COMPLIANCE
National Security Scheme
National Security Scheme (Spanish NSS)
The National Security Scheme (NSS) establishes security controls, which are exhaustively analyzed and guarantee the most demanding security measures.
To implement the Scheme it is necessary:
- Develop a security policy.
- Perform a prior analysis (the criticality of the services and the type of information affected are analyzed) in order to determine the system’s category.
- Conduct a risk analysis, based on an internationally recognized methodology and according to the category of the system.
- Develop an applicability statement that determines which measures are the most effective in reducing the system’s risk, and – once this has been done – the measures adopted must be implemented.
Furthermore, as the National Security Scheme is an information security management system, based on Deming’s continuous improvement cycle, it requires periodic verifications to be carried out. The objective is to ensure that the system is working properly, to identify non-conformities or points for improvement and to implement the necessary measures.