<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Isms on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/isms/</link><description>Recent content in Isms on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/isms/index.xml" rel="self" type="application/rss+xml"/><item><title>BSI IT-Grundschutz</title><link>https://lesitedefrancois.be/en/compliance/bsi-it-grundschutz/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/bsi-it-grundschutz/</guid><description>&lt;p&gt;&lt;strong&gt;BSI IT-Grundschutz&lt;/strong&gt; is Germany&amp;rsquo;s national framework for establishing, implementing, and certifying an Information Security Management System (ISMS). It is developed and maintained by the BSI (Bundesamt für Sicherheit in der Informationstechnik) and stands out from generic standards like ISO/IEC 27001 by its extreme level of prescriptive detail — the IT-Grundschutz Compendium contains hundreds of specific security building blocks (&amp;ldquo;Bausteine&amp;rdquo;) covering technical, organizational, infrastructure, and personnel aspects. The framework is defined across four BSI Standards: &lt;strong&gt;200-1&lt;/strong&gt; (ISMS requirements), &lt;strong&gt;200-2&lt;/strong&gt; (methodology with three approaches: Basis-Absicherung, Standard-Absicherung, Kern-Absicherung), &lt;strong&gt;200-3&lt;/strong&gt; (risk analysis), and &lt;strong&gt;200-4&lt;/strong&gt; (business continuity management). Organizations can pursue &lt;strong&gt;ISO 27001 certification based on IT-Grundschutz&lt;/strong&gt;, which is recognized as equivalent to standalone ISO 27001 but with the added rigor of the BSI&amp;rsquo;s detailed control catalog. Compliance is &lt;strong&gt;mandatory&lt;/strong&gt; for German federal agencies (Bundesbehörden) under the UP Bund framework and is strongly recommended — often contractually required — for KRITIS operators and public-sector contractors. A major modernization is underway: &lt;strong&gt;Grundschutz++&lt;/strong&gt;, introduced in 2025–2026, replaces the traditional PDF-based building blocks with OSCAL/JSON machine-readable catalogs, aligning with the NIS2 implementation requirement for a BSI-defined &amp;ldquo;state of the art.&amp;rdquo; The classic IT-Grundschutz remains valid for audits until end of 2028.&lt;/p&gt;</description></item><item><title>E-ITS / ISKE (Estonian Information Security Standard)</title><link>https://lesitedefrancois.be/en/compliance/e-its/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/e-its/</guid><description>&lt;p&gt;&lt;strong&gt;E-ITS&lt;/strong&gt; (Eesti infoturbestandard — Estonian Information Security Standard) is Estonia&amp;rsquo;s national information security framework, developed and maintained by the &lt;strong&gt;RIA&lt;/strong&gt; (Riigi Infosüsteemi Amet — Information System Authority). It replaced the previous &lt;strong&gt;ISKE&lt;/strong&gt; (Infosüsteemide kolmeastmeline etalonturbe süsteem) system, which was in effect until 31 December 2022. E-ITS entered into force in December 2022 and is &lt;strong&gt;mandatory&lt;/strong&gt; for all organizations performing public duties in Estonia — state agencies, local governments, and any entity operating information systems essential for the functioning of society. Private organizations may also voluntarily adopt E-ITS to achieve their information security goals. The standard is based on the German &lt;strong&gt;BSI IT-Grundschutz&lt;/strong&gt; baseline protection methodology and is designed to be fully compatible with &lt;strong&gt;ISO/IEC 27001&lt;/strong&gt; — an audited E-ITS conformity allows organizations to demonstrate compliance equivalent to the international standard. E-ITS presents a baseline protection catalog containing security modules with specific measures, organized by asset type (IT systems, networks, applications, industrial automation, vehicles, etc.). Organizations must identify their assets, determine protection needs, apply the corresponding baseline measures, and undergo periodic audits. Alternatively, organizations may satisfy their obligation by holding a valid ISO/IEC 27001 certificate and submitting it to RIA. The standard is updated annually each autumn to reflect new threats and technological developments, and RIA provides a free support application (based on the 2024 version) to guide implementers through the process.