PowerLabDK/EnergyDataDK has based its information security work on DTU’s IT security policies and the guidelines of DTU Wind and Energy Systems. DTU’s overarching IT security policies are based on the ISO 27001 standard, and the IT security work for EnergyDataDK reflects this.
DTU Security Operations establishes the overall objectives for IT security, defines formal roles and their areas of responsibility and key concepts, and sets out a classification scale, etc., while DTU’s departments play an implementation and advisory role.
DTU has decided to implement security measures—as outlined in ISO 27001 Annex A and further detailed in ISO 27002—through a series of topic-specific IT security policies, and has established requirements that must be met to ensure compliance with DTU’s information security policy.
For EnergyDataDK, a number of topic-specific policies have been identified as relevant for compliance. These include:
The requirements arising from the designated topic-specific policies comprise, in aggregate, the following ISO 27002 controls for EnergyDataDK:
A number of relevant stakeholders at DTU were involved in the development of DTU’s IT security policy. The aim was to ensure that the policy, as far as possible, also addresses the requirements and needs set out in DTU’s other policies and guidelines, including the personal data policy (GDPR) and NIS 2.
DTU currently bases its implementation of the NIS 2 Directive on the aforementioned IT security policy and the associated Information Security Management System (ISMS).
However, DTU’s IT security policy does not guarantee compliance with other DTU policies; EnergyDataDK therefore works separately on compliance with other policies and legal requirements, including GDPR and the Data Regulation.