United States (API; referenced by the TSA Pipeline Security Guidelines and used internationally)

API 1164

163 controls. 297 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

163 controls 297 frameworks share controls with it United States (API; referenced by the TSA Pipeline Security Guidelines and used internationally) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

API 1164 Pipeline Control Systems Cybersecurity Evidence & Implementation Kit

163 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
API1164-01Scope and Applicability0
API1164-02Risk Management Framework51
API1164-03Governance and Roles0
API1164-04Asset Inventory1
API1164-05Network Segmentation and Zones10
API1164-06Access Control127
API1164-07Remote Access203
API1164-08Configuration Management4
API1164-09Patch and Vulnerability Management124
API1164-10Malware Protection4
API1164-11Logging and Monitoring20
API1164-12Incident Response34
API1164-13Business Continuity and Recovery94
API1164-14Physical Security59
API1164-15Personnel Security1
API1164-16Supply Chain and Third Party2
API1164-17Wireless and Field Communications171
API1164-18Field Device Security179
API1164-19Safety Instrumented Systems Interface171
API1164-20Program Review and Continuous Improvement1
API1164-21TSA Pipeline Security Directive Alignment128
API1164-22Configuration management for OT systems110
API1164-23Change management procedures101
API1164-24Vulnerability assessment for critical systems154
DEDetect (DE): anomalies and events, continuous monitoring, detection processes (Section 8)0
DE.AE8.1 Anomalies and Events (DE.AE)0
DE.AE-1DE.AE-1 Expected data flows across conduits in the baseline configuration0
DE.AE-2DE.AE-2 Audit anomalies analysed to confirm incidents and understand targets and methods0
DE.AE-3DE.AE-3 Event data from multiple sources correlated and analysed0
DE.AE-4DE.AE-4 Event impact determined with consistent criteria and the API 1164 impact assessment0
DE.AE-5DE.AE-5 Incident alert thresholds defined in the incident response plan0
DE.CM8.2 Security Continuous Monitoring (DE.CM)0
DE.CM-1DE.CM-1 Continuous monitoring of conduit ingress and egress, extending into zones at higher profiles0
DE.CM-2DE.CM-2 Physical security events coordinated into IAC monitoring0
DE.CM-3DE.CM-3 Personnel activity monitoring with privacy and civil liberties considered0
DE.CM-4DE.CM-4 Malware risk assessed per environment and detection deployed and updated per vendor practice0
DE.CM-5DE.CM-5 Mobile code risk-assessed, approved and monitored0
DE.CM-6DE.CM-6 External service provider activity monitored locally and remotely0
DE.CM-7DE.CM-7 Monitoring for unauthorised personnel, connections, devices and software0
DE.CM-8DE.CM-8 Automated vulnerability detection in production risk-assessed, approved and used per vendor practice0
DE.DP8.3 Detection Processes (DE.DP)0
DE.DP-1DE.DP-1 Detection roles and responsibilities defined, updated and communicated0
DE.DP-2DE.DP-2 Periodic review that detection mechanisms and processes match the baseline and the plan0
DE.DP-3DE.DP-3 Periodic testing of the design and operating effectiveness of technical and procedural detection controls0
DE.DP-4DE.DP-4 Event detection information communicated to defined stakeholders by authorised personnel0
DE.DP-5DE.DP-5 Continuous improvement of detection processes with lessons learned0
IDIdentify (ID): governance, risk strategy, business environment, supply chain, risk assessment, asset management (Section 6)0
ID.AM6.6 Asset Management (ID.AM)0
ID.AM-1ID.AM-1 IAC cyber asset inventory with consistent identification, minimum attributes and zone membership0
ID.AM-2ID.AM-2 Software asset catalogue covering essential-function software with dependencies0
ID.AM-3ID.AM-3 Communications and data flows catalogued within zones and across every conduit type0
ID.AM-4ID.AM-4 External cyber assets and dependencies catalogued0
ID.AM-5ID.AM-5 Resource prioritisation by classification, criticality and business value0
ID.AM-6ID.AM-6 Cybersecurity roles and responsibilities documented, allocated and matched to capability0
ID.BE6.3 Business Environment (ID.BE)0
ID.BE-1ID.BE-1 Critical infrastructure supply chain role in risk tolerance and decisions (Enhanced and above)0
ID.BE-2ID.BE-2 Critical infrastructure and industry sector roles in the risk strategy (Enhanced and above)0
ID.BE-3ID.BE-3 Mission, objectives and activity priorities drive roles, risk decisions and training0
ID.BE-4ID.BE-4 Essential functions for critical service delivery catalogued (Enhanced and above)0
ID.BE-5ID.BE-5 A risk-based critical services resiliency plan (Enhanced and above)0
ID.GV6.1 Governance (ID.GV)0
ID.GV-1ID.GV-1 IAC cybersecurity plan governance, performance measurement and review0
