Skip to content

Evidence request lists

API 1164

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

API 1164: Access Management

API1164-06
Access Control

Implement least-privilege identity and access management for SCADA users, engineers, vendors, and service accounts.

Artefacts an auditor will ask for
  • access matrix
  • joiner-mover-leaver records
  • privileged account inventory
  • quarterly recerts
Where this commonly fails
  • shared HMI accounts
  • no vendor account expiry
API1164-07
Remote Access

Control remote access to pipeline SCADA via authenticated jump hosts, MFA, session monitoring, and approval workflow.

Artefacts an auditor will ask for
  • jump host config
  • MFA logs
  • approval tickets
  • session recordings
Where this commonly fails
  • MFA missing for engineers
  • no session recording
API1164-08
Configuration Management

Manage baseline configurations of SCADA devices with change control, version tracking, and unauthorized-change detection.

Artefacts an auditor will ask for
  • baseline configs
  • change tickets
  • drift reports
  • approval evidence
Where this commonly fails
  • no baselines for PLCs
  • undetected changes
API1164-09
Patch and Vulnerability Management

Identify, evaluate, and apply patches and compensating controls to SCADA assets following risk-based prioritization.

Artefacts an auditor will ask for
  • vulnerability scans
  • patch schedule
  • exception register
  • mitigation evidence
Where this commonly fails
  • legacy systems unpatched without compensating controls
API1164-10
Malware Protection

Deploy malware protections on SCADA endpoints and removable media controls considering availability requirements.

Artefacts an auditor will ask for
  • AV deployment list
  • update logs
  • USB control policy
Where this commonly fails
  • AV missing on engineering workstations

API 1164: Asset Identification & Governance

API1164-01
Scope and Applicability

Establish scope of the pipeline SCADA security program covering control systems, supporting infrastructure, and connected business systems.

Artefacts an auditor will ask for
  • program charter
  • asset boundary diagram
  • applicability statement
Where this commonly fails
  • business-to-OT boundaries undefined
  • scope excludes safety systems
API1164-02
Risk Management Framework

Operate a documented risk management process for pipeline SCADA addressing identification, analysis, evaluation, and treatment of cyber risks.

Artefacts an auditor will ask for
  • risk register
  • threat model
  • risk acceptance records
  • treatment plan
Where this commonly fails
  • no OT-specific threat model
  • no risk acceptance authority
API1164-03
Governance and Roles

Define cyber security governance with executive sponsorship, accountable roles, segregation of duties, and program oversight for pipeline SCADA.

Artefacts an auditor will ask for
  • org chart
  • RACI
  • executive briefings
  • policy approval records
Where this commonly fails
  • no executive sponsor
  • RACI conflates OT and IT roles
API1164-04
Asset Inventory

Maintain a current inventory of SCADA assets including controllers, RTUs, HMIs, network devices, and software with criticality classification.

Artefacts an auditor will ask for
  • asset database
  • criticality ratings
  • firmware versions
  • update cadence
Where this commonly fails
  • RTUs not inventoried
  • firmware versions stale
API1164-05
Network Segmentation and Zones

Apply zone and conduit architecture separating IT, OT, safety, and external networks with documented data flows and enforcement points.

Artefacts an auditor will ask for
  • network diagrams
  • zone-conduit register
  • firewall rule reviews
  • DMZ design
Where this commonly fails
  • flat network with no enforcement
  • DMZ bypasses

API 1164: Incident Response & Recovery

API1164-16
Supply Chain and Third Party

Manage cyber risk from vendors, integrators, and OEM equipment supplying pipeline SCADA components and services.

Artefacts an auditor will ask for
  • vendor security questionnaires
  • contract clauses
  • SBOM intake
  • integrator oversight
Where this commonly fails
  • no SBOM intake
  • contract clauses missing
API1164-17
Wireless and Field Communications

Protect wireless, cellular, satellite, and radio links carrying SCADA traffic with encryption, authentication, and integrity.

Artefacts an auditor will ask for
  • link inventory
  • crypto module list
  • key management procedures
Where this commonly fails
  • legacy radio without authentication
API1164-18
Field Device Security

Apply hardening, authenticated commands, and tamper resistance to field devices including RTUs, PLCs, and meters.

Artefacts an auditor will ask for
  • hardening standards
  • factory default review
  • tamper logs
Where this commonly fails
  • default credentials in field
  • unauthenticated command channels
API1164-19
Safety Instrumented Systems Interface

Protect interfaces between SCADA and Safety Instrumented Systems to prevent cyber events from impairing safety functions.

