There is a number of procedures to report an incident to the CCN-CERT:

  • LUCIA tool for those organizations participating in the National Security Scheme.

  • Via email Incident reporting

    Please write a detailed description of the incident and contact information (at least an email address and a telephone number). In this case, the message needs to be encrypted and identity authenticated. Please find our PGP/GPG key in our web site.

More information

The information below is made up of excerpts from a number of CCN-STIC Guides and incident management related documents. The Security Policy of any organization should comply with these guidelines, and consider the following aspects:

Further information

The CCN-CERT, as the National Government CERT, partners with Spanish public bodies and companies of strategic interest to detect, report, evaluate, counter, handle and learn from information security incidents or cyber incidents that may affect their systems.

Throughout this process —which always ensures strict confidentiality between the parties—, the CCN-CERT provides technical and operational support to detect, react, contain and defeat incidents. A preventive approach is also implemented, and a team of experts investigates the techniques, trends, solutions and the most appropriate procedures to counter incidents, including methodologies to gather and analyze data and events, and procedures to assess the risk level and to determine priority.

The CCN-CERT also operates as a Cyber Incident Information Exchange Node in the Information Systems of the Public Administrations, and as the main coordinator of information exchange among the relevant entities.

As the National Government CERT, it participates in international forums attended by counterparts from a number of countries, which provides it with very valuable information to manage any incident efficiently and swiftly.

CCN-STIC-401 Glossary and abbreviations

Document

Released

Updated

Descargar

CCN-STIC-401 Glosario y Abreviaturas Jul 2014 Ago 2015 Descargar
CCN-STIC-401 Glosario y Abreviaturas (HTML) Jul 2014 Ago 2015 Ver

 

Law 11/2007 of 22 June, on the electronic access of citizens to Public Services established the National Security Scheme, approved by Royal Decree 3/2010 of 8 January, which purpose is to establish the principles and requirements of a security policy regarding the use of electronic means, to allow the adequate protection of information. Subsequently, Law 40/2015, of 1 October, the Legal Regime of the Public Sector, includes the National Security Scheme in Article 156 paragraph 2 in similar terms.

In 2015 the amendment of the National Security Scheme was published by the Royal Decree 951/2015, of 23 October, in response to the changing regulatory environment, in particular the European Union, of information technologies and experience of the implementation of the Scheme.

More information

Ministerio de Defensa
CNI
CCN
CCN-CERT