API1164-01 | Scope and Applicability | 0 |
API1164-02 | Risk Management Framework | 51 |
API1164-03 | Governance and Roles | 0 |
API1164-04 | Asset Inventory | 1 |
API1164-05 | Network Segmentation and Zones | 10 |
API1164-06 | Access Control | 127 |
API1164-07 | Remote Access | 203 |
API1164-08 | Configuration Management | 4 |
API1164-09 | Patch and Vulnerability Management | 124 |
API1164-10 | Malware Protection | 4 |
API1164-11 | Logging and Monitoring | 20 |
API1164-12 | Incident Response | 34 |
API1164-13 | Business Continuity and Recovery | 94 |
API1164-14 | Physical Security | 59 |
API1164-15 | Personnel Security | 1 |
API1164-16 | Supply Chain and Third Party | 2 |
API1164-17 | Wireless and Field Communications | 171 |
API1164-18 | Field Device Security | 179 |
API1164-19 | Safety Instrumented Systems Interface | 171 |
API1164-20 | Program Review and Continuous Improvement | 1 |
API1164-21 | TSA Pipeline Security Directive Alignment | 128 |
API1164-22 | Configuration management for OT systems | 110 |
API1164-23 | Change management procedures | 101 |
API1164-24 | Vulnerability assessment for critical systems | 154 |
DE | Detect (DE): anomalies and events, continuous monitoring, detection processes (Section 8) | 0 |
DE.AE | 8.1 Anomalies and Events (DE.AE) | 0 |
DE.AE-1 | DE.AE-1 Expected data flows across conduits in the baseline configuration | 0 |
DE.AE-2 | DE.AE-2 Audit anomalies analysed to confirm incidents and understand targets and methods | 0 |
DE.AE-3 | DE.AE-3 Event data from multiple sources correlated and analysed | 0 |
DE.AE-4 | DE.AE-4 Event impact determined with consistent criteria and the API 1164 impact assessment | 0 |
DE.AE-5 | DE.AE-5 Incident alert thresholds defined in the incident response plan | 0 |
DE.CM | 8.2 Security Continuous Monitoring (DE.CM) | 0 |
DE.CM-1 | DE.CM-1 Continuous monitoring of conduit ingress and egress, extending into zones at higher profiles | 0 |
DE.CM-2 | DE.CM-2 Physical security events coordinated into IAC monitoring | 0 |
DE.CM-3 | DE.CM-3 Personnel activity monitoring with privacy and civil liberties considered | 0 |
DE.CM-4 | DE.CM-4 Malware risk assessed per environment and detection deployed and updated per vendor practice | 0 |
DE.CM-5 | DE.CM-5 Mobile code risk-assessed, approved and monitored | 0 |
DE.CM-6 | DE.CM-6 External service provider activity monitored locally and remotely | 0 |
DE.CM-7 | DE.CM-7 Monitoring for unauthorised personnel, connections, devices and software | 0 |
DE.CM-8 | DE.CM-8 Automated vulnerability detection in production risk-assessed, approved and used per vendor practice | 0 |
DE.DP | 8.3 Detection Processes (DE.DP) | 0 |
DE.DP-1 | DE.DP-1 Detection roles and responsibilities defined, updated and communicated | 0 |
DE.DP-2 | DE.DP-2 Periodic review that detection mechanisms and processes match the baseline and the plan | 0 |
DE.DP-3 | DE.DP-3 Periodic testing of the design and operating effectiveness of technical and procedural detection controls | 0 |
DE.DP-4 | DE.DP-4 Event detection information communicated to defined stakeholders by authorised personnel | 0 |
DE.DP-5 | DE.DP-5 Continuous improvement of detection processes with lessons learned | 0 |
ID | Identify (ID): governance, risk strategy, business environment, supply chain, risk assessment, asset management (Section 6) | 0 |
ID.AM | 6.6 Asset Management (ID.AM) | 0 |
ID.AM-1 | ID.AM-1 IAC cyber asset inventory with consistent identification, minimum attributes and zone membership | 0 |
ID.AM-2 | ID.AM-2 Software asset catalogue covering essential-function software with dependencies | 0 |