&lt;/p&gt;</description></item><item><title>ENS (Esquema Nacional de Seguridad)</title><link>https://lesitedefrancois.be/en/compliance/ens/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/ens/</guid><description>&lt;p&gt;The &lt;strong&gt;Esquema Nacional de Seguridad (ENS)&lt;/strong&gt; is Spain&amp;rsquo;s national security framework, currently governed by &lt;strong&gt;Royal Decree 311/2022&lt;/strong&gt; (effective May 2022, with a transition period that ended April 2024). It is a &lt;strong&gt;mandatory&lt;/strong&gt; regulatory requirement — not a voluntary standard — enforced by Spain&amp;rsquo;s &lt;strong&gt;CCN&lt;/strong&gt; (Centro Criptológico Nacional, part of the CNI intelligence service) and applies to all Spanish public administrations (central, regional, local), as well as &lt;strong&gt;private-sector organizations&lt;/strong&gt; that provide technology services or process data on behalf of the public sector. The ENS defines basic security principles, 16 minimum requirements (covering risk management, access control, incident handling, continuity, personnel security, etc.), and &lt;strong&gt;73 security measures&lt;/strong&gt; organized in three groups: organizational framework (4 measures), operational framework (31 measures), and protection measures (38 measures). Systems are classified into three categories — &lt;strong&gt;Basic, Medium, and High&lt;/strong&gt; — based on the potential impact of a security incident on each security dimension (confidentiality, integrity, availability, authenticity, traceability). Each category level triggers progressively stricter &amp;ldquo;reinforcement&amp;rdquo; requirements for the applicable measures. Organizations with Medium or High systems must obtain &lt;strong&gt;formal certification&lt;/strong&gt; every two years through an ENAC-accredited auditor, while Basic systems require a self-assessment declaration. The ENS is aligned with ISO/IEC 27001 and is being updated to incorporate NIS2 Directive requirements as Spain transposes the directive through its draft Cybersecurity Coordination and Governance Law (approved by the Council of Ministers in January 2025).&lt;/p&gt;</description></item><item><title>ISO/IEC 27001</title><link>https://lesitedefrancois.be/en/compliance/iso-27001/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/iso-27001/</guid><description>&lt;p&gt;&lt;strong&gt;ISO/IEC 27001&lt;/strong&gt; is the world&amp;rsquo;s most widely recognized standard for Information Security Management Systems (ISMS). It is published jointly by &lt;strong&gt;ISO&lt;/strong&gt; (International Organization for Standardization) and &lt;strong&gt;IEC&lt;/strong&gt; (International Electrotechnical Commission) — making it a truly international standard, not tied to any single country or jurisdiction. The current version is &lt;strong&gt;ISO/IEC 27001:2022&lt;/strong&gt;, which replaced the 2013 edition and restructured its Annex A controls to align with the updated ISO/IEC 27002:2022 guidance (93 controls organized in 4 themes: Organizational, People, Physical, Technological). The standard specifies &lt;strong&gt;requirements&lt;/strong&gt; (clauses 4–10) for establishing, implementing, maintaining, and continually improving an ISMS — covering context analysis, leadership commitment, risk assessment, treatment planning, operational controls, performance evaluation, and continuous improvement. Certification is &lt;strong&gt;voluntary&lt;/strong&gt; but has become a global market expectation: ISO 27001 certification is required by countless procurement policies, regulatory frameworks (NIS2 references it, ENS aligns with it, E-ITS accepts it as equivalent, BSI IT-Grundschutz enables ISO 27001 certification), and customer contracts. Certification is issued by accredited certification bodies (accredited under ISO/IEC 17021) following a two-stage audit process, valid for &lt;strong&gt;3 years&lt;/strong&gt; with annual surveillance audits. Over 70,000 organizations worldwide hold ISO 27001 certification. Unlike prescriptive frameworks (DISA STIG, CIS Benchmarks), ISO 27001 is &lt;strong&gt;risk-based and outcome-oriented&lt;/strong&gt; — it specifies what must be achieved but not how, allowing organizations to tailor implementations to their context.&lt;/p&gt;</description></item></channel></rss>