API 1164
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
API 1164: Access Management
Implement least-privilege identity and access management for SCADA users, engineers, vendors, and service accounts.
- access matrix
- joiner-mover-leaver records
- privileged account inventory
- quarterly recerts
- shared HMI accounts
- no vendor account expiry
Control remote access to pipeline SCADA via authenticated jump hosts, MFA, session monitoring, and approval workflow.
- jump host config
- MFA logs
- approval tickets
- session recordings
- MFA missing for engineers
- no session recording
Manage baseline configurations of SCADA devices with change control, version tracking, and unauthorized-change detection.
- baseline configs
- change tickets
- drift reports
- approval evidence
- no baselines for PLCs
- undetected changes
Identify, evaluate, and apply patches and compensating controls to SCADA assets following risk-based prioritization.
- vulnerability scans
- patch schedule
- exception register
- mitigation evidence
- legacy systems unpatched without compensating controls
Deploy malware protections on SCADA endpoints and removable media controls considering availability requirements.
- AV deployment list
- update logs
- USB control policy
- AV missing on engineering workstations
API 1164: Asset Identification & Governance
Establish scope of the pipeline SCADA security program covering control systems, supporting infrastructure, and connected business systems.
- program charter
- asset boundary diagram
- applicability statement
- business-to-OT boundaries undefined
- scope excludes safety systems
Operate a documented risk management process for pipeline SCADA addressing identification, analysis, evaluation, and treatment of cyber risks.
- risk register
- threat model
- risk acceptance records
- treatment plan
- no OT-specific threat model
- no risk acceptance authority
Define cyber security governance with executive sponsorship, accountable roles, segregation of duties, and program oversight for pipeline SCADA.
- org chart
- RACI
- executive briefings
- policy approval records
- no executive sponsor
- RACI conflates OT and IT roles
Maintain a current inventory of SCADA assets including controllers, RTUs, HMIs, network devices, and software with criticality classification.
- asset database
- criticality ratings
- firmware versions
- update cadence
- RTUs not inventoried
- firmware versions stale
Apply zone and conduit architecture separating IT, OT, safety, and external networks with documented data flows and enforcement points.
- network diagrams
- zone-conduit register
- firewall rule reviews
- DMZ design
- flat network with no enforcement
- DMZ bypasses
API 1164: Incident Response & Recovery
Manage cyber risk from vendors, integrators, and OEM equipment supplying pipeline SCADA components and services.
- vendor security questionnaires
- contract clauses
- SBOM intake
- integrator oversight
- no SBOM intake
- contract clauses missing
Protect wireless, cellular, satellite, and radio links carrying SCADA traffic with encryption, authentication, and integrity.
- link inventory
- crypto module list
- key management procedures
- legacy radio without authentication
Apply hardening, authenticated commands, and tamper resistance to field devices including RTUs, PLCs, and meters.
- hardening standards
- factory default review
- tamper logs
- default credentials in field
- unauthenticated command channels
Protect interfaces between SCADA and Safety Instrumented Systems to prevent cyber events from impairing safety functions.
- SIS interface diagram
- one-way gateway evidence
- change isolation procedures
- bidirectional SIS write paths
Periodically review and improve the SCADA security program through assessments, internal audits, and management review.
- assessment reports
- internal audit findings
- management review minutes
- CAP
- no annual program review
API 1164: Supply Chain & Configuration
Align SCADA security controls with applicable TSA pipeline security directives and cyber incident reporting requirements.
- TSA SD compliance matrix
- CISA reporting evidence
- designated cyber coordinator records
- no SD compliance matrix
Configuration management for OT systems. Control from API 1164 framework, domain: API 1164: Supply Chain & Configuration.
- OT asset inventory with classification and ownership
- Configuration baseline standards for SCADA and ICS components
- Change management records for OT environment
- Vulnerability assessment reports for critical pipeline systems
- Network segmentation diagrams between IT and OT zones
- Patch management exception register with risk acceptance
- OT asset inventory incomplete or stale
- Patch management exceptions without documented risk acceptance
- Change management not consistently applied to OT systems
- Vulnerability scanning frequency insufficient for criticality
Change management procedures. Control from API 1164 framework, domain: API 1164: Supply Chain & Configuration.
- OT asset inventory with classification and ownership
- Configuration baseline standards for SCADA and ICS components
- Change management records for OT environment
- Vulnerability assessment reports for critical pipeline systems
- Network segmentation diagrams between IT and OT zones
- Patch management exception register with risk acceptance
- OT asset inventory incomplete or stale
- Patch management exceptions without documented risk acceptance
- Change management not consistently applied to OT systems
- Vulnerability scanning frequency insufficient for criticality
Vulnerability assessment for critical systems. Control from API 1164 framework, domain: API 1164: Supply Chain & Configuration.
- OT asset inventory with classification and ownership
- Configuration baseline standards for SCADA and ICS components
- Change management records for OT environment
- Vulnerability assessment reports for critical pipeline systems
- Network segmentation diagrams between IT and OT zones
- Patch management exception register with risk acceptance
- OT asset inventory incomplete or stale
- Patch management exceptions without documented risk acceptance
- Change management not consistently applied to OT systems
- Vulnerability scanning frequency insufficient for criticality
API 1164: Systems Security
Collect and review SCADA security logs and operational anomalies to detect potential cyber incidents.
- log sources list
- SIEM rules
- review records
- alert tuning history
- PLC logs not collected
- no OT alerting
Maintain an incident response plan covering pipeline SCADA, including coordination with operations, safety, and regulators.
- IR plan
- Playbooks
- tabletop after-action reports
- CISA coordination contacts
- no OT-specific playbooks
- no regulator coordination
Maintain continuity and recovery capabilities for SCADA to restore pipeline operations after disruption while preserving safety.
- BCP/DRP
- backup tests
- RTO/RPO
- manual operations procedures
- backups untested
- no manual operating procedure
Apply physical protections at control centers, communication sites, and field assets consistent with cyber-physical risk.
- site surveys
- access logs
- CCTV inventory
- tamper detection
- remote sites lack tamper detection
Apply screening, role-based training, and awareness for personnel with access to pipeline SCADA.
- screening records
- training plan
- completion logs
- no OT-specific training
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the API 1164 framework page.