K.J. George and officials with BESCOM’s ISO/IEC 27001:2022 certificate at Energy Bhavan. Photograph supplied.
Bengaluru: BESCOM has obtained ISO/IEC 27001:2022 certification for its information security management system, putting the focus on identifying digital risks, addressing weaknesses and regularly improving safeguards as electricity operations become increasingly dependent on technology.
The certificate was formally handed over to Minister K.J. George at Energy Bhavan on Wednesday. The Bengaluru Electricity Supply Company said the certification followed coordinated work across its departments and stakeholders, including timely correction of identified shortcomings and checks on implementation.
Protecting information as digital dependence grows
George described the certification as an important step towards strengthening information security and cybersecurity at BESCOM. With the power sector relying more heavily on digital systems, protecting critical information had become essential, he said.
He said the certification reflected the utility’s commitment to adopting internationally recognised information-security practices and strengthening the security of its digital infrastructure.
Explaining the management system, George said it provides a structured approach to identifying information-security risks, implementing appropriate controls, maintaining compliance with security requirements and improving safeguards over time.
Confidentiality, integrity and availability
BESCOM said its information security management system, or ISMS, is intended to strengthen three principles: confidentiality, integrity and availability. These concern protecting information, maintaining its accuracy and ensuring authorised users can access it when required.
The utility said implementing the system across its digital operations would help protect information resources against potential threats. It also expects the measures to support operational efficiency and reduce the risk of financial losses. These are the stated objectives of the security programme.
Correcting gaps and reviewing controls
George said the certification process was completed through cooperation among BESCOM’s departments and stakeholders, with identified gaps corrected and the implementation of corrective measures checked.
BESCOM Managing Director Dr. N. Shivashankar said the system would help identify potential risks and apply the controls needed to address them. It also offers a systematic method for following security measures and improving them when required, he said.
He said these coordinated efforts would further strengthen BESCOM’s digital systems, operations and cybersecurity.
George linked the initiative to the Central Electricity Authority’s 2021 cybersecurity guidelines for the power sector, citing the cybersecurity-policy provisions in Article 1 in explaining the certification exercise.
