Skip to main content
Image coming soon

API 1164 Pipeline Control Systems Cybersecurity Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
API 1164 · Pipeline Control Systems Cybersecurity · Evidence & Implementation Kit
Secure your pipeline control systems to API 1164 without forcing IT security onto OT that cannot take it.
Every API 1164 control handed to you as adopt-ready policy written for operational technology, with the OT realities, the exact evidence an assessor examines, and the finding they most often raise.
Assessment-ready in a weekend, not a quarter.

Here is the honest situation. API 1164 is the benchmark for pipeline OT cybersecurity, and regulators and partners increasingly expect it. The hard part is that pipeline control systems are not IT: availability and safety come first, many devices are legacy and cannot be patched on an IT cadence, and monitoring is often passive. Translating a control catalogue into policy that works for SCADA and OT, with the evidence an assessor examines, is the real job. A consultant charges heavily and takes months.

This Kit removes the build. It is every API 1164 control as OT-aware policy you personalize in a weekend, organized by the cybersecurity framework functions.

What you get, the moment you buy

88
Controls as adopt-ready OT policy. All 88 controls across the twelve API 1164 requirement sections, from risk management to compliance and assessment, written for pipeline operational technology. Personalize and you are done.
12
Requirement sections, in full. Every section covered: risk management, security architecture, access control, system integrity, data protection, monitoring, incident response, continuity, supply chain, personnel, physical and compliance.
1
API 1164 Control Matrix, pre-built. Every control in a working spreadsheet, ready to record your implementation, status and evidence location.
1
Gap & Readiness Assessment. Score each control and the workbook tells you your readiness as a single percentage, and exactly what to fix next.

Organized by API 1164's twelve requirement sections and grounded on the NIST SP 800-53 families it aligns to, written for OT realities: IAC-from-IT isolation, allow listing, passive monitoring and safe operating modes. Editable Word and Excel files.

OT is not IT, and this Kit knows it
Pipeline control systems put availability and safety first and run legacy devices that cannot take an IT patching cadence. The controls here are written for that: strong IT and OT segmentation, allow listing over signature antivirus, passive monitoring, and safe containment. You protect the pipeline without breaking it.

What one control looks like

This is an Access Control requirement for the pipeline control network. All 88 controls, across the twelve API 1164 sections, are built to this depth.

API1164-6-1 Enforce Unique Individual Identities ACCESS CONTROL
Adopt this control

[Operator] shall assign unique individual identities to all persons accessing industrial automation and control systems and shall prohibit routine use of shared or generic accounts. Where legacy devices cannot support individual accounts, [Operator] shall compensate with logged, supervised, and physically controlled access so operator actions remain attributable to a specific person.

Evidence an assessor examines
  • Account inventory showing individual identities for control-system users
  • Policy prohibiting routine shared account use
  • Compensating access logs for legacy shared-credential devices
  • Access reviews for control-system accounts
Common finding they raise: Control room staff share a single always-logged-in operator account across shifts, destroying attribution.

Why this is not another template pack

  • The evidence is the point. Generic IT policies fail in OT. This tells you exactly what an assessor examines and the finding they raise, for every control, in an OT context. That is what passes a pipeline assessment.
  • Written for operational technology. Segmentation, legacy-device constraints, availability-first patching and safe operating modes are built in, not bolted on.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. API 1164 maps to the NIST Cybersecurity Framework and 800-53, so this work aligns with your wider security and any IEC 62443 program.

Who buys this

Pipeline operators and their OT and control-system engineers, security leads responsible for SCADA environments, and consultants preparing operators for assessment. Whether it is a first uplift or a re-assessment, you save weeks and walk in with OT-aware controls and evidence ready.

By the end of the weekend you will have
✓  A control for every one of the 88 API 1164 requirements
✓  A completed API 1164 control matrix
✓  The evidence an assessor examines
✓  Your IT and OT segmentation boundary anchored
✓  A readiness percentage and a fix list
✓  The common findings closed before the assessment

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this an API product? No. API 1164 is the American Petroleum Institute's standard; this is an independent implementation aid to help you adopt and evidence the controls.

Does it account for legacy OT? Yes. The controls are written for availability-first, legacy-constrained environments, with segmentation and safe operating modes rather than blanket IT patching.

Does it map to NIST? Yes. It follows the cybersecurity framework functions and aligns conceptually to the 800-53 families, matching how the 3rd edition is structured.

What if it is not for me? A 30-day money-back guarantee.

Do not secure a pipeline with an IT checklist.
A consultant is a heavy fee and months. The Kit is instant, and it is guaranteed.
Add it to your cart and be assessment-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com