Compliance & EU/ES regulation
Definiciones en lenguaje claro del tema compliance & eu/es regulation.
CCN-STIC guides
The CCN-STIC guides are the security guidance series published by Spain’s Centro Criptológico Nacional. They are the reference an ENS audit works from, and the 800 series in particular sets out how the national security scheme is interpreted, implemented and evidenced in practice.
CISO (chief information security officer)
In security governance, the CISO is the person an organisation holds accountable for its information security: they decide which risks are accepted, in what order the rest are treated, and they answer for it to whoever governs the company. It is a decision-making role rather than a technical one, and most of the confusion follows from that.
Cyber Resilience Act
In EU regulation, the Cyber Resilience Act (CRA) sets security requirements for products with digital elements sold in the European market, covering their whole lifecycle. It reaches every manufacturer of connected products, which is exactly the client of an IoT assessment, and it links the world of devices to the world of compliance.
Data protection impact assessment (DPIA)
In EU data protection, a data protection impact assessment (DPIA) is the analysis the GDPR requires before processing that is likely to result in a high risk to people’s rights. It is the deliverable a supervisory authority expects, and the place where a technical firm contributes the real risk picture. In Spain it is known as an EIPD.
Data protection officer (DPO)
A data protection officer is the person an organisation designates to inform, advise and monitor compliance with data protection law, and to act as the contact point for the supervisory authority and for data subjects. The role is independent by design: they report to the highest level of management and cannot be instructed on how to do the job.
DORA
DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, applicable since January 2025. Being a regulation it binds directly, without national transposition, and it is the only European framework that obliges some entities to undergo threat-led penetration testing on a fixed cycle.
e-Government
e-Government is the delivery of administrative and public services through digital channels. It makes public services faster to reach, and it concentrates citizen data and identity in systems that have to hold.
ENS
In Spanish security regulation, the ENS (Esquema Nacional de Seguridad) is the mandatory security framework for the public sector and its suppliers, established by Royal Decree 311/2022. It sets security requirements by category, and it exists to raise the baseline of public-sector systems, which is a different thing from any single test of one of them.
ENS security categories
In Spanish public-sector security, the ENS security categories are the levels (basic, medium and high) that set how much protection a system needs under the Esquema Nacional de Seguridad. The category is what actually decides an assessment’s scope and cost, and the difference between a self-declaration and a certified conformity.
EU AI Act
In EU regulation, the EU AI Act governs artificial intelligence systems placed on or used in the European market, taking a risk-based approach: obligations rise with the risk a system poses. For certain systems it turns AI security testing from optional into an obligation, which is where the AI-security and European-regulation strands meet.
ISMS
In security governance, an ISMS (information security management system) is the framework of policies, processes and controls through which an organisation manages security risk continuously. It is the object that ISO 27001 certifies: the standard does not certify a checklist of controls, it certifies that you run a working management system around them.
ISO 27001
In security governance, ISO/IEC 27001:2022 is the international standard for an information security management system: a framework for managing security risk, not a checklist of controls. The edition is the point a client asks about first. The 2022 revision reorganised Annex A into ninety-three controls grouped in four themes, and it is the current version.
Licence agreement
A licence agreement is the contract that sets out the terms on which software, an application or an online service may be used. In security work it is where the limits on use, the data handling obligations and the liability caps actually live.
LOPDGDD
The LOPDGDD is Ley Orgánica 3/2018, of 5 December, on the protection of personal data and the guarantee of digital rights. It is the Spanish law that adapts the GDPR to national law, exercising the margins the regulation leaves to member states and adding a set of digital rights of its own.
PCI DSS
In payment security, PCI DSS is the standard that sets security requirements for organisations that store, process or transmit cardholder data. It is what obliges many businesses to run penetration tests on a fixed cadence, and it explains why tokenisation reduces scope, which makes it a direct bridge between compliance and commissioning a test.
Personal data (GDPR)
In EU data protection, personal data is any information relating to an identified or identifiable person, as defined in article 4 of the GDPR. It is the canonical concept in Spain and the EU, and it is broader than the US term PII: it covers online identifiers, IP addresses, cookies and pseudonymised data that can still be linked back.
Privacy
Privacy is the protection of personal and sensitive information against unauthorised access, misuse or disclosure. It is the principle; the GDPR is the law that turns it into obligations, and personal data is what both apply to.
Right to be forgotten
The right to be forgotten is the right of an individual to ask that personal information about them be erased or delisted, and to have that request assessed.
Risk analysis
Risk analysis is the structured assessment of the risks affecting an organisation’s assets, systems and operations, so that decisions about them can be made on evidence rather than instinct.
Risk model
A risk model is the structure an organisation uses to value risk: what counts as an asset, how likelihood and impact are scored, and above which threshold a risk gets treated rather than accepted.
Security audit
A security audit is a systematic review of the security controls protecting a system, network, application or infrastructure, to find weaknesses, check that policy is being followed and recommend what to improve.
Security compliance
In security governance, security compliance is the act of demonstrating, to auditors and regulators, that an organisation meets a defined set of controls. It is necessary, but it is not the same as being secure: a system can pass an audit and still be exploitable, which is precisely the gap an offensive assessment measures.
SOC 2
In security governance, SOC 2 is a US attestation, based on the Trust Services Criteria, that reports on the controls a service organisation operates. It is what a US customer asks a Spanish software company to provide, and it usually arrives as a question alongside ISO 27001, which makes the two a natural comparison.
Statement of Applicability
The Statement of Applicability is the document, required by ISO/IEC 27001, that lists the Annex A controls, states whether each is applicable, justifies every inclusion and every exclusion, and records its implementation status. It is the first artefact an auditor asks for and the one that most often fails to survive scrutiny.