Skip to main content
Review and revision metadata
Review Date: 2026-06-19
Reviewer: Director

previous version on gdrive

CCN-STIC 825 ENS - self assessment

1. Regulatory Harmonization Baseline (CCN-STIC 825 & Royal Decree 311/2022)

The CCN-STIC 825 governance framework, issued by the Spanish National Cryptologic Centre (CCN), establishes the mandatory alignment mapping between the international ISO/IEC 27001:2023 standard and the Spanish National Security Framework (Esquema Nacional de Seguridad — ENS, codified under Royal Decree 311/2022). CCN-STIC 825 is strictly required for any entity providing IT services, cloud hosting, or software to the Spanish Public Sector, as well as critical infrastructure providers.

This self-assessment formalizes anDREa B.V.’s (hereafter "anDREa") compliance posture, serving as an administrative bridge that leverages our existing ISO/IEC 27001 certification to fulfill ENS structural, organizational, and operational control criteria across Basic, Medium, and High security categorizations without duplicative audit overhead.


Gap analysis

Based on CCN-STIC 825 ENS - Certifications 27001 anDREa conducted two gap analyses.

Status 2025-12-30

Strongly compliant except on some items summarized in the table below:

Related toStatusExplanation
Risk management / security dimensionsExplainAuditability (Tracebility) and Authenticity are added in mydre CIA-AA Classification
Certified productsExplainMicrosoft Azure and ENS High
Continuity of service / BackupsExplainmydre CIA-AA Classification
Information classificationExplainPublic = LOW, Confidential = HIGH. MEDIUM is not a valid anDREa classification.
CryptographyExplainmyDRE Cryptographic Configuration
Login attempts 10ExplainSecure myDRE access relies mostly on MFA and hardware keys or passkeys. Lockout Threshold is set to 10 with 60 seconds lockout configuration. Failed logins are monitored.
Traceability: User NotificationExplainUsers see at the mandatory MFA screen (at least every 24h) instructions on how to review their last login.
Password history not usedExplainCannot reuse the current password on change; this policy is controlled by Microsoft and is part of Self-service password reset policies - Microsoft Entra ID. MFA is integral part of login protection.
Password expirationExplainfollowing NIST Special Publication 800-63 - Digital Identity Guidelines and Password policy recommendation for Microsoft 365 Passwords passwords are set to Never Expire but will be required to be changed when the password is (suspected to be) lost. MFA is integral part of login protection. (Logon policy)

The full detailed analyses can be found in the following appendices:

Appendix: CCN-STIC 825 ENS - gap analysis A on 2025-12-25

ENS ControlDescriptionanDREa ISMS Coverage & Gap AnalysisCompliance Score (1-10)ReasoningCorrective actions
[org.1]Security Policy Requires a policy approved by top management detailing objectives, mission, and scope.Covered in: Clause 5.2 - Policy and Clause 5.1 - Leadership and Commitment.

Gap: ENS requires the policy to clearly distinguish the roles of "Responsable de la Información" and "Responsable del Servicio". Your [Roles & Responsibilities Matrix] covers Asset Owners but should explicitly map to these ENS terms.
9/10Policy exists and is comprehensive. Minor terminology adjustment needed for ENS roles.None: Terms of Service document. Under the section For workspace accountable, it explicitly states: "The final responsibility of workspace contents lies with the workspace accountable. He/She is responsible for both contents and activities that take place within the Workspace but also for the costs incurred due to used resources." For all myDRE services, anDREa is both responsible for information and the service.
[org.2]Security Standards Mandatory rules for acceptable use, clear desk, etc.Covered in: A.05.01 - Policies for information security, A.06.07 - Remote working, A.05.37 - Documented operating procedures.

Gap: None significant. Your Communication Facilities Policy and*A.06.07 - Remote working* policies align well.
10/10Strong documentation on acceptable use and remote working norms.None
[op.pl.1]Risk Analysis Requires continuous risk management.Covered in: Risk Assessment Guidance and Clause 6.1 - Actions to address risks and opportunities.

Gap: ENS requires analysis on 5 dimensions: C, I, A, Authenticity, and Traceability. Your guidance covers C, I, A, "Auditability" (Traceability) and Authenticity.
10/10Strong methodology (expert assessment).2025-12-26 The Auditability (Tracebility) and Authenticity are added in mydre CIA-AA Classification. Relevant risks are already part of Compliance and Risk Matrices and thus are part of the Risk Assessment Guidance.
[op.pl.2]Security Architecture System hardening and defense in depth.Covered in: A.08.25 - Secure development life cycle.

Gap: ENS emphasizes a formal "Security Architecture" document approved by the security responsible. You have high-level architecture documents, but formalizing them as a specific "Security Architecture" document is recommended.
9/10Architecture is well documented and follows "containment and isolation" principles Security Manifesto.None
[op.pl.5]Certified Products Use of CC/Common Criteria or CPSTIC certified products.Covered in: A.05.19 - Information security in supplier relationships.

Gap: You rely on Azure (Microsoft). While Azure generally holds high certifications (ENS High), you need to explicitly verify and document that your critical security components (e.g., Firewalls, IDM) appear in the CPSTIC (CCN-STIC 105) catalog or have equivalent EU certifications.
7/10Implicitly compliant via Azure, but requires formal verification/documentation in your anDREa Supplier List.None myDRE only relies on Microsoft Azure with respect to ingress, store, process, and egress data. See: Microsoft Azure and ENS High
[op.acc.1] - [op.acc.6]Access Control & Authentication Identification, MFA, segregation.Covered in: A.05.15 - Access control, Logon policy, Password Policy.

Gap: ENS [op.acc.6] requires double factor for access from "non-controlled zones" (Internet). Your Logon policy enforces MFA ("At least every 24h"). This is fully compliant.
10/10Your MFA enforcement with number matching and geo-location exceeds basic requirements.None
[op.exp.8]Activity Logging Recording user activities, exceptions, faults.Covered in: A.08.15 - Logging and Assessment Framework for Services.

Gap: ENS requires specific retention periods and protection against deletion. Your [Retention & Destruction Policy] states logs are immutable and kept for 90 days (user) / 2 years (forensic). This aligns well.
10/10Immutable logging and strong retention policies are in place.None
[op.ext.3]Supply Chain Protection Security in supplier relationships.Covered in: A.05.21 - Managing information security in the information and communication technology (ICT) supply chain, *A.05.19 - Information security in supplier relationships*.

Gap: ENS requires extending security requirements to subcontractors. Your A.05.21 - Managing information security in the information and communication technology (ICT) supply chain policy explicitly mentions "Supply chain risk management".
9/10Robust supplier management. Ensure contracts specifically mention ENS compliance where relevant for Spanish public sector data.None myDRE only relies on Microsoft Azure with respect to ingress, store, process, and egress data. See: Microsoft Azure and ENS High
[op.cont.2]Continuity of Service Business continuity planning (BCP).Covered in: Disaster Recovery Plan, Baseline Recovery of myDRE Service.

Gap: ENS Category High (if applicable) requires alternate means. Your Disaster Recovery Plan relies heavily on Azure availability. Ensure RTO/RPO aligns with specific ENS service level requirements if dealing with critical public services.
8/10Good plans, but reliance on a single cloud provider (Azure West Europe) is a noted risk in your [Baseline Recovery] document. ENS might view this as a concentration risk.None See: mydre CIA-AA Classification for the rational
[mp.eq.3]Portable Devices Protection of laptops/mobile (encryption).Covered in: A.06.07 - Remote working and A.08.01 - User end point devices.

Gap: ENS requires encryption for data outside premises. Your policy mandates Bitlocker/FileVault/ChromeOS encryption.
10/10Fully compliant. "Remote-first" nature means this is well covered.None
[mp.info.2]Information Qualification Marking/labeling information.Covered in: A.05.12 - Classification of information and A.05.13 - Labelling of information.

Gap: ENS uses specific labels (e.g., "Difusión Limitada"). Your classification is "Public/Confidential". You may need a mapping document stating "Confidential = ENS Media/Alta" or specific handling for Spanish government data classifications.
7/10Good classification scheme, but needs a "translation" layer for specific ENS labels if working with Spanish public administration.None: Public = LOW Confidential = HIGH anDREa does not recognise MEDIUM as a valid classification.
[mp.info.6]Backups Backup copies and restoration.Covered in: A.08.13 - Information backup, Retention & Destruction Policy.

Gap: ENS requires backups to be stored in a separate location. Your [Baseline Recovery] notes Azure LRS (Locally Redundant Storage) replicates within the same datacenter. This is a potential gap for ENS "Medium/High" which prefers geographic separation (GRS) to survive a datacenter disaster.
6/10Critical: LRS might not satisfy ENS requirements for "separate location" if the entire datacenter is lost. Consider upgrading to GRS for critical ENS-scope data.None See: mydre CIA-AA Classification for the rational

Appendix: CCN-STIC 825 ENS - gap analysis B on 2025-12-25

ENS Domain / RequirementanDREa Current Status (ISO 27001)Compliance Score (1-10)Explanation of Gap & RemediationCorrective actions
Security Dimensions (CCN-STIC 825, Sec 4.2)anDREa defines security objectives based on C-I-A (Confidentiality, Integrity, Availability). mydre CIA-AA Classification6/10

Gap: The ISMS lacks explicit definition of Authenticity and Traceability as core dimensions, which are required by ENS.

