Frameworks · ENS (National Security Framework)
ENS: comply with the public sector’s National Security Framework.
We prepare and support agencies and their providers to comply with the ENS — with the categorization and controls for the required level.
Who it applies to
The ENS applies to public-sector agencies and the companies that provide services to them, according to the category (basic, medium or high) of their systems.
What the framework requires
The ENS requires categorizing systems by level (basic, medium or high) and applying the corresponding controls, with a declaration or certification of conformity as applicable.
Categorization
Levels
Controls
Conformity
Risks of not acting
- Being unable to provide services to the public sector without meeting the ENS.
- Applying controls below the required level.
- Miscategorizing systems and over- or under-scoping.
- Facing conformity audits without evidence.
The i-Prot proposal
We categorize the systems, apply the controls for the corresponding level and prepare the ENS declaration or certification of conformity. Integrated into the CGF cycle.
How we work with this framework
Categorization
Gap analysis
Implementation
Evidence and conformity
Upkeep
Deliverables
- Gap analysis
- Implementation plan
- Controls matrix
- System documentation
- Evidence
- Internal audit
- Management review
- Roadmap
How it connects with CGF
CGF uses the ENS as a source of requirements. This framework mainly covers the Assess, Design, Implement and Operate & measure stages of the cycle.
See the CGF methodology →
Complyze and the ENS
Complyze maintains the categorization, the controls by level and the conformity evidence, with the status visible over time.
Frequently asked questions
Do you need to comply with the ENS?
Tell us your systems and their category, and we’ll define the approach.
By submitting you accept our privacy policy.