What is MAGERIT and how is it used for risk analysis
By Kike Gandia · Co-Founder & CEO, OSCP
MAGERIT (Risk Analysis and Management Methodology for Information Systems) is the reference methodology used by Spain's public sector to assess information system risk. It was developed by the Higher Council for e-Government and is now maintained by the Ministry of Finance; Spain's National Security Framework (ENS) explicitly cites it as the recommended risk analysis framework.
The five security dimensions MAGERIT assesses
MAGERIT values every asset (information, services, applications, equipment, facilities, personnel) across five dimensions: confidentiality, integrity, availability, authenticity and traceability. These are the same five dimensions the ENS uses to classify a system as BASIC, MEDIUM or HIGH — no coincidence: MAGERIT is the risk-analysis engine specifically designed to feed that classification.
How the process works: assets, threats, impact and risk
The process follows a logical sequence: identify assets and their value across each dimension; identify the threats that can affect each asset (human error, technical failure, deliberate attack, natural disaster); estimate the degradation each threat would cause and its likelihood; calculate impact (asset value × degradation) and risk (impact × probability); and finally select the safeguards that reduce that risk to an acceptable level, arriving at the residual risk.
PILAR: the tool that automates MAGERIT
PILAR (Logical-Computer Procedure for Risk Analysis) is the tool developed by Spain's National Cryptologic Centre (CCN) that implements MAGERIT in automated form: it lets you model the asset inventory, apply the five-dimension valuation, calculate impact and risk, and generate the reports submitted as evidence in the ENS certification audit. Its use isn't mandatory, but it's the de facto standard in public-sector ENS projects.
MAGERIT isn't exclusive to the ENS
Although it was created for the public sector, nothing stops you from using MAGERIT as the risk analysis methodology in an ISO 27001 project: the standard requires "a risk assessment process" (clause 6.1.2) without mandating a specific methodology, and MAGERIT satisfies that requirement perfectly. It is a particularly sensible choice for companies that already work with the Public Administration and want to reuse the same risk analysis for both ENS and ISO 27001 instead of duplicating the work with two different methodologies.
What question each dimension answers
The five dimensions sound abstract until they are translated into the concrete question you put to whoever owns each asset. This is the translation used in valuation interviews:
| Dimension | Question asked of the asset owner | Where it usually weighs most |
|---|---|---|
| Confidentiality | What harm is caused if the wrong person sees this information? | Case files with personal data, health records, tax information |
| Integrity | What happens if the data is correct but someone alters it without us noticing? | Population registers, accounting records, administrative decisions |
| Availability | How long can this be down before there are real consequences? | Citizen portals, emergency systems, application processing platforms |
| Authenticity | Can we prove the person who did this was really who they claim to be? | Electronic signature, form submission, privileged access |
| Traceability | Can we reconstruct afterwards who did what, and when? | Any system holding access to third-party data |
Valuation is done by whoever understands the business impact, not by the technical team: the service owner is the one who can say what two days of downtime means, and that answer is what ends up setting the ENS category of the whole system.
What you need in place before starting the analysis
The analysis almost always stalls at the inventory stage, not at the calculation. Before the first session you want: an asset inventory with a named owner for each one — a person, not a department; the dependency map between assets, because value is inherited (a database is worth what the services depending on it are worth, and that is the mechanism most often forgotten); the list of suppliers and which asset each one manages; and the security measures already in place, which in MAGERIT are the existing safeguards and are what determine residual risk. An oversized inventory is as much of a problem as an incomplete one: grouping equivalent assets into types — "workstations", "application servers" — instead of listing them one by one keeps the analysis manageable without losing precision where it matters.
FAQ
Is MAGERIT mandatory to certify under the ENS?
The ENS requires a risk analysis, and MAGERIT is the methodology it cites as the reference, but it doesn't rule out an equivalent methodology if justified. In practice, the vast majority of ENS projects in Spain use MAGERIT because it's the recognized standard and because PILAR greatly simplifies documenting evidence.
Do I need to buy or install PILAR myself?
PILAR is a tool with controlled distribution managed by the CCN, available to public administrations and authorized entities. In a consulting project, it's normally the consultant who has access to the tool and runs the analysis, delivering the generated reports as part of the project.
How long does a MAGERIT risk analysis take?
It depends on the size of the asset inventory, but for a BASIC or MEDIUM category system it usually takes 2-4 weeks within the overall ENS compliance project.
Who values the assets — the technical team or the business?
The business, with technical people alongside. IT knows which systems exist and how they depend on each other, but cannot decide what impact it has on the organisation if a case file is altered or a service is down for two days. When valuation is left entirely to the technical team, results tend towards the extremes — everything critical or everything irrelevant — and the auditor spots it because the valuations do not match the actual service.
How often does the risk analysis need repeating?
At least as often as your own procedure states — annually is the norm — and whenever something changes the premises: a new service, a change of cloud provider, an architecture migration or a significant incident. The analysis is not rebuilt from scratch each time: you revisit the inventory, update the implemented safeguards and recalculate residual risk, which is where you see whether the year's work achieved anything.
What deliverables does a MAGERIT analysis produce?
An asset inventory valued across the five dimensions, a catalogue of applicable threats by asset type, a map of potential risk (before safeguards) and residual risk (after), and the treatment plan listing pending safeguards with an owner and a deadline. That last document is what connects the analysis to the budget: without it, the risk analysis stays a report nobody uses.
Does the same analysis work for NIS2?
As a base, yes. NIS2 requires managing cybersecurity risk with proportionate measures without mandating a methodology, so a well-executed MAGERIT analysis meets that requirement. What has to be added is the directive's own emphasis: supply chain and incident notification obligations, which an ENS-oriented analysis does not always develop in the detail NIS2 expects.