Artefacts an auditor will ask for
  • SIS interface diagram
  • one-way gateway evidence
  • change isolation procedures
Where this commonly fails
  • bidirectional SIS write paths
API1164-20
Program Review and Continuous Improvement

Periodically review and improve the SCADA security program through assessments, internal audits, and management review.

Artefacts an auditor will ask for
  • assessment reports
  • internal audit findings
  • management review minutes
  • CAP
Where this commonly fails
  • no annual program review

API 1164: Supply Chain & Configuration

API1164-21
TSA Pipeline Security Directive Alignment

Align SCADA security controls with applicable TSA pipeline security directives and cyber incident reporting requirements.

Artefacts an auditor will ask for
  • TSA SD compliance matrix
  • CISA reporting evidence
  • designated cyber coordinator records
Where this commonly fails
  • no SD compliance matrix
API1164-22
Configuration management for OT systems

Configuration management for OT systems. Control from API 1164 framework, domain: API 1164: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • OT asset inventory with classification and ownership
  • Configuration baseline standards for SCADA and ICS components
  • Change management records for OT environment
  • Vulnerability assessment reports for critical pipeline systems
  • Network segmentation diagrams between IT and OT zones
  • Patch management exception register with risk acceptance
Where this commonly fails
  • OT asset inventory incomplete or stale
  • Patch management exceptions without documented risk acceptance
  • Change management not consistently applied to OT systems
  • Vulnerability scanning frequency insufficient for criticality
API1164-23
Change management procedures

Change management procedures. Control from API 1164 framework, domain: API 1164: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • OT asset inventory with classification and ownership
  • Configuration baseline standards for SCADA and ICS components
  • Change management records for OT environment
  • Vulnerability assessment reports for critical pipeline systems
  • Network segmentation diagrams between IT and OT zones
  • Patch management exception register with risk acceptance
Where this commonly fails
  • OT asset inventory incomplete or stale
  • Patch management exceptions without documented risk acceptance
  • Change management not consistently applied to OT systems
  • Vulnerability scanning frequency insufficient for criticality
API1164-24
Vulnerability assessment for critical systems

Vulnerability assessment for critical systems. Control from API 1164 framework, domain: API 1164: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • OT asset inventory with classification and ownership
  • Configuration baseline standards for SCADA and ICS components
  • Change management records for OT environment
  • Vulnerability assessment reports for critical pipeline systems
  • Network segmentation diagrams between IT and OT zones
  • Patch management exception register with risk acceptance
Where this commonly fails
  • OT asset inventory incomplete or stale
  • Patch management exceptions without documented risk acceptance
  • Change management not consistently applied to OT systems
  • Vulnerability scanning frequency insufficient for criticality

API 1164: Systems Security

API1164-11
Logging and Monitoring

Collect and review SCADA security logs and operational anomalies to detect potential cyber incidents.

Artefacts an auditor will ask for
  • log sources list
  • SIEM rules
  • review records
  • alert tuning history
Where this commonly fails
  • PLC logs not collected
  • no OT alerting
API1164-12
Incident Response

Maintain an incident response plan covering pipeline SCADA, including coordination with operations, safety, and regulators.

Artefacts an auditor will ask for
  • IR plan
  • Playbooks
  • tabletop after-action reports
  • CISA coordination contacts
Where this commonly fails
  • no OT-specific playbooks
  • no regulator coordination
API1164-13
Business Continuity and Recovery

Maintain continuity and recovery capabilities for SCADA to restore pipeline operations after disruption while preserving safety.

Artefacts an auditor will ask for
  • BCP/DRP
  • backup tests
  • RTO/RPO
  • manual operations procedures
Where this commonly fails
  • backups untested
  • no manual operating procedure
API1164-14
Physical Security

Apply physical protections at control centers, communication sites, and field assets consistent with cyber-physical risk.

Artefacts an auditor will ask for
  • site surveys
  • access logs
  • CCTV inventory
  • tamper detection
Where this commonly fails
  • remote sites lack tamper detection
API1164-15
Personnel Security

Apply screening, role-based training, and awareness for personnel with access to pipeline SCADA.

Artefacts an auditor will ask for
  • screening records
  • training plan
  • completion logs
Where this commonly fails
  • no OT-specific training
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the API 1164 framework page.