The significance of open standards and industry collaborations cannot be overstated in today’s interconnected and rapidly evolving technological landscape. Open standards enable interoperability between diverse systems and technologies, fostering innovation and allowing for seamless integration across platforms. Industry collaborations bring together experts and stakeholders from various sectors to address common challenges, share knowledge, and develop best practices.
By promoting cooperation and shared objectives, open standards and collaborative initiatives play a pivotal role in enhancing consistency and efficiency across engineering design, operations, and maintenance. They enable operating companies, equipment vendors and system integrators to adopt more robust and streamlined approaches. By establishing common frameworks and protocols, these collaborations ensure that diverse organisations can align their processes, reduce redundancies and work seamlessly together. This unified effort not only improves interoperability but also accelerates innovation and optimises performance across the industry.
Here are a few key open standards, tools and collaborative initiatives.
- CFIHOS – Capital Facilities Information Handover Specification
- CSET – Cybersecurity Evaluation Tool
- ETHOS – Emerging THreat Open Sharing
- JIP33 – Joint Industry Programme
- LOGIIC – Linking Oil and Gas Industry to Improve Cybersecurity
- MITRE ATT&CK
- NIST – Cybersecurity Framework
- NOA – NAMUR Open Architecture
- OPAF – Open Process Automation Forum
- OSDU – Open Subsurface Data Universe
- PODS – Pipeline Open Data Standards
- STIX – Structured Threat Information Expression
- ZVEI – Zentralverband Elektrotechnik- und Elektronikindustrie
CFIHOS – Capital Facilities Information Handover Specification
Capital Facilities Information Handover Specification or CFIHOS, is an international standard designed to improve how information is transferred across the lifecycle of large capital facilities, such as those in the oil, gas, energy, and construction sectors. CFIHOS has it’s roots in an oil & gas information standard, which began when the company Shell approached the process industry organisation USPI to turn its Engineering Information Specification (EIS) into an industry standard for the process industries supply chain. In January 2020, the governance of CFIHOS transferred from USPI to IOGP, becoming Joint Industry Project(JIP)36.
In industries with extensive regulatory requirements and high complexity, efficient data sharing between stakeholders, including operators, contractors, and suppliers, is essential to avoid delays, reduce project costs, and maintain safety and compliance. Under the JIP36 initiative by the IOGP, CFIHOS establishes a clear, structured framework for managing and exchanging data. This standard defines key elements of information—such as asset documentation, operational data, and maintenance information—required during the construction, operation, and decommissioning of industrial facilities, thereby providing a common language and set of expectations for information handovers.
Additionally, CFIHOS provides a comprehensive set of templates, formats, and definitions that standardise information handover processes, enabling seamless interoperability across various software and data management systems. This structured approach ensures that organisations can maintain accurate, accessible data, reduce project risks, and achieve operational efficiencies across their facilities.
CFIHOS Version 2 introduces enhanced standards for information handover, addressing the full lifecycle of capital facilities with updated guidelines and a more comprehensive data structure. The CFIHOS Reference Data Library (RDL) within Version 2 is a structured repository of standardised terms, classifications, and attributes used to ensure consistent data across capital projects. By providing a common vocabulary, the RDL supports interoperability between systems and stakeholders, making it easier to share, understand, and manage complex facility data throughout the asset lifecycle.
CSET – Cybersecurity Evaluation Tool
Cybersecurity Evaluation Tool (CSET), developed by the Cybersecurity and Infrastructure Security Agency (CISA) under the U.S. Department of Homeland Security (DHS), is a free, open-source desktop software tool designed to help organisations assess and improve their cybersecurity posture. CSET provides a systematic, repeatable framework for evaluating the security of both information technology (IT) and industrial control systems (ICS).
The tool offers a structured approach to help organisations understand, evaluate, and strengthen their cybersecurity defences by aligning with established industry standards and best practices. CSET guides users through a comprehensive assessment process based on recognised cybersecurity frameworks and standards such as the DHS Catalog of Control Systems Security: Recommendations for Standards Developers; NIST Special Publication 800-82, Guide to Industrial Control Systems Security; NIST Special Publication 800-53, Recommended Security Controls for Federal Information Systems; NIST Cybersecurity Framework; NERC Critical Infrastructure Protection (CIP) Standards 002 – 009 and NRC Regulatory Guide 5.71 Cyber Security Programs for Nuclear Facilities. These frameworks provide foundational guidelines and best practices that CSET uses to help organisations evaluate and enhance their cybersecurity posture across various domains.
