Category and scope
We determine if Basic, Medium or High applies and what systems are included.
For organizations that work with public administrations or suppliers that need to order compliance and security in accordance with the ENS.
We convert technical, regulatory and client requirements into prioritized, responsible actions and maintainable evidence.
We determine if Basic, Medium or High applies and what systems are included.
We compare the current situation against expected measures and evidence.
We prioritize measures by risk, impact and dependencies.
We prepare evidence and leave a maintainable system.
Documents and decisions prepared to operate, review and defend before clients, audits or management.
First we understand scope and urgency. We then prioritize gaps by risk, business impact, and effort. Finally we accompany the implementation with evidence and monitoring.
Direct answers before starting.
No. They can be complemented: ENS sets requirements for the public sector and suppliers; ISO 27001 structures the ISMS.
It depends on services, information processed, impact and contractual obligations.
Yes. It is recommended to avoid oversizing measurements.
We give you a brief route with priorities and next steps.