Detaljer på forslag

Forslagstitel på sprog (en): Information technology – Security techniques – Information security controls for the energy utility industry
Nummer:DSF/ISO/IEC DIS 27019
Type:Forslag
Kilde:ISO
Udvalg:S-441
Udvalgsnavn:Cyber- og informationssikkerhed
Forslag udgivet:11. sep 2023
Kommentarfrist:10. nov 2023
Antal kommentarer:0
Beskrivelse af forslaget:ISO/IEC 27019:2017 provides guidance based on ISO/IEC 27002:2013 applied to process control systems used by the energy utility industry for controlling and monitoring the production or generation, transmission, storage and distribution of electric power, gas, oil and heat, and for the control of associated supporting processes. This includes in particular the following: - central and distributed process control, monitoring and automation technology as well as information systems used for their operation, such as programming and parameterization devices; - digital controllers and automation components such as control and field devices or Programmable Logic Controllers (PLCs), including digital sensor and actuator elements; - all further supporting information systems used in the process control domain, e.g. for supplementary data visualization tasks and for controlling, monitoring, data archiving, historian logging, reporting and documentation purposes; - communication technology used in the process control domain, e.g. networks, telemetry, telecontrol applications and remote control technology; - Advanced Metering Infrastructure (AMI) components, e.g. smart meters; - measurement devices, e.g. for emission values; - digital protection and safety systems, e.g. protection relays, safety PLCs, emergency governor mechanisms; - energy management systems, e.g. of Distributed Energy Resources (DER), electric charging infrastructures, in private households, residential buildings or industrial customer installations; - distributed components of smart grid environments, e.g. in energy grids, in private households, residential buildings or industrial customer installations; - all software, firmware and applications installed on above-mentioned systems, e.g. DMS (Distribution Management System) applications or OMS (Outage Management System); - any premises housing the above-mentioned equipment and systems; - remote maintenance systems for above-mentioned systems. ISO/IEC 27019:2017 does not apply to the process control domain of nuclear facilities. This domain is covered by IEC 62645. ISO/IEC 27019:2017 also includes a requirement to adapt the risk assessment and treatment processes described in ISO/IEC 27001:2013 to the energy utility industry-sector?specific guidance provided in this document.

Du kan kommentere på alle dele af dette dokument. Forslag vises i ét af to formater:

PDF-version
HTML-version

Hvis du ser indholdsfortegnelsen i venstre side, er det HTML-formatet. For at kommentere skal du åbne de enkelte afsnit ved at klikke på afsnittet i indholdsfortegnelsen.

Hvis du i stedet bliver bedt om at downloade et dokument, er det PDF-formatet. Du skal åbne dokumentet i et separat vindue og derefter kommentere ved at angive afsnitsnummer eller -tekst i "Sektion". Der er mere vejledning, når du har klikket på "Læs forslag".

For at afsende kommentar til Dansk Standard, skal du klikke på "Send kommentar" for det aktuelle afsnit.. Hvis du ønsker at arbejde videre med dine kommentarer, skal du i stedet klikke på "Gem kommentar til senere redigering".

Du kan tilføje og ændre i gemte kommentarer, men hvis du sender kommentaren, kan du ikke vende tilbage for at redigere.

Hvis du har gemte kommentarer, som ikke er afsendt, vil du, før høringsperioden udløber, blive mindet om, at du har ikke-afsendte kommentarer.