API Standard 1164 Pipeline Control Systems Cybersecurity 3rd Edition
Industry standard for cybersecurity of pipeline SCADA and control systems in the oil and natural gas sector. 12 requirement areas covering risk management, security architecture, access control, system integrity, data protection, monitoring and detection, incident response, business continuity, supply chain security, personnel security, physical security, and compliance assessment. Aligned with NIST CSF and TSA Pipeline Security Directives. Used by pipeline operators for control system cybersecurity programs.
Controls: 88
Total Mappings: 90
Publisher: American Petroleum Institute (API) Version: 3rd Edition (2021) AC (7) AT (3) AU (3) CA (5) CM (6) CP (7) IA (4) IR (6) MP (2) PE (8) PL (1) PM (3) PS (6) RA (6) SA (3) SC (8) SI (4) SR (6)
AC Access Control
AT Awareness and Training
AU Audit and Accountability
CA Security Assessment and Authorization
CM Configuration Management
CP Contingency Planning
IA Identification and Authentication
IR Incident Response
MP Media Protection
PE Physical and Environmental Protection
| Control | Name | API 1164 References |
|---|---|---|
| PE-01 | Policy and Procedures | Sec 14 |
| PE-02 | Physical Access Authorizations | Sec 14 |
| PE-03 | Physical Access Control | Sec 14 |
| PE-04 | Access Control for Transmission | Sec 14 |
| PE-06 | Monitoring Physical Access | Sec 14 |
| PE-08 | Visitor Access Records | Sec 14 |
| PE-09 | Power Equipment and Cabling | Sec 14 |
| PE-11 | Emergency Power | Sec 14 |
PL Planning
| Control | Name | API 1164 References |
|---|---|---|
| PL-08 | Security and Privacy Architectures | Sec 5 |
PM Program Management
PS Personnel Security
RA Risk Assessment
SA System and Services Acquisition
SC System and Communications Protection
| Control | Name | API 1164 References |
|---|---|---|
| SC-07 | Boundary Protection | Sec 5 |
| SC-08 | Transmission Confidentiality and Integrity | Sec 8 |
| SC-12 | Cryptographic Key Establishment and Management | Sec 8 |
| SC-13 | Cryptographic Protection | Sec 8 |
| SC-28 | Protection of Information at Rest | Sec 8 |
| SC-32 | System Partitioning | Sec 5 |
| SC-46 | Cross Domain Policy Enforcement | Sec 5 |
| SC-48 | Sensor Relocation | Sec 9 |
SI System and Information Integrity
SR Supply Chain Risk Management
| Control | Name | API 1164 References |
|---|---|---|
| SR-01 | Policy and Procedures | Sec 12 |
| SR-02 | Supply Chain Risk Management Plan | Sec 12 |
| SR-03 | Supply Chain Controls and Processes | Sec 12 |
| SR-05 | Acquisition Strategies, Tools, and Methods | Sec 12 |
| SR-06 | Supplier Assessments and Reviews | Sec 12 |
| SR-11 | Component Authenticity | Sec 12 |