ID.GV-2ID.GV-2 Cybersecurity roles and responsibilities coordinated across stakeholders and boundaries0
ID.GV-3ID.GV-3 Legal and regulatory requirements catalogued, used in risk decisions and communicated0
ID.GV-4ID.GV-4 Governance and risk management of IAC cyber risk aligned with enterprise governance0
ID.RA6.5 IAC Risk Assessment (ID.RA)0
ID.RA-1ID.RA-1 Vulnerability catalogue with consistent identification, categorisation and control effectiveness assessment0
ID.RA-2ID.RA-2 Threat intelligence catalogued, classified and protected; external forums used at higher profiles0
ID.RA-3ID.RA-3 Threat catalogue with consistent identification and categorisation by vector and actor0
ID.RA-4ID.RA-4 Impact and likelihood assessed with consistent criteria and a formal impact assessment0
ID.RA-5ID.RA-5 Risk determination from documented impact and likelihood, physical security and HSE assessments, with stakeholders consulted on change0
ID.RA-6ID.RA-6 Risk response options determined, prioritised and approved by accountable management before action0
ID.RM6.2 Risk Management Strategy (ID.RM)0
ID.RM-1ID.RM-1 IAC risk management strategy considers enterprise and operations risk strategies0
ID.RM-2ID.RM-2 Risk tolerance documented, approved and set per profile0
ID.RM-3ID.RM-3 Critical infrastructure and sector-specific risk tolerance (Enhanced and above)0
ID.SC6.4 Supply Chain Risk Management (ID.SC)0
ID.SC-1ID.SC-1 An IAC supply chain risk management program integrated with risk management0
ID.SC-2ID.SC-2 Suppliers identified; supply chain risk assessment process (Enhanced and above)0
ID.SC-3ID.SC-3 Cybersecurity requirements in supplier contracts and communicated to vendors0
ID.SC-4ID.SC-4 Audit, assessment or validation of supplier compliance built into procurement0
ID.SC-5ID.SC-5 Supply chain dependencies in response and recovery plans0
PLANSection 5: the IAC cybersecurity policy, plan and program; zones, conduits, impact assessment and profile selection0
PRProtect (PR): access control, training, data security, protection processes, maintenance, protective technology (Section 7)0
PR.AC7.1 Access Control (PR.AC)0
PR.AC-1PR.AC-1 Identity lifecycle management for human, device and process accounts; authentication on every interface0
PR.AC-2PR.AC-2 A physical security plan for sites with IAC cyber assets, aligned to the highest profile present0
PR.AC-3PR.AC-3 Nonlocal access managed: boundaries, approvals, failed logons, session control, emergency access and log retention0
PR.AC-4PR.AC-4 Role-based authorisation with least privilege and segregation of duties0
PR.AC-5PR.AC-5 Network integrity through security zones and conduits with maintained architecture diagrams0
PR.AC-6PR.AC-6 Non-repudiation, identity proofing and binding of digital identities to real identities0
PR.AC-7PR.AC-7 Risk-appropriate and consistent authentication strength within a segregated environment0
PR.AT7.2 IAC Cybersecurity Awareness and Training (PR.AT)0
PR.AT-1PR.AT-1 Cybersecurity training for all IAC users before access and periodically, including emergency behaviour0
PR.AT-2PR.AT-2 Training for high-privileged account users before administering any environment0
PR.AT-3PR.AT-3 Third-party stakeholder training, contractually bound, with acknowledgement of policies0
PR.AT-4PR.AT-4 Training for line managers and senior executives including regulatory requirements0
PR.AT-5PR.AT-5 Training for physical security and cybersecurity personnel with IAC responsibilities0
PR.DS7.3 Data Security (PR.DS)0
PR.DS-1PR.DS-1 Data at rest authorised, validated and protected by classification0
PR.DS-2PR.DS-2 Data in transit protected within zones and across internal, intermediate and external conduits0
PR.DS-3PR.DS-3 Secure disposal of IAC cyber assets no longer needed0
PR.DS-4PR.DS-4 Capacity planning with essential functions prioritised over security functions0
PR.DS-5PR.DS-5 Data leak protection: confidentiality agreements, removal of data from support assets, departing workers and removable media0
PR.DS-6PR.DS-6 Integrity verified before service and after maintenance; executables protected and updates authenticated0
PR.DS-7PR.DS-7 Development and test zones separated from production and protected to production standards0
PR.DS-8PR.DS-8 Physical tamper detection on IAC cyber assets (Extended)0
PR.IP7.4 Information Protection Processes and Procedures (PR.IP)0
PR.IP-1PR.IP-1 Documented baseline configurations for assets and environments on least functionality, verified before service0
PR.IP-10PR.IP-10 Response and recovery plans exercised and tested (Enhanced and above)0
PR.IP-11PR.IP-11 Personnel screening before access (Enhanced and above)0
PR.IP-12PR.IP-12 A formal vulnerability management plan using risk assessment, covering disclosures and scanning0