ID.AM-3 | ID.AM-3 Communications and data flows catalogued within zones and across every conduit type | 0 |
ID.AM-4 | ID.AM-4 External cyber assets and dependencies catalogued | 0 |
ID.AM-5 | ID.AM-5 Resource prioritisation by classification, criticality and business value | 0 |
ID.AM-6 | ID.AM-6 Cybersecurity roles and responsibilities documented, allocated and matched to capability | 0 |
ID.BE | 6.3 Business Environment (ID.BE) | 0 |
ID.BE-1 | ID.BE-1 Critical infrastructure supply chain role in risk tolerance and decisions (Enhanced and above) | 0 |
ID.BE-2 | ID.BE-2 Critical infrastructure and industry sector roles in the risk strategy (Enhanced and above) | 0 |
ID.BE-3 | ID.BE-3 Mission, objectives and activity priorities drive roles, risk decisions and training | 0 |
ID.BE-4 | ID.BE-4 Essential functions for critical service delivery catalogued (Enhanced and above) | 0 |
ID.BE-5 | ID.BE-5 A risk-based critical services resiliency plan (Enhanced and above) | 0 |
ID.GV | 6.1 Governance (ID.GV) | 0 |
ID.GV-1 | ID.GV-1 IAC cybersecurity plan governance, performance measurement and review | 0 |
ID.GV-2 | ID.GV-2 Cybersecurity roles and responsibilities coordinated across stakeholders and boundaries | 0 |
ID.GV-3 | ID.GV-3 Legal and regulatory requirements catalogued, used in risk decisions and communicated | 0 |
ID.GV-4 | ID.GV-4 Governance and risk management of IAC cyber risk aligned with enterprise governance | 0 |
ID.RA | 6.5 IAC Risk Assessment (ID.RA) | 0 |
ID.RA-1 | ID.RA-1 Vulnerability catalogue with consistent identification, categorisation and control effectiveness assessment | 0 |
ID.RA-2 | ID.RA-2 Threat intelligence catalogued, classified and protected; external forums used at higher profiles | 0 |
ID.RA-3 | ID.RA-3 Threat catalogue with consistent identification and categorisation by vector and actor | 0 |
ID.RA-4 | ID.RA-4 Impact and likelihood assessed with consistent criteria and a formal impact assessment | 0 |
ID.RA-5 | ID.RA-5 Risk determination from documented impact and likelihood, physical security and HSE assessments, with stakeholders consulted on change | 0 |
ID.RA-6 | ID.RA-6 Risk response options determined, prioritised and approved by accountable management before action | 0 |
ID.RM | 6.2 Risk Management Strategy (ID.RM) | 0 |
ID.RM-1 | ID.RM-1 IAC risk management strategy considers enterprise and operations risk strategies | 0 |
ID.RM-2 | ID.RM-2 Risk tolerance documented, approved and set per profile | 0 |
ID.RM-3 | ID.RM-3 Critical infrastructure and sector-specific risk tolerance (Enhanced and above) | 0 |
ID.SC | 6.4 Supply Chain Risk Management (ID.SC) | 0 |
ID.SC-1 | ID.SC-1 An IAC supply chain risk management program integrated with risk management | 0 |
ID.SC-2 | ID.SC-2 Suppliers identified; supply chain risk assessment process (Enhanced and above) | 0 |
ID.SC-3 | ID.SC-3 Cybersecurity requirements in supplier contracts and communicated to vendors | 0 |
ID.SC-4 | ID.SC-4 Audit, assessment or validation of supplier compliance built into procurement | 0 |
ID.SC-5 | ID.SC-5 Supply chain dependencies in response and recovery plans | 0 |
PLAN | Section 5: the IAC cybersecurity policy, plan and program; zones, conduits, impact assessment and profile selection | 0 |
PR | Protect (PR): access control, training, data security, protection processes, maintenance, protective technology (Section 7) | 0 |
PR.AC | 7.1 Access Control (PR.AC) | 0 |
PR.AC-1 | PR.AC-1 Identity lifecycle management for human, device and process accounts; authentication on every interface | 0 |
PR.AC-2 | PR.AC-2 A physical security plan for sites with IAC cyber assets, aligned to the highest profile present | 0 |