Through detailed questionnaires and checklists, the tool evaluates an organisation’s practices, identifies vulnerabilities, and offers prioritised recommendations for enhancement. CSET’s output includes tailored reports with actionable insights, making it a valuable resource for organisations across sectors, from small businesses to large enterprises, aiming to bolster their cybersecurity resilience.
ETHOS – Emerging THreat Open Sharing
ETHOS (Emerging THreat Open Sharing) is an open-source framework launched in April 2023 to support real-time information sharing and early warning detection for cybersecurity threats within critical infrastructure sectors. Primarily focused on operational technology (OT) and industrial control system (ICS) environments, ETHOS enables organisations to collaborate on identifying and mitigating potential cyber threats before they escalate.
ETHOS’s objective is to create a collaborative, open-source platform where industry stakeholders, government agencies, and academia can share cybersecurity information, tools, and best practices to strengthen the security and resilience of critical infrastructure sectors. ETHOS fosters a community-driven approach to cybersecurity, where participants contribute to a GitHub open-source codebase and platform that supports the detection, analysis, and mitigation of threats. The platform is designed to be vendor-agnostic and interoperable, allowing any organisation to set up their own ETHOS server and integrate with others to share anonymous, real-time threat data.
ETHOS emphasises early warning through machine-to-machine communication of potential indicators, complementing existing frameworks like STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Indicator Information). By promoting open standards and creating an inclusive governance model, ETHOS provides critical infrastructure sectors with the tools and insights needed for proactive threat management and security resilience.
JIP33 – Joint Industry Programme
Joint Industry Programme 33 (JIP33), led by the International Association of Oil & Gas Producers (IOGP), is a groundbreaking initiative to standardise procurement specifications across the oil and gas sector. By developing uniform specifications, JIP33 aims to create significant efficiency gains, reduce variation in equipment standards, and improve both cost control and project scheduling for industry stakeholders.
JIP33’s mission is to make a substantial improvement in the specification, procurement, and delivery of equipment for the oil and gas industry by introducing and promoting standardised procurement specifications. These specifications are designed to foster industry-wide efficiency, quality, and cost-effectiveness. JIP33 actively engages with oil and gas operators, suppliers, and engineering, procurement, and construction (EPC) partners to create, refine, and maintain open-access specifications.
All developed specifications are made freely accessible in the Specification Library, are hosted on the IOGP Publications Library and are available free for use, encouraging widespread industry adoption. To ensure relevance and quality, JIP33 continuously expands its portfolio of specifications and invites public feedback through the Specification Development page. Additionally, the Supplier Network is integral to the program, fostering close collaboration with vendors to support efficient delivery and adherence to standardised quality expectations across the supply chain. Through these collaborative and transparent efforts, JIP33 drives substantial value by reducing variability, optimising procurement processes, and aligning industry standards.
LOGIIC – Linking Oil and Gas Industry to Improve Cybersecurity
LOGIIC (Linking Oil and Gas Industry to Improve Cybersecurity) is a collaborative initiative formed between the U.S. Department of Homeland Security (DHS) Science & Technology Directorate (S&T) and key stakeholders in the oil and gas industry. Established in 2004, LOGIIC’s mission is to enhance cybersecurity resilience within critical infrastructure sectors, particularly focusing on digital control systems in oil and gas.
The mission of LOGIIC is to strengthen the cybersecurity posture of the oil and gas sector by fostering collaboration among industry leaders and government, facilitating the exchange of best practices, and supporting research efforts that target cybersecurity challenges unique to the industry.
LOGIIC achieves its mission by conducting collaborative R&D projects aimed at addressing specific cybersecurity needs within the oil and gas industry. These projects include the development of guidelines, pilot programs, and protective strategies, such as the Correlation Project, Host Protection Strategies Project and the Safety Instrumented Systems Project. The initiative also provides a platform for information sharing and fosters partnerships among industry, government, and technology vendors to promote a more secure operational environment.
According to the DHS website, LOGIIC is currently archived content, which indicates that it may no longer be an active initiative.
MITRE ATT&CK
MITRE ATT&CK Framework: The MITRE ATT&CK® Framework is a comprehensive, publicly accessible knowledge base documenting adversary tactics and techniques observed in real-world cybersecurity incidents. It serves as a foundational resource for threat modelling, enhancing security operations, and improving incident response strategies.
MITRE is a not-for-profit organisation that operates federally funded research and development centres (FFRDCs) and provides independent technical expertise to U.S. government agencies. Known for its collaborative approach, MITRE engages with government, industry, and academia to solve complex national challenges across multiple domains, including cybersecurity, healthcare, aviation, and defence.
