A meeting in a bright meeting room

ISMS and supplier management for a critical-infrastructure energy provider

ISMS to ISO 27001 in the regulated environment of critical infrastructure.

An energy provider with critical infrastructure is expanding its cybersecurity program. ODCUS owns the ISMS, risk and supplier management in line with the regulatory requirements.

Starting point

As an operator of critical infrastructure, the company must meet an ISMS to ISO 27001 and the ICT minimum standard (BWL/BFE). Assets, protection needs and supplier risks were not captured in a structured way.

Approach

  • Full asset inventory with owner, data classification and protection-need levels
  • Protection-need assessment through guided workshops with the business units
  • Built and operationally maintained an ISMS to ISO 27001
  • Risk analyses and data protection impact assessments (DPIA) under revDSG and GDPR
  • Structured third-party risk management to ISO 27036
  • A binding catalogue of measures, harmonized across ISO 27001 Annex A, the ICT minimum standard and NIST CSF 2.0

Result

  • An audit-ready, lived ISMS with clear roles and control evidence
  • A complete asset and protection-need inventory, documented transparently
  • An established supplier review process with standardized assessments
  • A measurable security organization with KPI reporting

Frameworks and tools used

ISO 27001ICT minimum standardNIST CSF 2.0IEC 62443ISO 27036