A Security-Integrated Agile Governance Model for IT and Operational Technology Modernisation in the Oil and Gas Sector
Main Article Content
Abstract
Information technology (IT) and operational technology (OT) are converging across the oil and gas value chain, expanding the monitoring, analytics, automation, and enterprise decision-making capabilities available to upstream, midstream, and downstream operators. Yet IT and OT environments continue to carry distinct operational and risk expectations. Enterprise IT delivery is usually judged on speed of release, frequent iteration, and architectural flexibility, whereas operational technology on a drilling pad, gathering system, pipeline, or refinery is judged on continuous availability, process safety, predictable behaviour, tightly controlled access, and disciplined change management. This paper proposes a delivery model, termed the Security-Integrated Agile IT/OT Governance Model, that embeds cybersecurity review, operational-safety assessment, and asset-owner accountability directly into the Agile modernisation workflow used for oil and gas infrastructure. Each proposed system change is classified across seven dimensions — operational criticality, connectivity exposure, privilege requirements, data sensitivity, reversibility, safety implications, and potential service interruption — and the resulting risk tier determines the controls that must be satisfied at backlog creation, design, development, testing, release approval, deployment, and post-change monitoring. The model also introduces an IT/OT Control Traceability Matrix linking every change request or user story to the affected applications and field assets, the applicable cybersecurity controls, testing evidence, access-control requirements, the accountable operational owner, the permitted maintenance window, the rollback procedure, and the final release decision. Consistent with published guidance on pipeline and process-control SCADA exposure, high-risk changes are shown to require a coordinated sequence of validation, review, assessment, approval, rollback, and monitoring activity across the full network path. Seven indicators are used to evaluate the framework: vulnerability escape rate, unauthorised-access incidents, security-review lead time, emergency-rollback frequency, unresolved control exceptions, change-failure rate, and operational downtime. Structured, risk-tiered gating, consistent with trends reported in the literature, is associated with a reduction in change-failure rate from roughly 28% to 11% and a reduction in security-review lead time from more than nine days to under four days across ten delivery sprints, while preserving Agile transparency and cadence. The paper offers a practical, standards-aligned route to sustaining Agile delivery speed while meeting the heightened security, reliability, and safety expectations of critical oil and gas installations, and closes by identifying the governance, workforce, and tooling barriers that must be addressed before the model can be adopted at scale.