Duyurular
Regulation on Cybersecurity Competency Model in the Energy Sector has been Published
The Regulation on Cybersecurity Competency Model in the Energy Sector (“Regulation”) prepared by the Energy Market Regulatory Authority has been published in the Official Gazette dated June 6, 2023, and numbered 32213.
• The purpose of the Regulation[1] is to regulate the procedures and principles regarding the continuous improvement of the cybersecurity of industrial control systems used in the energy sector in line with evolving needs and threats, defining the minimum acceptable security level, and ensuring the cybersecurity resilience, competence, and maturity of these control systems.
• The Regulation covers the provisions to be applied for organizations consisting of legal entities holding an electricity transmission license, an electricity distribution license, a temporary acceptance and operation license with an installed capacity of 100 MWe or above for each electricity generation facility owner, a natural gas transmission license holder operating a pipeline, a natural gas distribution license holder obligated to establish a shipment control center, a natural gas storage license holder (LNG, underground), a crude oil transmission license holder, and a refining license holder. It excludes OSB distribution license holders and OSB production license holders.
• The competency model addresses the following regulatory and compliance requirements:
- Information and Communication Security Guide
- Security Analysis and Testing Principles and Procedures for Industrial Control Systems Used in the Energy Sector
- TS ISO/IEC 27001
- TS EN ISO/IEC 27019
- EKS security controls in the energy sector
• The competency model varies across energy sub-sectors but generally consists of the following topics: a) Industrial network security; b) Industrial client and server security; c) Industrial threat and vulnerability management; d) Industrial cybersecurity risk management; e) Industrial asset, change, and configuration management; f) Industrial identity and access management; g) Industrial event management and continuity; h) Smart device security; i) Industrial operation security; j) Human resources security; k) Physical security; l) Supplier management; m) PLC security.
• When determining the mandatory control measures to be implemented by obligated organizations, the classification provided in the tables below will be used:
|
Sector |
Minimum Level |
Criticality Level |
|
Electricity Distribution |
Level 2 |
Organization-specific |
|
Natural Gas Distribution |
Level 1 |
Organization-specific |
|
Criticality Level |
Description |
Minimum Level |
|
Class A |
Represents the class of obligated organizations with the highest criticality level in the respective sector. |
Level 3 |
|
Class B |
Represents the class of obligated organizations with moderate criticality levels in the respective sector. |
Level 2 |
|
Class C |
Represents the class of obligated organizations with an expected level of criticality in the respective sector. |
Level 1 |
• The obligation to implement the competency model will begin when the criticality levels are determined by the Authority and notified to obligated organizations. Obligated organizations must achieve full compliance with the obligated control measures at the end of the targeted completion period.
• During self-audit/gap analysis activities, obligated organizations will not be able to conduct sectoral audits with the consulting firm they receive consultancy services from. Consultancy and sectoral audit services cannot be performed through subcontractors. Sectoral audits can be conducted with the same firm for a maximum of three consecutive times.
• Along with this Regulation, the Regulation on Information Security in Industrial Control Systems Used in the Energy Sector published in the Official Gazette dated July 13, 2017, and numbered 30123 has been repealed.
• The Technical Control Measures table for the Cybersecurity Competency Model in the Electricity Distribution Sector is included in the annex of the Regulation.
• The minimum applicable controls for electricity distribution companies have been determined as Level 2.
• The Regulation has entered into force as of the publication date.
You can access the full text of the mentioned Regulation (in Turkish) from here.
Kind regards,
Zumbul Attorneys-at-Law
[1] The Regulation has been prepared based on Article 5, 5/A, and 5/B of the Law No. 4628 dated February 20, 2001, regarding the Organization and Duties of the Energy Market Regulatory Authority.
Türkçe
English