Skip to main content
  1. Index/

E-ITS / ISKE (Estonian Information Security Standard)

Table of Contents

E-ITS (Eesti infoturbestandard — Estonian Information Security Standard) is Estonia’s national information security framework, developed and maintained by the RIA (Riigi Infosüsteemi Amet — Information System Authority). It replaced the previous ISKE (Infosüsteemide kolmeastmeline etalonturbe süsteem) system, which was in effect until 31 December 2022. E-ITS entered into force in December 2022 and is mandatory for all organizations performing public duties in Estonia — state agencies, local governments, and any entity operating information systems essential for the functioning of society. Private organizations may also voluntarily adopt E-ITS to achieve their information security goals. The standard is based on the German BSI IT-Grundschutz baseline protection methodology and is designed to be fully compatible with ISO/IEC 27001 — an audited E-ITS conformity allows organizations to demonstrate compliance equivalent to the international standard. E-ITS presents a baseline protection catalog containing security modules with specific measures, organized by asset type (IT systems, networks, applications, industrial automation, vehicles, etc.). Organizations must identify their assets, determine protection needs, apply the corresponding baseline measures, and undergo periodic audits. Alternatively, organizations may satisfy their obligation by holding a valid ISO/IEC 27001 certificate and submitting it to RIA. The standard is updated annually each autumn to reflect new threats and technological developments, and RIA provides a free support application (based on the 2024 version) to guide implementers through the process.

Red Hat’s relevance to E-ITS stems from its deployment in Estonian public sector IT infrastructure and the standard’s technical alignment with BSI IT-Grundschutz, for which Red Hat has established support. Since E-ITS inherits its structure and methodology from Grundschutz, Red Hat’s capabilities map directly: the baseline protection modules covering operating systems, container platforms, and network services correspond to RHEL and OpenShift security features. RHEL’s OpenSCAP tooling can assess systems against baselines derived from the E-ITS catalog (via its Grundschutz heritage), SELinux enforces the access control requirements E-ITS modules prescribe, and system-wide cryptographic policies satisfy the encryption measures defined in the standard. For organizations choosing the ISO 27001 compliance path (which E-ITS explicitly accepts as equivalent), Red Hat’s Compliance Operator, Ansible-enforced configurations, and documented security architecture provide the technical evidence needed for ISO 27001 certification — simultaneously satisfying E-ITS obligations. The annual update cycle of E-ITS means that organizations must continuously maintain their security posture rather than treating compliance as a point-in-time exercise; Red Hat’s continuous compliance tooling (automated scanning, drift detection, policy-as-code remediation) is specifically designed for this operational model. As Estonia continues to lead in digital government and align E-ITS with EU-wide requirements (NIS2, CRA), Red Hat’s platform provides a stable, auditable foundation that evolves alongside the standard.

Additional Information
#

Related

ENS (Esquema Nacional de Seguridad)

The Esquema Nacional de Seguridad (ENS) is Spain’s national security framework, currently governed by Royal Decree 311/2022 (effective May 2022, with a transition period that ended April 2024). It is a mandatory regulatory requirement — not a voluntary standard — enforced by Spain’s CCN (Centro Criptológico Nacional, part of the CNI intelligence service) and applies to all Spanish public administrations (central, regional, local), as well as private-sector organizations that provide technology services or process data on behalf of the public sector. The ENS defines basic security principles, 16 minimum requirements (covering risk management, access control, incident handling, continuity, personnel security, etc.), and 73 security measures organized in three groups: organizational framework (4 measures), operational framework (31 measures), and protection measures (38 measures). Systems are classified into three categories — Basic, Medium, and High — based on the potential impact of a security incident on each security dimension (confidentiality, integrity, availability, authenticity, traceability). Each category level triggers progressively stricter “reinforcement” requirements for the applicable measures. Organizations with Medium or High systems must obtain formal certification every two years through an ENAC-accredited auditor, while Basic systems require a self-assessment declaration. The ENS is aligned with ISO/IEC 27001 and is being updated to incorporate NIS2 Directive requirements as Spain transposes the directive through its draft Cybersecurity Coordination and Governance Law (approved by the Council of Ministers in January 2025).

BSI IT-Grundschutz

BSI IT-Grundschutz is Germany’s national framework for establishing, implementing, and certifying an Information Security Management System (ISMS). It is developed and maintained by the BSI (Bundesamt für Sicherheit in der Informationstechnik) and stands out from generic standards like ISO/IEC 27001 by its extreme level of prescriptive detail — the IT-Grundschutz Compendium contains hundreds of specific security building blocks (“Bausteine”) covering technical, organizational, infrastructure, and personnel aspects. The framework is defined across four BSI Standards: 200-1 (ISMS requirements), 200-2 (methodology with three approaches: Basis-Absicherung, Standard-Absicherung, Kern-Absicherung), 200-3 (risk analysis), and 200-4 (business continuity management). Organizations can pursue ISO 27001 certification based on IT-Grundschutz, which is recognized as equivalent to standalone ISO 27001 but with the added rigor of the BSI’s detailed control catalog. Compliance is mandatory for German federal agencies (Bundesbehörden) under the UP Bund framework and is strongly recommended — often contractually required — for KRITIS operators and public-sector contractors. A major modernization is underway: Grundschutz++, introduced in 2025–2026, replaces the traditional PDF-based building blocks with OSCAL/JSON machine-readable catalogs, aligning with the NIS2 implementation requirement for a BSI-defined “state of the art.” The classic IT-Grundschutz remains valid for audits until end of 2028.

ISO/IEC 27001

ISO/IEC 27001 is the world’s most widely recognized standard for Information Security Management Systems (ISMS). It is published jointly by ISO (International Organization for Standardization) and IEC (International Electrotechnical Commission) — making it a truly international standard, not tied to any single country or jurisdiction. The current version is ISO/IEC 27001:2022, which replaced the 2013 edition and restructured its Annex A controls to align with the updated ISO/IEC 27002:2022 guidance (93 controls organized in 4 themes: Organizational, People, Physical, Technological). The standard specifies requirements (clauses 4–10) for establishing, implementing, maintaining, and continually improving an ISMS — covering context analysis, leadership commitment, risk assessment, treatment planning, operational controls, performance evaluation, and continuous improvement. Certification is voluntary but has become a global market expectation: ISO 27001 certification is required by countless procurement policies, regulatory frameworks (NIS2 references it, ENS aligns with it, E-ITS accepts it as equivalent, BSI IT-Grundschutz enables ISO 27001 certification), and customer contracts. Certification is issued by accredited certification bodies (accredited under ISO/IEC 17021) following a two-stage audit process, valid for 3 years with annual surveillance audits. Over 70,000 organizations worldwide hold ISO 27001 certification. Unlike prescriptive frameworks (DISA STIG, CIS Benchmarks), ISO 27001 is risk-based and outcome-oriented — it specifies what must be achieved but not how, allowing organizations to tailor implementations to their context.