PR.IP-2PR.IP-2 A formal system development lifecycle with security roles and integrated risk management0
PR.IP-3PR.IP-3 Configuration change control with defined scope, documented decisions, testing, review and impact assessment0
PR.IP-4PR.IP-4 Backup and restore supporting continuity objectives, with integrity, secure storage and tested restoration0
PR.IP-5PR.IP-5 Physical operating environment requirements and defence-in-depth agreed with physical security0
PR.IP-6PR.IP-6 Information and document management with risk-based retention and destruction0
PR.IP-7PR.IP-7 Continuous improvement of protection processes with lessons learned0
PR.IP-8PR.IP-8 Protection technology effectiveness measurements protected and shared on need to know0
PR.IP-9PR.IP-9 A formal incident response plan covering preparation to recovery, classified, approved and with defined reportable incidents0
PR.MA7.5 Maintenance (PR.MA)0
PR.MA-1PR.MA-1 Maintenance documented, approved, performed to specification, with controls re-verified and tools and personnel authorised0
PR.MA-2PR.MA-2 Nonlocal maintenance risk-assessed, approved, logged and performed from an equivalently secured source0
PR.PT7.6 Protective Technology (PR.PT)0
PR.PT-1PR.PT-1 Security audit records generated, retained, reviewed and protected, with defined event types and managed storage0
PR.PT-2PR.PT-2 Removable media tested, approved and marked before use; any change voids the approval0
PR.PT-3PR.PT-3 Least functionality: only capabilities required for essential functions enabled, verified at change0
PR.PT-4PR.PT-4 Zone and conduit communication rules: monitored boundaries, inherited profiles, conduit-only paths and deny by default0
PR.PT-5PR.PT-5 Availability and resiliency requirements per zone and conduit with priority of service0
PROFSection 4: the three profiles, threat protection objectives, business objectives and impact levels0
RCRecover (RC): recovery planning, improvements, communications (Section 10)0
RC.CO10.3 Communications (RC.CO)0
RC.CO-1RC.CO-1 Internal owners of public relations during incidents0
RC.CO-2RC.CO-2 Internal owners of reputation repair0
RC.CO-3RC.CO-3 Recovery activities communicated to defined stakeholders0
RC.IM10.2 Improvements (RC.IM)0
RC.IM-1RC.IM-1 Recovery lessons learned identified, reviewed and tracked to completion0
RC.IM-2RC.IM-2 Recovery strategy updated from lessons learned0
RC.RP10.1 Recovery Planning (RC.RP)0
RC.RP-1RC.RP-1 Recovery initiated as soon as practicable0
RSRespond (RS): response planning, communications, analysis, mitigation, improvements (Section 9)0
RS.AN9.3 Analysis (RS.AN)0
RS.AN-1RS.AN-1 Notifications and alerts investigated0
RS.AN-2RS.AN-2 Incident impact analysed within and beyond the environment where detected, feeding lessons learned0
RS.AN-3RS.AN-3 Evidence preservation, collection and forensic analysis for root cause0
RS.AN-4RS.AN-4 Incident categorisation by disruption of essential functions, type, severity and sensitivity0
RS.AN-5RS.AN-5 Vulnerability disclosure intake (no profile-specific requirement)0
RS.CO9.2 Communications (RS.CO)0
RS.CO-1RS.CO-1 Response structure, roles and contacts documented, distributed, updated and tested0
RS.CO-2RS.CO-2 A reporting mechanism for suspected incidents and criteria for official declaration0
RS.CO-3RS.CO-3 Incident communications plan with defined recipients, content and authorised external communicators0
RS.CO-4RS.CO-4 Coordination of response with internal and external stakeholders0
RS.CO-5RS.CO-5 Voluntary information sharing (no profile-specific requirement)0
RS.IM9.5 Improvements (RS.IM)0
RS.IM-1RS.IM-1 Response lessons learned identified, reviewed and tracked to completion after every execution0
RS.IM-2RS.IM-2 Response strategy updated from lessons learned0
RS.MI9.4 Mitigation (RS.MI)0
RS.MI-1RS.MI-1 Containment processes with escalation to authorising management0
RS.MI-2RS.MI-2 Mitigation processes with escalation to authorising management0
RS.MI-3RS.MI-3 Vulnerabilities found during response documented or mitigated through vulnerability management0
RS.RP9.1 Response Planning (RS.RP)0
RS.RP-1RS.RP-1 Incident response plan activated on official declaration0
STDAPI Standard 1164 third edition: what it is, its editions and what is held0

Tell me when API 1164 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • security charter
  • board reporting pack
  • risk register
  • policy library
  • Executive sponsor designation
  • PDPA compliance roadmap
  • Admin handbook
  • PAW configuration baseline
  • Jump host architecture
  • jump host config

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for API 1164, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition