Axio CEO and co-founder Dave White was interviewed in this article for Quartz in response to 2021’s rapidly increasing number of cyber-attacks. White heavily stresses...
In a recent webinar, Axio’s Global Co-founder and President, David White, sat down with American Gas Association’s Managing Director of Security and Operations, Kimberly Denbow, to discuss the latest release (v3) of API-1164, Pipeline Control Systems Cybersecurity, which is a NIST CSF-based community standard for cybersecurity regulation. We encourage you to check out the full webinar for all the enlightening details and discussion, which can be found on Axio’s website. Read on for some highlights…
The API-1164 is a standard released by the American Petroleum Institute (API) for pipeline and SCADA systems that was initially developed after the terrorist attacks on 9/11. From its conception, the primary objectives in creating this standard have been to help businesses:
Version one (v1) was released in September of 2004 and was created to provide guidance for operators of oil and gas liquid pipeline systems. Version two (v2) was released in 2009 and was updated with other API standards to improve cybersecurity, including the NIST 800 series. The latest release, v3, debuted in August of last year. It was rewritten to increase its scope to cover all pipeline operation technology environments for both oil and natural gas.
With significant support from the oil and natural gas business community, API-1164-v3 was developed using a consensus-based approach. Owners, operators, and federal partners were involved from beginning to end using fundamental security principles across critical infrastructure sectors – not just the pipeline sector. Collaboration was crucial throughout the development process, and included contributors from the Dept. of Energy, CISA, AGA, TSA, and many others. A three-year project, the latest version of the standard involved:
API-1164 v3 will have a broad applicability to other sectors because it now includes a progression of controls that can be customized to businesses of any size across industries. With greater flexibility and applicability, the controls in v3 are designed to be driven by
The strategy behind this design means you or any organization can fine-tune the suggested protection requirements to best meet your business’ operating condition, position, and risk tolerance.
For full details on API-1164 v3, download our webinar here, where David and Kimberly cover additional details of the new standard, including building blocks like the NIST CSF-800 series and ISA/IEC 62443 that were used to inform the latest version. They also discuss how business stakeholders across different industries can leverage it to their advantage. API-1164 v3 is the “best in breed” for pipeline security standards. Stay tuned for our ongoing, in-depth coverage of this latest release and how it can apply to your organization.
Axio CEO and co-founder Dave White was interviewed in this article for Quartz in response to 2021’s rapidly increasing number of cyber-attacks. White heavily stresses...
It’s time to start seeing risk management with more clarity—download our paper to learn more .