Security management for petroleum and natural gas industry systems
This is the fourth edition of CSA Z246.1, Security management for petroleum and natural gas industry systems . It supersedes the previous editions published in 2017, 2013 and 2009. The most significant change relative to the previous edition is the expansion of cybersecurity measures that have replaced the previous Clause 7 and incorporated the changes throughout the Standard. This Standard uses the concept of a security management program, and in particular risk management, to address security issues. This Standard provides a performance-based approach for use by the operator to establish governance, conduct planning, implement and improve security operations (including detection and mitigation practices), and refine the security management program through change management and audit processes. This approach allows users to apply this Standard across the petroleum and natural gas industry. This Standard is one of several security risk management tools. Operators should work with other industries, as well as governmental agencies, in order to effectively manage the security of their energy infrastructure. A security management program should complement existing programs and should consider the risks and criticality of the assets being protected. Therefore, this Standard should be read in conjunction with other security legislation, safety legislation, best practices, policies, standards, and applicable codes (e.g., CSA Z662, CAN/CSA-ISO 31000, and CSA Z1600). In particular, this Standard is aligned with CSA Z246.2, Emergency preparedness and response for the petroleum and natural gas industry systems, to both support a continual improvement process and to develop sound risk-based management processes. This Standard was prepared by the Technical Committee on Security Management for Petroleum and Natural Gas Industry Systems, under the jurisdiction of the Strategic Steering Committee on Petroleum and Natural Gas Industry Systems, and has been formally approved by the Technical Committee. This Standard has been developed in compliance with Standards Council of Canada requirements for National Standards of Canada. It has been published as a National Standard of Canada by CSA Group.
This Standard specifies criteria for establishing a security management program for petroleum and natural gas industry systems to ensure security threats and associated risks are identified and managed. This Standard provides mitigation and response processes and procedures to prevent and minimize the impact of security incidents that could adversely affect people, the environment, assets, and economic stability.
This Standard applies to all petroleum and natural gas industry systems (as illustrated in Figures 2 and 3), including
Note: 1) Examples of gas can include methane, carbon dioxide, and hydrogen. 2) Examples of liquid products can include methane, carbon dioxide, ammonia, and hydrogen. The requirements of this Standard are applicable to all operators, regardless of the size or number of their assets
This Standard does not apply to
This Standard also excludes security management for liquid or gaseous energy that is transported by rail, road, or ship. Note: See Figures 2 and 3
In this Standard, "shall" is used to express a requirement, i.e., a provision that the user is obliged to satisfy in order to comply with the Standard; "should" is used to express a recommendation or that which is advised but not required; and "may" is used to express an option or that which is permissible within the limits of the Standard. Notes accompanying clauses do not include requirements or alternative requirements; the purpose of a note accompanying a clause is to separate from the text explanatory or informative material. Notes to tables and figures are considered part of the table or figure and may be written as requirements. Annexes are designated normative (mandatory) or informative (non-mandatory) to define their application.
| SDO | CSA: Canadian Standards Association |
| Document Number | |
| Publication Date | Jan. 1, 2021 |
| Language | en - English |
| Page Count | 36 |
| Revision Level | |
| Supercedes | |
| Committee |