DTU has decided to implement security measures—as outlined in ISO 27001 Annex A and further detailed in ISO 27002—through a series of topic-specific IT security policies, and has established requirements that must be met to ensure compliance with DTU’s information security policy.
For EnergyDataDK, a number of topic-specific policies have been identified as relevant for compliance. These include:
The requirements arising from the designated topic-specific policies comprise, in aggregate, the following ISO 27002 controls for EnergyDataDK: