CONTACT US

GOVERNANCE RISK AND COMPLIANCE SERVICES

ISO/IEC 27019:2017

What is ISO/IEC 27019:2017?

ISO/IEC 27019 is a standard that provides guidance on information security controls for the energy industry, based on ISO/IEC 27002:2013 controls. It specifically addresses process control systems, also known as ICS-Industrial Control Systems, used by energy supply organizations to monitor and control the generation, transmission, storage, and distribution of various forms of energy, including electricity, gas, oil, and heat, as well as related support processes.

The aim of ISO/IEC 27019 is to extend the ISO/IEC 27000 standards to the areas of ICS and automation technology and to implement ISMS in accordance with the requirements of ISO/IEC 27001 in the energy supply industry from corporate governance to process control level.

Specifically, this scope includes the following systems, applications and components:

What are Critical Infrastructures?

In the "National Cyber Security Strategy and 2013-2014 Action Plan" document published on June 20, 2013, critical infrastructure is defined as "Infrastructures hosting information systems that may cause loss of life, large-scale economic damage, national security vulnerabilities or disruption of public order if the confidentiality, integrity or accessibility of the information they process is compromised."

Pursuant to the Cyber Security Board Decision No. 2 dated 20/06/2013, Critical Infrastructure Sectors are defined as "Electronic Communications", "Energy", "Water Management", "Critical Public Services", "Transportation" and "Banking and Finance" sectors that host critical infrastructures.

Industrial Control Systems, on the other hand, refers to information systems grouped as SCADA (Supervisory Control and Data Acquisition) and Distributed Control Systems (DCS), which are used for industrial processes such as production, product processing and distribution controls through programmable logic controllers, apart from traditional information technologies.

Article 5 of the "Council Directive 2008/114/EU on the Identification of European Critical Infrastructures and the Assessment of the Need to Improve their Security" published in the Official Journal of the EU on 23 December 2008 states that the directive focuses on the energy and transportation sectors and that the information and communication sectors may also be reviewed.

According to the 2016-2019 Cyber Security Strategy, the main risks related to critical infrastructures are as follows:

According to the 2016 assessment report of the US-based Industrial Control Systems - Cyber Emergency Response Team (ICS-CERT), the six key ICS vulnerabilities that the ICS-CERT team identified and developed recommendations for are as follows:

Obligations Imposed by EPDK

In December 2014, EPDK updated the following three regulations in line with information security requirements and imposed obligations on licensees to ensure the security of information systems: 

Within the scope of the National Cyber Security Strategy and 2013-2014 Action Plan, the National Cyber Incident Response Center (USOM) was established on May 27, 2013. Within the framework of the said action plan, it was envisaged to establish Cyber Incident Response Teams (Corporate SOME, sectoral SOME) within public institutions and organizations, and EMRA was designated as the sectoral SOME for the energy sector.

According to the 2016-2019 Cyber Security Strategy, 18 strategic objectives were identified for the period of 2016-2019. The objectives aimed to minimize existing risks based on the principles set forth. Among these objectives, there was a plan to create a national critical infrastructure inventory, ensure the security requirements of critical infrastructures are met, and monitor these critical infrastructures by the regulatory bodies (such as EPDK) to which they are connected.

Information Security Standards that Organizations Must Comply with

The ISO/IEC 27001 standard is not sector-specific and can be applied to any organization that aims to establish and maintain an Information Security Management System (ISMS). In the organization that will perform ISO IEC 27001 b certification (energy sector), Annex A mentioned in Clause 6.1.3. Risk Processing and Clause 8. Operation should be perceived as "Annex A and ISO/IEC TR 27019:2015-03".

When the scope of "Corporate Information System and Industrial Control Systems" in the regulations is evaluated together with the information security standards, the following standards should be taken into consideration: 

In addition, in the ICS Risk Management Process, it would be appropriate to consider NIST 800-82 Controls and Security Architecture Development in terms of efficiency and optimization of applications.

In addition to the ISO/IEC 27002 guide, ISO/IEC 27019 is a guide to the controls that can be implemented for the safety of process control systems used in the energy sector. Originally developed by the German Association of Energy and Water Industries (BDEW), ISO/IEC 27019 is a companion document for those responsible for implementing safety controls for Industrial Control Systems used in the energy sector.

ISO/IEC 27019 is a standard developed for the security of industrial control systems in the energy sector, in addition to the ISO/IEC 27002 guidance. Its main difference from ISO 27001 is that it is a standard for informational purposes and does not include management system requirements.

The objectives and control requirements to be considered in cyber security structuring and audits specific to the energy sector are further detailed in Annex A Extended Control Set of ISO/IEC 27019.

ISO/IEC 27019:2017 Consultancy

As ADEO, we provide ISO/IEC 27019 consultancy services to help companies and businesses prepare for and successfully pass ISO/IEC 27019 audits. We assist with all necessary preparations, and conduct periodic pre-audits to ensure continued compliance following the certification process.

As ADEO, with the ISO/IEC 27019 consultancy we offer, we make all the necessary preparations for companies and businesses to successfully pass ISO/IEC 27019 audits, we periodically carry out pre-audits for the continuation of compliance after the process.
 

Take advantage of maximum cyber security.

Experience the difference between a sense of security and real security.

CONTACT US

Add an ally to your defense

Add an ally to your defense


Experience first-hand how ADEO's 24x7 end-to-end security approach can help you achieve better results. Enhance your security coverage with our team of security experts, who work as an extension of your team, and reduce your risks with their rapid response capabilities. Maximize the value of your current security products by incorporating operational functionality into your telemetry data.

Reduce your average remediation time with our automation, playbooks, and incident response expertise. Take control of all your security alerts by managing, prioritizing, and viewing them from a single dashboard across your entire security infrastructure.