The security controls and assurance arrangements for the end-to-end Smart Metering System are defined in the Smart Energy Code (SEC) and aim to provide confidence to all SEC Parties that the systems and Devices supporting smart metering are appropriately secure.

The SEC Section G7.19 places an obligation on the Security Sub-Committee (SSC): “The Security Sub-Committee shall:

“(g) develop and maintain documents to be known as “SSC Guidance for Device Security Assurance and Triage” which shall set out the SSC’s guidance on the requirements and processes to be followed in respect of Devices (including their triage and refurbishment) in order to:

(i) achieve appropriate levels of security assurance in accordance with the requirement of this Code; and

(ii) obtain and maintain CPA Certification.”

The SSC has therefore developed guidance in 3 parts, SSC Guidance for Device Security Assurance and Triage. Triage Facilities are premises where Triage Activities, defined in SEC Section G12, are undertaken. The SSC clarification in Part 3 Section 2 of the SSC Guidance for Device Security Assurance and Triage explains the scope of assurance in a facility that undertakes Triage of non-Use Case 004 Devices in the form of a Triage Security Controls Framework (TSCF):

Section 1 of the TSCF describes the purpose and what the TSCF aims to achieve; the different types of Security Assessment and their frequency; and the role of the User CIO;

Section 2 of the TSCF provides greater detail at a practical level for the User Assessment lifecycle with information and logistical requirements for how a User should engage with the User CIO; the timeline for User Assessments; and the detailed questions the User CIO might ask, and the evidence it might expect to see from a User to support its assessment.

The SSC Guidance for Device Security Assurance and Triage forms part of the SEC Materials defined in SEC Section M5.1, and the document is regularly reviewed and updated by the SSC. Please refer to the TSCF pages of the website for more detail.

Book your Triage Security assessment

To book your Triage Security assessment please contact the SECAS Security Team at SSC@talan.com.

The Security Validation Workbook V2.5 will be used for the Management Response and Validation stages of the Assessments and will be provided to Users via the secure sharing platform Egress.

If you wish to reschedule or cancel your assessment, you are required to do so at least four weeks prior to the assessment commencement date. After this point a cancellation fee of 25% of the total cost is chargeable. Please note that the CIO are entitled to recover any costs they have incurred relating to an assessment, regardless of the notice provided. Please submit your amendment or cancellation request to SSC@talan.com

Sign Up to SEC Newsletter

By subscribing you consent to receiving the SEC newsletter.

Contact details provided will only be used to send the newsletter and not for any other purpose.

We use a tracking pixel to track engagements with our newsletter. This collects information on your device, the content you opened, and how many times you opened it. You can turn off this tracking by setting your email client to display emails as ‘text only’

The SEC newsletter will be sent bi-monthly and will provide information on SEC updates and events.