nube [op.nub] — Cloud services

Clause Functionality Explanation
[op.nub.1] Protección de servicios en la nube. Cloud services used by the entity shall be protected in proportion to the system category. Log360 - Cloud security monitoring (AWS, Azure, GCP, Salesforce), CASB, shadow-IT discovery Log360 monitors cloud-platform activity, applies CASB controls over cloud data movement and discovers shadow SaaS use, protecting the cloud services the measure covers. The provider's own CCN-qualified cloud configuration is a shared-responsibility element.

Service continuityContinuidad del servicio [op.cont] — Service continuity

Clause Functionality Explanation
[op.cont.2] Plan de continuidad. A continuity plan shall establish the mechanisms to guarantee continuity of operations in the event of loss of the usual means (availability dimension, ALTA). Log360 - Configuration backup AD360 backs up and restores directory objects, Entra ID and Microsoft 365 data, providing the identity-service recovery capability that underpins the continuity plan; Log360 backs up configuration for reconstruction after loss of normal means. Business-impact analysis, plan documentation and continuity testing ([op.cont.1]/[op.cont.3]) are organizational activities.

System monitoringMonitorización del sistema [op.mon] — System monitoring

Clause Functionality Explanation
[op.mon.1] Detección de intrusión. The system shall have intrusion-detection capability appropriate to its category. Log360 - Intrusion detection, real-time correlation, MITRE ATT&CK-mapped detection rules Log360 detects intrusion attempts through real-time correlation of security telemetry against 2,000-plus MITRE ATT&CK-mapped rules, delivering the intrusion-detection capability the measure requires from BÁSICA through ALTA reinforcement.
[op.mon.2] Sistema de métricas. A metrics system shall measure the evolution of the system's security state. Log360 - Security metrics dashboards, KPI reporting, trend analysis Log360 provides the metrics system the measure requires, presenting security indicators, dashboards and trend reports that let the entity measure the evolution of its security state and support decision-making.
[op.mon.3] Vigilancia. Continuous surveillance shall detect anomalous activities or behaviors and enable timely response; higher categories require extended surveillance capabilities. Log360 - Continuous monitoring, UEBA anomaly detection, threat intelligence, dark web monitoring Log360 provides the continuous surveillance the measure requires: ML-based UEBA detects anomalous behavior, threat-intelligence and dark-web feeds surface external exposure, and correlation delivers the anomalous-activity detection and timely response the principle of continuous vigilance demands.

Equipment protectionProtección de los equipos [mp.eq] — Equipment protection

Clause Functionality Explanation
[mp.eq.3] Protección de dispositivos portátiles. Information stored on or in transit through portable and peripheral devices shall receive specific protection. Log360 - Endpoint DLP, device control, portable-device activity monitoring Log360 protects information on portable and peripheral devices through endpoint DLP and device control — blocking unapproved USB devices, enforcing read-only access and preventing sensitive files from leaving the network — addressing the portable-device protection the measure requires. Full mobile-device management and disk encryption are provided by dedicated endpoint tooling.

Communications protectionProtección de las comunicaciones [mp.com] — Communications protection

Clause Functionality Explanation
[mp.com.1] Perímetro seguro. The system perimeter shall be protected, reinforcing prevention, detection and response when connected to public networks. Log360 - Firewall and perimeter log monitoring, perimeter event correlation Log360 monitors firewall and perimeter-device logs and correlates perimeter events, giving visibility over the secure perimeter the measure establishes. The firewall and gateway enforcement devices themselves are network infrastructure the entity operates.

Media protectionProtección de los soportes de información [mp.si] — Media protection

Clause Functionality Explanation
[mp.si.1] Marcado de soportes. Media shall be marked so that the security level of the information they hold is recognizable (confidentiality dimension). Log360 - Data classification and sensitivity labeling Log360 classifies information into sensitivity categories — Public, Private, Confidential and Restricted — and applies the corresponding labels, supporting the media-marking the measure requires so handling matches the security level of the content.

Information protectionProtección de la información [mp.info] — Information protection

Clause Functionality Explanation
[mp.info.1] Datos personales. Systems processing personal data shall apply the security measures derived from the data-protection risk analysis, in line with Article 3 and the GDPR. Log360 - Personal-data discovery and classification, DLP, access auditing Log360 discovers and classifies files containing personal data (PII, ePHI, PCI), prevents their exfiltration through DLP and audits all access to them, operationalizing the personal-data protection the measure requires in line with the GDPR risk analysis referenced in Article 3.
[mp.info.2] Calificación de la información. Information shall be classified so that handling matches the security level it requires (confidentiality dimension). Log360 - Data discovery and classification, content-aware policy Log360 locates sensitive content and classifies it by sensitivity, then applies content-aware protection per class, providing the information-qualification the measure requires so each information type receives controls proportionate to its level.
[mp.info.6] Copias de seguridad. Backups shall be maintained so information and services can be recovered after loss (availability dimension). Log360 - Configuration and log backup AD360 performs scheduled full and incremental backups of directory objects, Entra ID and Microsoft 365 and restores them selectively, providing the backups the measure requires for identity data; Log360 retains and archives logs and configuration. Backup of application and business data at large is handled by the entity's broader backup platform.

Service protectionProtección de los servicios [mp.s] — Service protection

Clause Functionality Explanation
[mp.s.1] Protección del correo electrónico. Email shall be protected against threats to which it is exposed. Log360 - Email and Microsoft 365 activity monitoring, email DLP Log360 monitors email and Microsoft 365 activity and applies DLP to prevent sensitive attachments from leaving via email, supporting the email protection the measure requires. Anti-spam and mail-gateway filtering are provided by the mail-security layer.
[mp.s.2] Protección de servicios y aplicaciones web. Web services and applications shall be protected against the threats to which they are exposed. Log360 - Web-server log monitoring, web-attack detection Log360 monitors web-server and application logs and detects web-borne attack patterns through correlation, supporting protection of web services and applications. The web application firewall that blocks requests inline is a separate network control.
[mp.s.3] Protección de la navegación web. Web browsing shall be protected against unsafe or unsolicited content. Log360 - URL filtering, web content control, shadow-IT discovery Log360 restricts access to unsafe web content — malware, phishing and spyware sites — through URL filtering and controls the use of web applications, addressing the web-browsing protection the measure requires.
[mp.s.4] Protección frente a denegación de servicio. The system shall be protected against denial-of-service attacks (availability dimension). Log360 - Denial-of-service detection, traffic-anomaly correlation Log360 detects denial-of-service conditions by correlating traffic anomalies and perimeter events, delivering the detection the measure requires. Upstream traffic scrubbing and volumetric mitigation are network-layer services outside the suite.