|Title||Information technology — Security techniques — Information security controls for the energy utility industry|
|Committee||ISO/IEC JTC 1/SC 27 INFORMATION SECURITY, CYBERSECURITY AND PRIVACY PROTECTION|
ISO/IEC 27019:2017 provides guidance based on ISO/IEC 27002:2013 applied to process control systems used by the energy utility industry for controlling and monitoring the production or generation, transmission, storage and distribution of electric power, gas, oil and heat, and for the control of associated supporting processes. This includes in particular the following:
– digital protection and safety systems, e.g. protection relays, safety PLCs, emergency governor mechanisms;
– energy management systems, e.g. of Distributed Energy Resources (DER), electric charging infrastructures, in private households, residential buildings or industrial customer installations;
– distributed components of smart grid environments, e.g. in energy grids, in private households, residential buildings or industrial customer installations;
– all software, firmware and applications installed on above-mentioned systems, e.g. DMS (Distribution Management System) applications or OMS (Outage Management System);
– any premises housing the above-mentioned equipment and systems;
– remote maintenance systems for above-mentioned systems.
ISO/IEC 27019:2017 does not apply to the process control domain of nuclear facilities. This domain is covered by IEC 62645.
ISO/IEC 27019:2017 also includes a requirement to adapt the risk assessment and treatment processes described in ISO/IEC 27001:2013 to the energy utility industry-sector?specific guidance provided in this document.