> epdk_siber_güvenlik_modeli:2024
EPDK Siber Güvenlik Modeli:2024
EMRA Cybersecurity Competency Model for the Energy Sector
The EMRA (EPDK) Cybersecurity Competency Model establishes a mandatory, audited cybersecurity framework for energy utilities across Türkiye. Mandating compliance with international standards (IEC 62443, ISO/IEC 27019, NIST CSF), it classifies critical industrial control infrastructure, enforces Purdue model segmentation between SCADA and corporate IT, mandates multi-factor authentication for maintenance jumpboxes, and requires annual third-party penetration testing.
Scope & Applicability
Licensed electricity generation, transmission, and distribution companies, natural gas network operators, petroleum pipeline managers, and critical power market participants in Türkiye.
Non-Coverage Boundaries
Does not replace statutory consumer billing regulations or physical security guards; it focuses strictly on IT, OT, SCADA, telecontrol, and AMR cybersecurity resilience.
Key Clauses & Control Requirements
Utility Categorization & Target Maturity Tier (Seviye Belirleme)
Categorizing energy assets into Level 1, 2, or 3 based on megawatt capacity and customer count, establishing minimum mandatory technical security controls.
Purdue IT/OT Network Segmentation (Ağ İzolasyonu)
Strict prohibition of direct routing between corporate enterprise networks and SCADA/DCS networks; mandatory Industrial DMZ with jumpbox MFA.
Independent Third-Party Auditing (TSE Onaylı Denetim)
Mandatory annual independent penetration testing and gap assessment conducted by certified firms, with results submitted directly to EMRA.
Required Regulatory & Audit Evidence Artifacts
- [✓]EPDK Target Maturity Self-Assessment and Gap Analysis Report
- [✓]Network Architecture Diagram showing physical/logical separation between OT and Corporate IT
- [✓]Annual TSE-Certified Penetration Testing Report with remediation evidence
- [✓]SCADA remote access jumpbox MFA authentication logs and session recordings
“In energy utilities, an unsegmented PLC connected to an office PC is not just an IT risk; it is an immediate regulatory violation under EPDK that risks statutory operating license suspension.”
Cross-Surface Ecosystem Relationships
- EPDK Enerji Sektöründe Siber Güvenlik Yetkinlik Modeli Yönetmeliği ↗(Enerji Piyasası Düzenleme Kurumu)
Frequently Asked Questions
Does the EPDK model apply to privately owned solar or wind plants?
Yes, all licensed grid-connected generation facilities exceeding statutory MW thresholds must implement the model based on their assigned tier.
