
ISO 27019:2024
ISO 27019:2024 Information security, cybersecurity and privacy protection – Information security controls for the energy utility industry
CDN $336.00
Description
This document provides information security controls for the energy utility industry, based on ISO/IEC 27002:2022, for controlling and monitoring the production or generation, transmission, storage and distribution of electric power, gas, oil and heat, and for the control of associated supporting processes. This includes in particular the following:
–¬†¬†¬† central and distributed process control, monitoring and automation technology as well as information systems used for their operation, such as programming and parameterization devices;
–¬†¬†¬† digital controllers and automation components such as control and field devices or programmable logic controllers (PLCs), including digital sensor and actuator elements;
–¬†¬†¬† all further supporting information systems used in the process control domain, e.g. for supplementary data visualization tasks and for controlling, monitoring, data archiving, historian logging, reporting and documentation purposes;
–¬†¬†¬† communication technology used in the process control domain, e.g. networks, telemetry, telecontrol applications and remote-control technology;
–¬†¬†¬† Advanced metering infrastructure (AMI) components, e.g. smart meters;
–¬†¬†¬† measurement devices, e.g. for emission values;
–¬†¬†¬† digital protection and safety systems, e.g. protection relays, safety PLCs, emergency governor mechanisms;
–¬†¬†¬† energy management systems, e.g. for distributed energy resources (DER), electric charging infrastructures, and for private households, residential buildings or industrial customer installations;
–¬†¬†¬† distributed components of smart grid environments, e.g. in energy grids, in private households, residential buildings or industrial customer installations;
–¬†¬†¬† all software, firmware and applications installed on above-mentioned systems, e.g. distribution management system (DMS) applications or outage management systems (OMS);
–¬†¬†¬† any premises housing the abovementioned equipment and systems;
–¬†¬†¬† remote maintenance systems for abovementioned systems.
This document does not apply to the process control domain of nuclear facilities. This domain is covered by IEC 63096.
Edition
2
Published Date
2024-10-18
Status
PUBLISHED
Pages
39
Format 
Secure PDF
Secure – PDF details
- Save your file locally or view it via a web viewer
- Viewing permissions are restricted exclusively to the purchaser
- Device limits - 3
- Printing – Enabled only to print (1) copy
See more about our Environmental Commitment
Abstract
This document provides information security controls for the energy utility industry, based on ISO/IEC 27002:2022, for controlling and monitoring the production or generation, transmission, storage and distribution of electric power, gas, oil and heat, and for the control of associated supporting processes. This includes in particular the following:
-    central and distributed process control, monitoring and automation technology as well as information systems used for their operation, such as programming and parameterization devices;
-    digital controllers and automation components such as control and field devices or programmable logic controllers (PLCs), including digital sensor and actuator elements;
-    all further supporting information systems used in the process control domain, e.g. for supplementary data visualization tasks and for controlling, monitoring, data archiving, historian logging, reporting and documentation purposes;
-    communication technology used in the process control domain, e.g. networks, telemetry, telecontrol applications and remote-control technology;
-    Advanced metering infrastructure (AMI) components, e.g. smart meters;
-    measurement devices, e.g. for emission values;
-    digital protection and safety systems, e.g. protection relays, safety PLCs, emergency governor mechanisms;
-    energy management systems, e.g. for distributed energy resources (DER), electric charging infrastructures, and for private households, residential buildings or industrial customer installations;
-    distributed components of smart grid environments, e.g. in energy grids, in private households, residential buildings or industrial customer installations;
-    all software, firmware and applications installed on above-mentioned systems, e.g. distribution management system (DMS) applications or outage management systems (OMS);
-    any premises housing the abovementioned equipment and systems;
-    remote maintenance systems for abovementioned systems.
This document does not apply to the process control domain of nuclear facilities. This domain is covered by IEC 63096.
Previous Editions
Can’t find what you are looking for?
Please contact us at:
Related Documents
-

ISO 20009:2022 Information security – Anonymous entity authentication – Part 3: Mechanisms based on blind signatures
CDN $186.00 Add to cart -

ISO 18180:2013 Information technology – Specification for the Extensible Configuration Checklist Description Format (XCCDF) Version 1.2
CDN $0.00 Add to cart -

ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection – Information security management systems – Requirements
CDN $288.00 Add to cart -

ISO 22739:2024 Blockchain and distributed ledger technologies – Vocabulary
CDN $186.00 Add to cart







