LEET Security's reference service
The LEET Seal is a label that shows the level of cybersecurity of a rated service.
The LEET Seal gives a "score" to the security measures integrated by the supplier in the construction and operation of the service, unlike other mechanisms that only certify the implementation of management procedures -such as the ISO/IEC 27001 certification– or certifying product characteristics -Certification Common Criteria-, but in no case establish a quantitative assessment nor do they allow organizations to show the security level in a given service regarding the information or data being handled.
In practical terms it is similar to what happens with hotels: They all require an opening license but not all offer the same number of stars. Likewise, an ICT service must also be provided by an authorized company and possibly have an ISO/IEC 27001 certification, but it is the LEET Seal that indicates not only the number of stars, but also separately values their rooms, the restaurant and auxiliary facilities. Higher ratings indicate a lower likelihood of security incidents and, more importantly, a greater ability of the supplier to restore normal service quickly in the event of a disruption.
The entire methodology, evaluation criteria and the registry of services are public, so it provides total transparency when it comes to assess and compare different services when selecting your ICT suppliers.
The rating system managed by LEET Security became the first implementation of the recommendation of the EU Cybersecurity Strategy, to create ICT security labeling systems.
This rating is awarded in three dimensions: Confidentiality, Integrity and Availability, and the LEET Seal shows the assessment obtained by the rated service in each of them based on the security and continuity measures implemented, expressed by three letters, from A+ (corresponding to the highest level) to D (the most basic one).
LEET Security's objective is to facilitate the processes of contracting ICT services by simplifying the evaluation of their security.
LEET Security covers the lack of an objective system that standardizes the criteria and minimizes inequalities in the selection process of companies that compete in the ICT services market, avoiding adverse selection.
Through its seal, the LEET Security agency labels the different ICT services offered by suppliers based on an exhaustive and rigorous evaluation of the security measures they incorporate, the reliability of the supplier and the resilience mechanisms applied.
From the customer's perspective
From the supplier perspective
All users can know the rating levels of a service and have a complaint mechanism in case of non-compliance of the necessary conditions.
The security system, based on supervised self-assessment, reduces the possibility of conflict of interest and sets the responsibility on the side of the supplier of services.
An expert is not required to assess whether the service to be contracted is the appropriate one for the risk profile pursued.
The supervised self-assessment model allows suppliers to enroll without having to face large adaptation costs.
By leveraging widely used standards and a regulatory control rating, ICT service suppliers can avoid repetitive testing of the same controls, following the “audit once, use multiple times” principle.
Developed since 2010 and continuously evolving, LEET Security’s rating system is recognized by the European Agency for Network and Information Security and is registered as a trusted instrument with the National Institute of Cybersecurity (INCIBE).
The rating methodology complies with UNE 71381:2016 Information Technology. Cloud computing. Labelling Systems
Understand and Improve Your Cybersecurity Posture