IT Security Framework for EnergyDataDK (ISO27001)

Introduction

PowerLabDK/EnergyDataDK has based its information security work on DTU’s IT security policies and the guidelines of DTU Wind and Energy Systems. DTU’s overarching IT security policies are based on the ISO 27001 standard, and the IT security work for EnergyDataDK reflects this.
DTU Security Operations establishes the overall objectives for IT security, defines formal roles and their areas of responsibility and key concepts, and sets out a classification scale, etc., while DTU’s departments play an implementation and advisory role.

Topic-specific IT security policies

DTU has decided to implement security measures—as outlined in ISO 27001 Annex A and further detailed in ISO 27002—through a series of topic-specific IT security policies, and has established requirements that must be met to ensure compliance with DTU’s information security policy.

For EnergyDataDK, a number of topic-specific policies have been identified as relevant for compliance. These include:

  • Classification and management
  • Identity and access management
  • System operations
  • Logging
  • Backup and restore
  • Software maintenance (patch management)
  • Business continuity

Reference to ISO 27002 controls

The requirements arising from the designated topic-specific policies comprise, in aggregate, the following ISO 27002 controls for EnergyDataDK:

Classification and management:

  • Information security in projects
  • Inventory of information and supporting assets
  • Acceptable use of information and supporting assets
  • Information labelling
  • Information transfer
  • Information security awareness, education and training
  • Data leakage prevention

Identity and access management:

  • Segregation of duties
  • Return of assets
  • Access management
  • Identity management
  • Authentication information
  • Access rights
  • Responsibilities regarding termination or change of employment
  • Privileged access rights
  • Restricted access to information
  • Secure authentication
  • Use of privileged utility programs

System Operations

  • Documented operating procedures
  • Capacity management
  • Configuration management
  • Information deletion
  • Clock synchronization
  • Use of privileged utility programs
  • Separation of development, test, and production environments
  • Change management
  • Protection of information systems during audit

Logging

  • Logging
  • Activity monitoring

Backup and restoration

  • Backup of information

Patch management

  • Management of technical vulnerabilities

Continuous operations

  • Information security during service disruptions
  • ICT readiness for business continuity
  • Security of supply
  • Capacity management
  • Redundancy of information processing facilities

Responsibility, compliance, control, and auditing

Compliance with the topic-specific IT security policies is primarily the responsibility of the information asset or system owner. Documents prepared in connection with the compliance assessment for EnergyDataDK document how the relevant topic-specific IT security policies have been implemented. For EnergyDataDK, there are also three procedure descriptions that detail the practical implementation of the relevant policies. These cover:
  1. Backup and restore procedure
  2. Identity and Access Management
  3. Operation and maintenance
DTU uses the ‘Control Manager’ ISMS system to manage and document the updating of policies, procedure descriptions, and periodic checks. EnergyDataDK is registered as a system within DTU Wind and Energy Systems and is thus included in this shared management process. Internal control, auditing, and overall compliance with DTU’s IT security policy are also integrated into DTU’s overarching risk and vulnerability assessment processes.

GDPR, NIS 2, and other DTU policies and guidelines

A number of relevant stakeholders at DTU were involved in the development of DTU’s IT security policy. The aim was to ensure that the policy, as far as possible, also addresses the requirements and needs set out in DTU’s other policies and guidelines, including the personal data policy (GDPR) and NIS 2.

DTU currently bases its implementation of the NIS 2 Directive on the aforementioned IT security policy and the associated Information Security Management System (ISMS).

However, DTU’s IT security policy does not guarantee compliance with other DTU policies; EnergyDataDK therefore works separately on compliance with other policies and legal requirements, including GDPR and the Data Regulation.