The ATT&CK Framework’s mission aligns with MITRE’s broader vision of a safer world by equipping the cybersecurity community with actionable insights into adversary behaviours to build more resilient defences. MITRE ATT&CK® has become a global resource for understanding and defending against cyber threats and MITRE continuously updates ATT&CK with insights from ongoing cyber activities, detailing adversarial tactics, techniques, and procedures (TTPs) based on global threat intelligence. By offering this information free of charge, MITRE empowers organisations to enhance their understanding of threats, design more robust security measures, and foster collaboration across the cybersecurity community.
NIST – Cybersecurity Framework
NIST Cybersecurity Framework (NIST-CSF) is a voluntary, comprehensive framework developed by the National Institute of Standards and Technology (NIST) to guide organisations in managing and reducing cybersecurity risk. Widely adopted across industries, the framework provides a flexible set of standards, guidelines, and best practices that apply to organisations of all sizes.
NIST-CSF delivers a policy framework that assists U.S. private sector organisations assess and improve their cybersecurity resilience. By offering structured guidance, NIST-CSF empowers organisations to prevent, detect, and respond to cyber threats, strengthening national cybersecurity posture. NIST-CSF accomplishes this through a structured framework organised around five core functions—Identify, Protect, Detect, Respond, and Recover—which together create a holistic view of an organisation’s cybersecurity risk management lifecycle.
The framework’s adaptability allows it to be tailored to specific industries, enabling organisations to enhance their security while aligning with their unique operational needs. With the release of CSF 2.0, NIST has introduced additional resources like Quick Start Guides and Community Profiles, providing streamlined entry points for small businesses and advanced templates for sector-specific applications. This flexible, scalable approach makes NIST-CSF a valuable tool for improving cybersecurity across diverse environments.
NOA – NAMUR Open Architecture
NAMUR Open Architecture (NOA), developed by NAMUR (User Association of Automation Technology in Process Industries), is a concept designed to bridge the gap between IT and OT systems in process industries. NOA enables seamless, secure access to production data, making it easier to monitor and optimise plant operations. A detailed description of the NOA concept can be found in the NAMUR Recommendation NE 175, a working document prepared by NAMUR members.
NOA enhances data accessibility and operational efficiency by creating an architecture that integrates traditional process control systems with IT systems. This integration is intended to provide a clearer view of production data without compromising the stability and security of existing automation structures.
NOA provides a dual communication channel system that allows data transfer without disrupting conventional automation processes. The architecture is designed for both existing systems (brownfield) and new installations (greenfield) and supports compatibility with advanced technologies such as the Advanced Physical Layer (APL) and the Modular Type Package (MTP).
NOA encourages the use of open interfaces and standardised protocols, enabling scalable and interoperable solutions. Collaborating with ZVEI, NAMUR has established several working groups to develop detailed guidelines, covering areas like information modelling, security zones, and aggregation servers, all of which contribute to creating a robust, future-proof framework that supports advanced analytics, edge, and cloud computing for process optimisation.
OPAF – Open Process Automation Forum
Open Process Automation Forum (OPAF) is a global collaboration of industry end users, suppliers, system integrators, academia, and standards organisations, working under The Open Group to establish a standardised, open, and interoperable architecture for process automation systems. This vendor-neutral forum focuses on developing the O-PAS™ Standard, which serves as a “standard of standards” by integrating existing and emerging frameworks to create a cohesive, secure, and adaptable automation environment.
OPAF’s mission is to design and evolve the O-PAS™ Standard—an open, interoperable architecture specification endorsed by industry stakeholders, which enhances flexibility and security in industrial process automation systems. By unifying and building upon established standards, OPAF promotes a robust, scalable approach to automation that can adapt to the evolving needs of industrial sectors.
The O-PAS™ Standard, Version 2.1 contains 7 parts. Part 6 contains six information and exchange models – Overview and Interfaces, Basic Configuration, Alarm and Event Configuration, Function Block, IEC 61499, IEC 61131 and Physical Platform.
OPAF achieves its goals through collaboration among over 110 member organisations, including leaders from various sectors. The forum actively publishes the O-PAS™ Standard along with supporting guides and white papers to drive adoption and industry alignment. OPAF’s structure encourages input from members, who participate in standard development and refinement through regular meetings, collaborative platforms, and liaison partnerships. This open architecture initiative is designed to streamline industrial automation processes by enabling secure, interoperable systems that integrate seamlessly across different platforms and technologies.
OSDU – Open Subsurface Data Universe
Open Subsurface Data Universe (OSDU) is a global data platform initiative designed to create a standardised framework for accessing and managing subsurface data in the oil and gas industry. Developed by The Open Group, OSDU helps oil and gas companies streamline data handling, enabling consistent access across multiple applications and vendors. By offering a centralised platform, OSDU aims to reduce data silos and foster collaboration, paving the way for efficient and innovative data usage in energy production.
