What is ISO/IEC 27019:2017?
ISO/IEC 27019 is a standard that provides guidance on information security controls for the energy industry, based on ISO/IEC 27002:2013 controls. It specifically addresses process control systems, also known as ICS-Industrial Control Systems, used by energy supply organizations to monitor and control the generation, transmission, storage, and distribution of various forms of energy, including electricity, gas, oil, and heat, as well as related support processes.
The aim of ISO/IEC 27019 is to extend the ISO/IEC 27000 standards to the areas of ICS and automation technology and to implement ISMS in accordance with the requirements of ISO/IEC 27001 in the energy supply industry from corporate governance to process control level.
Specifically, this scope includes the following systems, applications and components:
- Information systems used for operations such as centralized and distributed process control, monitoring and automation technology, programming and parameter devices,
- Control and field devices, including digital sensors and actuator elements, or digital control devices and automation components such as Programmable Logic Controllers (PLC),
- All other supporting information systems used in EKS areas for additional data visualization tasks and for control, monitoring, data archiving, logging, reporting and documentation purposes,
- General communication technology used in ICS areas such as networking, telemetry, telecontrol applications and remote control technology,
- Advanced Metering Infrastructure (AMI) components such as smart meters
- Measuring instruments used for emission values,
- Digital protection and safety systems such as protection relays, safety PLCs, emergency governor mechanisms
- Distributed Energy Resources (DER), electricity charging infrastructures, energy management systems used in private residential (excluded in the 2013 publication) or industrial customer premises,
- Distributed components of smart grid environments used in power grids, private residential or industrial customer premises,
- All software, firmware and applications installed on the systems mentioned above (such as DMS - Distribution Management System applications or OMS - Outage Management System),
- Any building housing the equipment and systems mentioned above,
- Remote maintenance systems for the systems mentioned above.
What are Critical Infrastructures?
In the "National Cyber Security Strategy and 2013-2014 Action Plan" document published on June 20, 2013, critical infrastructure is defined as "Infrastructures hosting information systems that may cause loss of life, large-scale economic damage, national security vulnerabilities or disruption of public order if the confidentiality, integrity or accessibility of the information they process is compromised."
Pursuant to the Cyber Security Board Decision No. 2 dated 20/06/2013, Critical Infrastructure Sectors are defined as "Electronic Communications", "Energy", "Water Management", "Critical Public Services", "Transportation" and "Banking and Finance" sectors that host critical infrastructures.
Industrial Control Systems, on the other hand, refers to information systems grouped as SCADA (Supervisory Control and Data Acquisition) and Distributed Control Systems (DCS), which are used for industrial processes such as production, product processing and distribution controls through programmable logic controllers, apart from traditional information technologies.
Article 5 of the "Council Directive 2008/114/EU on the Identification of European Critical Infrastructures and the Assessment of the Need to Improve their Security" published in the Official Journal of the EU on 23 December 2008 states that the directive focuses on the energy and transportation sectors and that the information and communication sectors may also be reviewed.
According to the 2016-2019 Cyber Security Strategy, the main risks related to critical infrastructures are as follows:
- Interruption of critical services such as energy, transportation, etc. as a result of denial of service and similar targeted attacks on information systems used by critical infrastructures.
- As a result of targeted attacks on information systems used by public and critical infrastructures; personal information belonging to citizens or confidential information belonging to the public may be captured, disclosed, changed or destroyed by attackers.
- As a result of targeted attacks to obtain trade secrets and know-how of institutions and organizations engaged in research, development and production (private companies, research institutions and defense industry), sensitive or commercially valuable information is captured, disclosed, modified or destroyed by attackers.
According to the 2016 assessment report of the US-based Industrial Control Systems - Cyber Emergency Response Team (ICS-CERT), the six key ICS vulnerabilities that the ICS-CERT team identified and developed recommendations for are as follows:
- Inadequate user access security controls to the hypervisor (VM monitor) host management interface,
- Insecure implementation of remote access,
- Improper use of Virtual Local Area Network (VLAN),
- Weak portable device (Bring-Your-Own-Device - BYOD) security policy for ICS
- Inadequate cloud services security and Service Level Agreements (SLAs) for critical ICS functions,
- In a critical system, the strategy of implementing ICS Network Monitoring, the main security measure for the attacker lifecycle, is insufficient.
Obligations Imposed by EPDK
In December 2014, EPDK updated the following three regulations in line with information security requirements and imposed obligations on licensees to ensure the security of information systems:
- Regulation Amending the Electricity Market License Regulation
- Regulation Amending the Natural Gas Market License Regulation and
- Regulation Amending the Petroleum Market License Regulation
Within the scope of the National Cyber Security Strategy and 2013-2014 Action Plan, the National Cyber Incident Response Center (USOM) was established on May 27, 2013. Within the framework of the said action plan, it was envisaged to establish Cyber Incident Response Teams (Corporate SOME, sectoral SOME) within public institutions and organizations, and EMRA was designated as the sectoral SOME for the energy sector.
According to the 2016-2019 Cyber Security Strategy, 18 strategic objectives were identified for the period of 2016-2019. The objectives aimed to minimize existing risks based on the principles set forth. Among these objectives, there was a plan to create a national critical infrastructure inventory, ensure the security requirements of critical infrastructures are met, and monitor these critical infrastructures by the regulatory bodies (such as EPDK) to which they are connected.
Information Security Standards that Organizations Must Comply with
The ISO/IEC 27001 standard is not sector-specific and can be applied to any organization that aims to establish and maintain an Information Security Management System (ISMS). In the organization that will perform ISO IEC 27001 b certification (energy sector), Annex A mentioned in Clause 6.1.3. Risk Processing and Clause 8. Operation should be perceived as "Annex A and ISO/IEC TR 27019:2015-03".
When the scope of "Corporate Information System and Industrial Control Systems" in the regulations is evaluated together with the information security standards, the following standards should be taken into consideration:
- 27001 to define the general Information Security Management System in organizations and transfer it to document,
- 27002 regarding the measures to be taken in Corporate Information Systems and other assets, including human resources,
- 27002 and 27019 regarding the measures to be taken in Industrial Control Systems (ICS), 27001 Annex A.
In addition, in the ICS Risk Management Process, it would be appropriate to consider NIST 800-82 Controls and Security Architecture Development in terms of efficiency and optimization of applications.
In addition to the ISO/IEC 27002 guide, ISO/IEC 27019 is a guide to the controls that can be implemented for the safety of process control systems used in the energy sector. Originally developed by the German Association of Energy and Water Industries (BDEW), ISO/IEC 27019 is a companion document for those responsible for implementing safety controls for Industrial Control Systems used in the energy sector.
ISO/IEC 27019 is a standard developed for the security of industrial control systems in the energy sector, in addition to the ISO/IEC 27002 guidance. Its main difference from ISO 27001 is that it is a standard for informational purposes and does not include management system requirements.
The objectives and control requirements to be considered in cyber security structuring and audits specific to the energy sector are further detailed in Annex A Extended Control Set of ISO/IEC 27019.
ISO/IEC 27019:2017 Consultancy
As ADEO, we provide ISO/IEC 27019 consultancy services to help companies and businesses prepare for and successfully pass ISO/IEC 27019 audits. We assist with all necessary preparations, and conduct periodic pre-audits to ensure continued compliance following the certification process.
As ADEO, with the ISO/IEC 27019 consultancy we offer, we make all the necessary preparations for companies and businesses to successfully pass ISO/IEC 27019 audits, we periodically carry out pre-audits for the continuation of compliance after the process.