Remediation: Update the CIA (BIV) Classification policy to include Authenticity and Traceability as formal classification criteria.
2025-12-26 The Auditability (Tracebility) and Authenticity are added in [mydre CIA-AA Classification. Relevant risks are already part of anDREa Risksand thus are part of the Risk Assessment Guidance.
Authentication: Login Attempts (Request Consideration #2)anDREa sets the attempt limit to 10 with a cooling period of 60 seconds. Password Policy8/10

Gap: The specific ENS requirement provided limits attempts to 3 before blocking. anDREa's limit is too permissive for this specific requirement.

Remediation: Adjust Azure Entra ID / Application settings to lock out after 3 failed attempts for the specific scope, or document a risk acceptance if 10 is enforced by Microsoft defaults.
None anDREa follows Microsoft recommendations. Risky users are flagged and investigated. Secure myDRE access relies mostly on MFA (Microsoft Authenticator, number matching, maximum 24h valid, geo location). anDREa strongly recommends hardware keys or passkeys; easier and according to industry, more secure.
Traceability: User Notification (Request Consideration #2)anDREa logs sign-in activity in Azure Entra ID, but does not explicitly state it displays this to the user upon login. Logon policy4/10

Gap: ENS requires: "The user will be informed of the last access made with his identity". This is a functional requirement for the frontend that is likely missing.

Remediation: Implement a "Last Login" timestamp on the myDRE landing page dashboard.
2025-12-30 Users see at the mandatory MFA screen (at least every 24h) instructions on how to review their last login. 2025-12-25 Users can see a history of their last logins using standard Microsoft Azure login functionality Logon policy.
Authentication: Rejection Feedback (Request Consideration #2)anDREa uses Microsoft Azure AD defaults. Risky users, sign-ins and workloads, PIM roles9/10

Gap: ENS requires that "if rejected, the reason for rejection will not be reported". Azure generally complies with this (generic error messages), but it must be verified that custom error pages do not leak username validity.

Remediation: Verify Azure AD error message configuration.
None
Log Retention (Request Consideration #3)anDREa retains workspace logs for 90 days (hot) and forensic logs for 2 to 7 years (archived). Retention & Destruction Policy9/10

Gap: The specific request recommends retention for no less than two years for immediate review. While anDREa has 2-year forensic logs, the "90-day" limit for workspace members might be insufficient if the client requires immediate access to older logs.

Remediation: Clarify if "forensic logs" (2 years) are accessible enough to meet the client's "Activity Log" review requirement.
None The Retention Periods are well documented in detail. Customers can request reviewing and can request retention periods changes.
Cryptography (CCN-STIC 825, Sec 6.3)anDREa uses Azure/Google managed keys (AES-128/256). A.08.24 - Use of cryptography8/10

Gap: ENS requires algorithms authorized by the CCN-STIC 807 guide. While Azure's AES implementation is likely compliant, formal validation against the CCN guide is missing.

Remediation: Map current Azure encryption settings against CCN-STIC 807 and document compliance in the Use of Cryptography policy.
2025-12-30 A.08.24 - Use of cryptography Clients can verify if it meets their standards. Clients can request to manage their own keys provided they are mature enough.
Supply Chain/Cloud Security (CCN-STIC 825, Sec 5.21)anDREa uses Azure/Google and has strong supplier agreements. A.05.20 - Addressing information security within supplier agreements10/10No Gap: anDREa has robust supplier management, Security Impact Assessments (SIA), and relies on certified providers (Microsoft/Google) which aligns with ENS requirements for cloud services.None
Incident Management (CCN-STIC 825, Sec 5.24)anDREa has a 24-hour early warning and 72-hour full report SLA. A.05.25 - Assessment and decision on information security events10/10No Gap: The reporting timeline aligns perfectly with ENS requirements to notify the controller/authorities immediately/within 24 hours.None
Password History (Request Consideration #2)anDREa uses Microsoft recommendations. Policy does not explicitly state "Prohibition to reuse 10 previously used passwords" *Password Policy*.7/10

Gap: ENS specifically requires prohibiting the reuse of the last 10 passwords. The current policy relies on Microsoft defaults which may not enforce this specific count without custom configuration.

Remediation: Configure Entra ID Password Protection to enforce a history restriction of 10.
None Documented cases of users who in quick succession reset 11 times their password. Secure myDRE access relies mostly on MFA (Microsoft Authenticator, number matching, maximum 24h valid, geo location). anDREa strongly recommends hardware keys or passkeys; easier and according to industry, more secure. Microsoft Entra ID does not provide such an option.
Time Synchronization (Request Consideration #3)anDREa uses Windows clock synchronization. A.08.17 - Clock synchronization10/10No Gap: ENS requires synchronization with integrity mechanisms. Windows Time Service (NTP with authentication) satisfies this.None