PR.AC-3 | PR.AC-3 Nonlocal access managed: boundaries, approvals, failed logons, session control, emergency access and log retention | 0 |
PR.AC-4 | PR.AC-4 Role-based authorisation with least privilege and segregation of duties | 0 |
PR.AC-5 | PR.AC-5 Network integrity through security zones and conduits with maintained architecture diagrams | 0 |
PR.AC-6 | PR.AC-6 Non-repudiation, identity proofing and binding of digital identities to real identities | 0 |
PR.AC-7 | PR.AC-7 Risk-appropriate and consistent authentication strength within a segregated environment | 0 |
PR.AT | 7.2 IAC Cybersecurity Awareness and Training (PR.AT) | 0 |
PR.AT-1 | PR.AT-1 Cybersecurity training for all IAC users before access and periodically, including emergency behaviour | 0 |
PR.AT-2 | PR.AT-2 Training for high-privileged account users before administering any environment | 0 |
PR.AT-3 | PR.AT-3 Third-party stakeholder training, contractually bound, with acknowledgement of policies | 0 |
PR.AT-4 | PR.AT-4 Training for line managers and senior executives including regulatory requirements | 0 |
PR.AT-5 | PR.AT-5 Training for physical security and cybersecurity personnel with IAC responsibilities | 0 |
PR.DS | 7.3 Data Security (PR.DS) | 0 |
PR.DS-1 | PR.DS-1 Data at rest authorised, validated and protected by classification | 0 |
PR.DS-2 | PR.DS-2 Data in transit protected within zones and across internal, intermediate and external conduits | 0 |
PR.DS-3 | PR.DS-3 Secure disposal of IAC cyber assets no longer needed | 0 |
PR.DS-4 | PR.DS-4 Capacity planning with essential functions prioritised over security functions | 0 |
PR.DS-5 | PR.DS-5 Data leak protection: confidentiality agreements, removal of data from support assets, departing workers and removable media | 0 |
PR.DS-6 | PR.DS-6 Integrity verified before service and after maintenance; executables protected and updates authenticated | 0 |
PR.DS-7 | PR.DS-7 Development and test zones separated from production and protected to production standards | 0 |
PR.DS-8 | PR.DS-8 Physical tamper detection on IAC cyber assets (Extended) | 0 |
PR.IP | 7.4 Information Protection Processes and Procedures (PR.IP) | 0 |
PR.IP-1 | PR.IP-1 Documented baseline configurations for assets and environments on least functionality, verified before service | 0 |
PR.IP-10 | PR.IP-10 Response and recovery plans exercised and tested (Enhanced and above) | 0 |
PR.IP-11 | PR.IP-11 Personnel screening before access (Enhanced and above) | 0 |
PR.IP-12 | PR.IP-12 A formal vulnerability management plan using risk assessment, covering disclosures and scanning | 0 |
PR.IP-2 | PR.IP-2 A formal system development lifecycle with security roles and integrated risk management | 0 |
PR.IP-3 | PR.IP-3 Configuration change control with defined scope, documented decisions, testing, review and impact assessment | 0 |
PR.IP-4 | PR.IP-4 Backup and restore supporting continuity objectives, with integrity, secure storage and tested restoration | 0 |
PR.IP-5 | PR.IP-5 Physical operating environment requirements and defence-in-depth agreed with physical security | 0 |
PR.IP-6 | PR.IP-6 Information and document management with risk-based retention and destruction | 0 |
PR.IP-7 | PR.IP-7 Continuous improvement of protection processes with lessons learned | 0 |
PR.IP-8 | PR.IP-8 Protection technology effectiveness measurements protected and shared on need to know | 0 |
PR.IP-9 | PR.IP-9 A formal incident response plan covering preparation to recovery, classified, approved and with defined reportable incidents | 0 |
PR.MA | 7.5 Maintenance (PR.MA) | 0 |
