ISO/IEC 27019
ISO/IEC 27019 is a guidance standard that provides information security controls tailored to the energy utility industry, specifically for the systems that control and monitor energy production and distribution. It builds on the general-purpose controls in ISO/IEC 27002 and adapts them to the specialized process control systems used by energy utilities. It is intended to support, rather than replace, the broader ISO/IEC 27001 approach to managing information security.
ISO/IEC 27019 is a sector-specific standard in the ISO/IEC 27000 family that provides information security controls for the energy utility industry, focused on process control systems used to control and monitor the production and distribution of energy. It is derived from and structured on ISO/IEC 27002, with the 2017 edition based on ISO/IEC 27002:2013 and the 2024 edition based on ISO/IEC 27002:2022. The document is targeted at those responsible for operating energy utility process control systems, as well as information security managers, and is typically applied alongside an ISO/IEC 27001 ISMS to inform control selection via the risk assessment and Statement of Applicability. As a guidance standard, ISO/IEC 27019 is not itself an independent certification scheme; its scope is limited to the energy utility sector context, and it should not be conflated with the ISO/IEC 27001 management system requirements (clauses 4-10) or with other sector guidance such as ISO/IEC 27017 or ISO/IEC 27018. Control counts and structure depend on the underlying ISO/IEC 27002 edition and the specific version cited.
Why it matters
Energy utilities operate process control systems that monitor and manage the production and distribution of energy, an environment where the security expectations of specialized operational technology differ meaningfully from those of general corporate IT. ISO/IEC 27019 matters because it adapts the general-purpose information security controls of ISO/IEC 27002 to this specific sector context, giving utility operators and their security managers a reference set of controls framed around the systems they actually run rather than generic guidance alone.
For organizations already pursuing or maintaining an ISO/IEC 27001 ISMS, this sector-specific guidance helps ensure that control selection reflects the realities of the energy utility environment. Because it is derived from and structured on ISO/IEC 27002, it can inform the risk assessment and Statement of Applicability that drive control choices within an ISMS, helping teams avoid gaps that a purely general-purpose control catalogue might leave in a process control setting.
It is important to keep the standard's role in proportion. ISO/IEC 27019 is guidance, not an independent certification scheme, and its scope is limited to the energy utility sector context. It supports rather than replaces the ISO/IEC 27001 management system requirements, and adopting it does not by itself constitute certification or guarantee security outcomes. Its usefulness depends on how well the organization integrates its controls into a broader, risk-driven ISMS.
Who it's relevant to
Inside ISO/IEC 27019
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27019.