OSDU empowers the upstream sector with a unified, open-source data platform that improves data accessibility, enhances decision-making, and accelerates innovation. This includes developing a collaborative ecosystem where oil and gas companies, service providers, and software vendors can seamlessly share and interact with subsurface data. Subsurface data refers to all data related to the geology, geophysics, and reservoir characteristics beneath the Earth’s surface that are essential for exploring and producing oil, gas, and other resources. By creating a common data model and platform, OSDU aims to break down traditional barriers between data formats and proprietary systems, promoting efficiency, transparency, and agility.
OSDU offers an open-source, cloud-native platform supported by APIs and data standards, which integrates with various cloud providers. The OSDU open-source portal provides developers and industry participants with access to the OSDU Data Platform codebase, fostering a thriving community of developers and vendors who can access tools, APIs, and updates, enabling them to build custom applications, improve data interoperability, and contribute new solutions within the upstream oil and gas sector.
PODS – Pipeline Open Data Standard
The Pipeline Open Data Standard (PODS) is a widely adopted framework that offers a robust database architecture for managing and exchanging pipeline-related data. Used by pipeline operators globally, PODS provides a consistent structure for storing essential information like asset details, inspection records, and compliance data. PODS aims to standardise pipeline data management to support regulatory compliance, asset tracking, and operational efficiency.
PODS offers a scalable Geographic Information Systems (GIS)-agnostic data model, allowing spatial data—such as pipeline routes, geolocations of assets, and environmental data—to be visualised and analysed on a map. The platform’s flexibility also allows operators to configure the model to their specific requirements, ensuring consistent data quality between vendors and across various business and asset management systems. By providing a unified data model, PODS enables companies to streamline reporting, improve decision-making, and maintain pipeline integrity.
PODS also facilitates collaboration with pipeline industry experts to keep its standards updated, ensuring alignment with technological advancements and evolving operational and regulatory needs. The PODS Model 7 is the latest version, offering a flexible, modular architecture that better supports modern pipeline data management needs.
STIX – Structured Threat Information Expression
STIX (Structured Threat Information Expression) is a standardised language developed to facilitate the sharing and analysis of cyber threat intelligence across organisations. Maintained by the OASIS Cyber Threat Intelligence Technical Committee, STIX provides a structured format for describing various aspects of cyber threats, enabling organisations to communicate threat information consistently and effectively. Together with TAXII (Trusted Automated eXchange of Indicator Information), which serves as a transport protocol, STIX helps organisations share threat intelligence securely and in real-time.
STIX’s objectives are to enhance cybersecurity resilience globally by enabling organisations to share threat intelligence in a standardised and automated manner. This collaborative approach improves threat detection, response, and prevention across sectors.
STIX provides a common language that defines eighteen STIX Domain Objects (SDOs) and two STIX Relationship Objects (SROs), which enable comprehensive descriptions of threat information. Through its integration with TAXII, STIX supports automated and secure sharing of threat intelligence, making it accessible to a broad community of cyber defenders, threat analysts, and security vendors. This standardised framework enhances situational awareness, facilitates rapid response, and fosters a coordinated defence against emerging cyber threats.
ZVEI – Zentralverband Elektrotechnik- und Elektronikindustrie
ZVEI (Zentralverband Elektrotechnik- und Elektronikindustrie), the German Electrical and Electronic Manufacturers’ Association represents the interests of Germany’s electronic and digital industries. Acting as a central force for innovation, ZVEI sets guidelines and standards that propel technological advancement, foster sustainability, and support the growth of a modern, interconnected society.
ZVEI envisions an “All-Electric Society” where electrification and digitalisation are central to a sustainable future. Their mission is to drive this transformation by facilitating technology, advocating progressive policies, and promoting sustainable practices that benefit industry and society. With a focus on renewable energy integration, efficiency, and digital solutions, ZVEI seeks to shape an electrified and digitalised world.
ZVEI collaborates with members from diverse sectors of the electro and digital industries, emphasising areas like energy efficiency, sustainability, and digital transformation. They engage in partnerships, research, and policy advocacy, with a commitment to harmonising regulations and advancing European and global standards. Through initiatives such as the Open Direct Current Alliance (ODCA) and collaborations on 5G technologies, ZVEI also addresses the unique challenges of the digital age. By providing research, guidelines, and policy recommendations, ZVEI supports the industry’s evolution toward an efficient and sustainable future, positioning Germany as a leader in the global electro-digital landscape.