What is MAGERIT and how is it used for risk analysis

By the QuantumSec team

MAGERIT (Risk Analysis and Management Methodology for Information Systems) is the reference methodology used by Spain's public sector to assess information system risk. It was developed by the Higher Council for e-Government and is now maintained by the Ministry of Finance; Spain's National Security Framework (ENS) explicitly cites it as the recommended risk analysis framework.

The five security dimensions MAGERIT assesses

MAGERIT values every asset (information, services, applications, equipment, facilities, personnel) across five dimensions: confidentiality, integrity, availability, authenticity and traceability. These are the same five dimensions the ENS uses to classify a system as BASIC, MEDIUM or HIGH — no coincidence: MAGERIT is the risk-analysis engine specifically designed to feed that classification.

How the process works: assets, threats, impact and risk

The process follows a logical sequence: identify assets and their value across each dimension; identify the threats that can affect each asset (human error, technical failure, deliberate attack, natural disaster); estimate the degradation each threat would cause and its likelihood; calculate impact (asset value × degradation) and risk (impact × probability); and finally select the safeguards that reduce that risk to an acceptable level, arriving at the residual risk.

PILAR: the tool that automates MAGERIT

PILAR (Logical-Computer Procedure for Risk Analysis) is the tool developed by Spain's National Cryptologic Centre (CCN) that implements MAGERIT in automated form: it lets you model the asset inventory, apply the five-dimension valuation, calculate impact and risk, and generate the reports submitted as evidence in the ENS certification audit. Its use isn't mandatory, but it's the de facto standard in public-sector ENS projects.

MAGERIT isn't exclusive to the ENS

Although it was created for the public sector, nothing stops you from using MAGERIT as the risk analysis methodology in an ISO 27001 project: the standard requires "a risk assessment process" (clause 6.1.2) without mandating a specific methodology, and MAGERIT satisfies that requirement perfectly. It is a particularly sensible choice for companies that already work with the Public Administration and want to reuse the same risk analysis for both ENS and ISO 27001 instead of duplicating the work with two different methodologies.

FAQ

Is MAGERIT mandatory to certify under the ENS?

The ENS requires a risk analysis, and MAGERIT is the methodology it cites as the reference, but it doesn't rule out an equivalent methodology if justified. In practice, the vast majority of ENS projects in Spain use MAGERIT because it's the recognized standard and because PILAR greatly simplifies documenting evidence.

Do I need to buy or install PILAR myself?

PILAR is a tool with controlled distribution managed by the CCN, available to public administrations and authorized entities. In a consulting project, it's normally the consultant who has access to the tool and runs the analysis, delivering the generated reports as part of the project.

How long does a MAGERIT risk analysis take?

It depends on the size of the asset inventory, but for a BASIC or MEDIUM category system it usually takes 2-4 weeks within the overall ENS compliance project.