Skip to main content
Category: Standards and Frameworks

ISO/IEC 27019

Also known as: ISO 27019, ISO/IEC 27019:2024, ISO/IEC 27019:2017
Simply put

ISO/IEC 27019 is a guidance standard that provides information security controls tailored to the energy utility industry, specifically for the systems that control and monitor energy production and distribution. It builds on the general-purpose controls in ISO/IEC 27002 and adapts them to the specialized process control systems used by energy utilities. It is intended to support, rather than replace, the broader ISO/IEC 27001 approach to managing information security.

Formal definition

ISO/IEC 27019 is a sector-specific standard in the ISO/IEC 27000 family that provides information security controls for the energy utility industry, focused on process control systems used to control and monitor the production and distribution of energy. It is derived from and structured on ISO/IEC 27002, with the 2017 edition based on ISO/IEC 27002:2013 and the 2024 edition based on ISO/IEC 27002:2022. The document is targeted at those responsible for operating energy utility process control systems, as well as information security managers, and is typically applied alongside an ISO/IEC 27001 ISMS to inform control selection via the risk assessment and Statement of Applicability. As a guidance standard, ISO/IEC 27019 is not itself an independent certification scheme; its scope is limited to the energy utility sector context, and it should not be conflated with the ISO/IEC 27001 management system requirements (clauses 4-10) or with other sector guidance such as ISO/IEC 27017 or ISO/IEC 27018. Control counts and structure depend on the underlying ISO/IEC 27002 edition and the specific version cited.

Why it matters

Energy utilities operate process control systems that monitor and manage the production and distribution of energy, an environment where the security expectations of specialized operational technology differ meaningfully from those of general corporate IT. ISO/IEC 27019 matters because it adapts the general-purpose information security controls of ISO/IEC 27002 to this specific sector context, giving utility operators and their security managers a reference set of controls framed around the systems they actually run rather than generic guidance alone.

For organizations already pursuing or maintaining an ISO/IEC 27001 ISMS, this sector-specific guidance helps ensure that control selection reflects the realities of the energy utility environment. Because it is derived from and structured on ISO/IEC 27002, it can inform the risk assessment and Statement of Applicability that drive control choices within an ISMS, helping teams avoid gaps that a purely general-purpose control catalogue might leave in a process control setting.

It is important to keep the standard's role in proportion. ISO/IEC 27019 is guidance, not an independent certification scheme, and its scope is limited to the energy utility sector context. It supports rather than replaces the ISO/IEC 27001 management system requirements, and adopting it does not by itself constitute certification or guarantee security outcomes. Its usefulness depends on how well the organization integrates its controls into a broader, risk-driven ISMS.

Who it's relevant to

Energy utility process control operators
The standard is targeted at persons responsible for the operation of process control systems used by energy utilities. These teams can use its controls as a sector-specific reference when securing the systems that control and monitor energy production and distribution, adapting general ISO/IEC 27002 controls to their operational environment.
Information security managers in the energy sector
Information security managers are an explicitly intended audience. They can draw on ISO/IEC 27019 to inform control selection within an ISO/IEC 27001 ISMS, using the risk assessment and Statement of Applicability to justify controls appropriate to energy utility process control systems.
GRC and compliance teams maintaining an ISMS
Teams operating an ISO/IEC 27001 management system in an energy utility context can use ISO/IEC 27019 as supporting guidance rather than a separate certification. They should note that the applicable control structure varies with the edition cited, since the 2017 version rests on ISO/IEC 27002:2013 and the 2024 version on ISO/IEC 27002:2022.

Inside ISO/IEC 27019

Sector-specific guidance
ISO/IEC 27019 provides information security controls guidance tailored to the energy utility industry, addressing process control systems used in the generation, transmission, distribution, and storage of electric power, gas, heat, and related utilities.
Extension of ISO/IEC 27002
The document builds upon and interprets ISO/IEC 27002 controls for the energy utility context, adding sector-specific implementation guidance and, in some cases, additional controls relevant to process control and automation environments. It is guidance rather than a certifiable requirements standard in itself.
Relationship to ISO/IEC 27001
ISO/IEC 27019 is intended to support an ISMS built on the ISO/IEC 27001 requirements (clauses 4 through 10). Organizations in the energy sector may use it to inform control selection and their Statement of Applicability, while certification itself is granted against ISO/IEC 27001.
Process control and operational technology focus
Unlike general-purpose IT guidance, ISO/IEC 27019 addresses considerations specific to operational technology and industrial control environments in energy utilities, where availability and safety concerns often differ from typical enterprise IT settings.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27019.

