Supplier Cybersecurity Guidelines
ENEC is committed to maintaining a secure, resilient, and trusted operating environment. Suppliers, contractors, and service providers are expected to implement appropriate cybersecurity measures to safeguard information, systems, and services throughout their engagement with ENEC.
Suppliers working with ENEC are expected to:
Have Established Cybersecurity Governance and Incident Management processes for identifying, managing, and reporting cybersecurity incidents, including data breaches, data leaks, ransomware events, and other security incidents that could impact the confidentiality, integrity, or availability of information, systems, or services.
Conduct appropriate cybersecurity and information security awareness training to their personnel on a regular basis.
Promptly notify ENEC of any cybersecurity incident, data breach, suspected compromise, or security event that may affect ENEC information, systems, services, operations, or business interests.
Establish and maintain effective cybersecurity controls that align with recognized industry standards and best practices throughout the design, development, delivery, operation, support, and maintenance of products and services provided to ENEC.
Protect ENEC information and assets from unauthorized access, disclosure, modification, destruction, loss, or misuse, and ensure that such information is appropriately handled, stored, transmitted, retained, and disposed of in a secure manner.
Obtain prior written authorization from ENEC before sharing, disclosing, publishing, or referencing any ENEC-related information, data, projects, or services with third parties, including the use of ENEC's name, logo, or project references in marketing materials, public communications, case studies, or company portfolios.
Ensure that personnel, subcontractors, and third parties involved in delivering products or services to ENEC comply with applicable cybersecurity, information protection, confidentiality, and contractual requirements. Suppliers should also implement appropriate personnel screening and background verification processes where permitted by applicable laws and regulations.
Maintain an effective information security management program that includes, at a minimum, risk management, access control, asset management, vulnerability management, security monitoring, incident response, business continuity, and disaster recovery capabilities.
Comply with all applicable legal, regulatory, contractual, and industry cybersecurity requirements, standards, and obligations relevant to the services, products, or activities being provided to ENEC.
Cooperate with cybersecurity assurance activities and, where requested, demonstrate compliance with applicable security requirements through assessments, audits, certifications, attestations, testing, or other verification mechanisms as part of supplier onboarding, engagement, and ongoing assurance processes.
By working with ENEC, suppliers acknowledge the importance of protecting information and operational assets and are expected to maintain cybersecurity practices commensurate with the nature, criticality, and risk profile of the services they provide.
