Overview
EN ISO/IEC 27019:2025 (aligned with ISO/IEC 27019:2024) provides sector-specific information security, cybersecurity and privacy protection controls tailored to the energy utility industry. Published by CEN and based on ISO/IEC 27002:2022, the standard addresses controls for the production/generation, transmission, storage and distribution of electric power, gas, oil and heat - including associated supporting processes and operational technology (OT) environments.
Key topics and technical requirements
The document structures controls into clear domains and energy-specific (ENR) additions. Key technical topics include:
-
Organizational controls
- Policies, roles and responsibilities, segregation of duties
- Threat intelligence, supplier and ICT supply chain security
- Asset inventory, classification, labelling and information transfer
-
People controls
- Screening, training, awareness, remote working and disciplinary processes
-
Physical controls
- Securing control centres, equipment rooms, peripheral sites
- Physical perimeters, access control, environment and cabling protection
- Secure disposal and storage media controls
-
Technological controls
- Identity and access management, privileged access, authentication
- Endpoint protection, malware defences, vulnerability and configuration management
- Data backup, deletion, masking and data leakage prevention
-
Incident and continuity
- Incident management planning, evidence collection, learning and business continuity readiness for ICT/OT
-
Compliance and assurance
- Legal/regulatory requirements, independent review, documented procedures
The standard includes energy-sector-specific controls (ENR) such as securing control centres, interconnected control systems and customer-facing security considerations.
Practical applications and who should use it
EN ISO/IEC 27019 is practical for organizations that need to apply ISO-class information security controls in energy contexts:
- Energy utilities and grid operators (electricity, gas, oil, heat)
- IT and OT security teams responsible for control systems and SCADA environments
- Compliance officers and internal auditors implementing ISMS aligned with ISO/IEC 27001/27002
- System integrators, suppliers and cloud providers delivering services to energy operators
- Incident response teams and business continuity planners for energy operations
Use cases include designing secure control centres, managing supplier/ICT supply chain risks, implementing privileged access for OT, and developing incident response playbooks specific to energy infrastructure.
Related standards
Keywords: EN ISO/IEC 27019:2025, ISO/IEC 27019:2024, information security controls, energy utility industry, cybersecurity, OT security, control centres, supplier security, ISMS.