Is ISO/IEC 27019 a standalone certification standard I can be certified against on its own?
Not on its own. ISO/IEC 27019 provides sector-specific guidance for the energy utility industry and is intended to be applied together with ISO/IEC 27001 and ISO/IEC 27002. Certification is achieved against ISO/IEC 27001, whose certifiable requirements sit in clauses 4 through 10; ISO/IEC 27019 supplements the control guidance rather than replacing the ISMS requirements. You should confirm the precise scope and applicability of 27019 with your certification body, as its role depends on your defined ISMS scope.
Does implementing ISO/IEC 27019 mean I no longer need ISO/IEC 27002?
No. ISO/IEC 27019 does not supersede ISO/IEC 27002; it complements it by offering additional, energy-sector-specific interpretation and guidance. In most implementations the two are used together, with 27019 adding context relevant to process control systems and energy utility operations. Which controls apply is determined through your risk assessment and reflected in the Statement of Applicability, so treat 27019 as supplementary guidance rather than a substitute.
How does ISO/IEC 27019 fit into an existing ISO/IEC 27001 ISMS?
It typically layers onto the ISMS as sector-specific guidance informing control selection and interpretation for energy utility environments. The certifiable ISMS requirements remain those in ISO/IEC 27001 clauses 4 through 10, and control choices continue to flow from risk assessment into the Statement of Applicability. Whether and how 27019 guidance is incorporated depends on your scope and should be agreed with your certification body.
How do I decide which ISO/IEC 27019 guidance applies to my organization?
Applicability is generally driven by your risk assessment and the defined scope of your ISMS, particularly where energy utility process control systems fall within that scope. In most engagements you would evaluate the sector-specific guidance against your identified risks and document the resulting decisions in the Statement of Applicability. Because relevance varies with scope and operating context, confirm the approach with your assessor rather than assuming universal applicability.
Does using ISO/IEC 27019 guarantee that my energy control systems are secure from breaches?
No. Like the broader ISO/IEC 27001 framework it supports, ISO/IEC 27019 helps structure and inform a management system and control set, but it does not guarantee freedom from security incidents. Any resulting ISO/IEC 27001 certificate covers only the defined scope of the ISMS at the time of assessment. Security outcomes depend on how controls are implemented and maintained over time within that scope.
How should I document ISO/IEC 27019-informed controls for an audit?
In most cases, controls informed by ISO/IEC 27019 guidance are documented through the same mechanisms as the rest of the ISMS, principally the risk assessment and the Statement of Applicability, along with supporting policies and evidence of operation. The specific documentation expectations depend on your certification body and defined scope, so confirm what evidence they expect for sector-specific guidance before the assessment.

Common misconceptions

ISO/IEC 27019 is a standalone certification that energy companies can be certified against instead of ISO/IEC 27001.
ISO/IEC 27019 provides sector-specific control guidance and is typically used alongside ISO/IEC 27001, which contains the certifiable ISMS requirements. Certification is granted against ISO/IEC 27001 by an accredited certification body; ISO/IEC 27019 informs control selection rather than serving as the certification basis.
ISO/IEC 27019 replaces ISO/IEC 27002 for energy organizations.
ISO/IEC 27019 extends and interprets ISO/IEC 27002 for the energy utility sector rather than replacing it. It adds context and, in some cases, additional guidance for process control environments, but organizations generally still reference the broader ISO/IEC 27002 control set.
Implementing ISO/IEC 27019 controls guarantees the security of an energy utility's process control systems.
The guidance supports risk-informed control selection but does not guarantee freedom from incidents. Its applicability depends on the defined scope of the ISMS, the organization's risk assessment, and the specific environment, and outcomes vary based on implementation and the certification body's assessment.

Best practices

Treat ISO/IEC 27019 as sector-specific guidance that supports an ISO/IEC 27001-based ISMS rather than as a standalone certification target.
Use ISO/IEC 27019 in conjunction with ISO/IEC 27002 to inform control selection for process control and operational technology environments in the energy sector.
Drive control selection through a documented risk assessment and reflect the chosen controls in the Statement of Applicability, noting where ISO/IEC 27019 guidance was applied.
Clearly define the ISMS scope, distinguishing operational technology and process control systems from general enterprise IT, since certification and applicable guidance depend on that scope.
Confirm the specific edition of ISO/IEC 27019 and its referenced ISO/IEC 27002 version in use, since control guidance and numbering depend on the edition.
Engage stakeholders familiar with both information security and industrial process control to address the availability and safety considerations characteristic of energy utility environments.