PR.MA-1 | PR.MA-1 Maintenance documented, approved, performed to specification, with controls re-verified and tools and personnel authorised | 0 |
PR.MA-2 | PR.MA-2 Nonlocal maintenance risk-assessed, approved, logged and performed from an equivalently secured source | 0 |
PR.PT | 7.6 Protective Technology (PR.PT) | 0 |
PR.PT-1 | PR.PT-1 Security audit records generated, retained, reviewed and protected, with defined event types and managed storage | 0 |
PR.PT-2 | PR.PT-2 Removable media tested, approved and marked before use; any change voids the approval | 0 |
PR.PT-3 | PR.PT-3 Least functionality: only capabilities required for essential functions enabled, verified at change | 0 |
PR.PT-4 | PR.PT-4 Zone and conduit communication rules: monitored boundaries, inherited profiles, conduit-only paths and deny by default | 0 |
PR.PT-5 | PR.PT-5 Availability and resiliency requirements per zone and conduit with priority of service | 0 |
PROF | Section 4: the three profiles, threat protection objectives, business objectives and impact levels | 0 |
RC | Recover (RC): recovery planning, improvements, communications (Section 10) | 0 |
RC.CO | 10.3 Communications (RC.CO) | 0 |
RC.CO-1 | RC.CO-1 Internal owners of public relations during incidents | 0 |
RC.CO-2 | RC.CO-2 Internal owners of reputation repair | 0 |
RC.CO-3 | RC.CO-3 Recovery activities communicated to defined stakeholders | 0 |
RC.IM | 10.2 Improvements (RC.IM) | 0 |
RC.IM-1 | RC.IM-1 Recovery lessons learned identified, reviewed and tracked to completion | 0 |
RC.IM-2 | RC.IM-2 Recovery strategy updated from lessons learned | 0 |
RC.RP | 10.1 Recovery Planning (RC.RP) | 0 |
RC.RP-1 | RC.RP-1 Recovery initiated as soon as practicable | 0 |
RS | Respond (RS): response planning, communications, analysis, mitigation, improvements (Section 9) | 0 |
RS.AN | 9.3 Analysis (RS.AN) | 0 |
RS.AN-1 | RS.AN-1 Notifications and alerts investigated | 0 |
RS.AN-2 | RS.AN-2 Incident impact analysed within and beyond the environment where detected, feeding lessons learned | 0 |
RS.AN-3 | RS.AN-3 Evidence preservation, collection and forensic analysis for root cause | 0 |
RS.AN-4 | RS.AN-4 Incident categorisation by disruption of essential functions, type, severity and sensitivity | 0 |
RS.AN-5 | RS.AN-5 Vulnerability disclosure intake (no profile-specific requirement) | 0 |
RS.CO | 9.2 Communications (RS.CO) | 0 |
RS.CO-1 | RS.CO-1 Response structure, roles and contacts documented, distributed, updated and tested | 0 |
RS.CO-2 | RS.CO-2 A reporting mechanism for suspected incidents and criteria for official declaration | 0 |
RS.CO-3 | RS.CO-3 Incident communications plan with defined recipients, content and authorised external communicators | 0 |
RS.CO-4 | RS.CO-4 Coordination of response with internal and external stakeholders | 0 |
RS.CO-5 | RS.CO-5 Voluntary information sharing (no profile-specific requirement) | 0 |
RS.IM | 9.5 Improvements (RS.IM) | 0 |
RS.IM-1 | RS.IM-1 Response lessons learned identified, reviewed and tracked to completion after every execution | 0 |
RS.IM-2 | RS.IM-2 Response strategy updated from lessons learned | 0 |
RS.MI | 9.4 Mitigation (RS.MI) | 0 |
RS.MI-1 | RS.MI-1 Containment processes with escalation to authorising management | 0 |
RS.MI-2 | RS.MI-2 Mitigation processes with escalation to authorising management | 0 |
RS.MI-3 | RS.MI-3 Vulnerabilities found during response documented or mitigated through vulnerability management | 0 |
RS.RP | 9.1 Response Planning (RS.RP) | 0 |
RS.RP-1 | RS.RP-1 Incident response plan activated on official declaration | 0 |
STD | API Standard 1164 third edition: what it is, its editions and what is held | 0 |