E-ITS (Eesti infoturbestandard — Estonian Information Security Standard) is Estonia’s national information security framework, developed and maintained by the RIA (Riigi Infosüsteemi Amet — Information System Authority). It replaced the previous ISKE (Infosüsteemide kolmeastmeline etalonturbe süsteem) system, which was in effect until 31 December 2022. E-ITS entered into force in December 2022 and is mandatory for all organizations performing public duties in Estonia — state agencies, local governments, and any entity operating information systems essential for the functioning of society. Private organizations may also voluntarily adopt E-ITS to achieve their information security goals. The standard is based on the German BSI IT-Grundschutz baseline protection methodology and is designed to be fully compatible with ISO/IEC 27001 — an audited E-ITS conformity allows organizations to demonstrate compliance equivalent to the international standard. E-ITS presents a baseline protection catalog containing security modules with specific measures, organized by asset type (IT systems, networks, applications, industrial automation, vehicles, etc.). Organizations must identify their assets, determine protection needs, apply the corresponding baseline measures, and undergo periodic audits. Alternatively, organizations may satisfy their obligation by holding a valid ISO/IEC 27001 certificate and submitting it to RIA. The standard is updated annually each autumn to reflect new threats and technological developments, and RIA provides a free support application (based on the 2024 version) to guide implementers through the process.
Red Hat’s relevance to E-ITS stems from its deployment in Estonian public sector IT infrastructure and the standard’s technical alignment with BSI IT-Grundschutz, for which Red Hat has established support. Since E-ITS inherits its structure and methodology from Grundschutz, Red Hat’s capabilities map directly: the baseline protection modules covering operating systems, container platforms, and network services correspond to RHEL and OpenShift security features. RHEL’s OpenSCAP tooling can assess systems against baselines derived from the E-ITS catalog (via its Grundschutz heritage), SELinux enforces the access control requirements E-ITS modules prescribe, and system-wide cryptographic policies satisfy the encryption measures defined in the standard. For organizations choosing the ISO 27001 compliance path (which E-ITS explicitly accepts as equivalent), Red Hat’s Compliance Operator, Ansible-enforced configurations, and documented security architecture provide the technical evidence needed for ISO 27001 certification — simultaneously satisfying E-ITS obligations. The annual update cycle of E-ITS means that organizations must continuously maintain their security posture rather than treating compliance as a point-in-time exercise; Red Hat’s continuous compliance tooling (automated scanning, drift detection, policy-as-code remediation) is specifically designed for this operational model. As Estonia continues to lead in digital government and align E-ITS with EU-wide requirements (NIS2, CRA), Red Hat’s platform provides a stable, auditable foundation that evolves alongside the standard.
