OIL AND GAS CONTROL

Oil and Gas Automation: How DCS, SCADA and Safety Systems Fit Together

Upstream, midstream and downstream each lean on a different control system. Where DCS, SCADA, ESD and fire and gas sit, the standards behind them, and a free route to learn them.

By EDWartens engineering team 28 November 2025 Updated 5 October 2026 8 min
Oil and Gas Automation: How DCS, SCADA and Safety Systems Fit Together

Oil and gas automation rests on three separate systems. A distributed control system (DCS) runs the process in plants, refineries and platforms. SCADA supervises wells, pipelines and terminals spread over long distances. A safety instrumented system shuts the process down when control fails. The ideas behind all three can be learnt free, before you ever sit at an engineering station.

“Difference between SIS and BPCS - Safety Instrumented Systems Training” by Instrumentation Tools, 15 min. Played from the creator's own YouTube channel; the video belongs to them.

In this lesson by Instrumentation Tools, the difference between the basic process control system (BPCS) and the safety instrumented system (SIS) is set out. It is the single most important idea in oil and gas control, so it is worth watching before the rest of this guide. Follow along, then check your understanding against the steps in the safety section below.

Upstream, midstream and downstream

The industry splits into three parts, and each leans on a different kind of control.

  • Upstream is exploration and production: wellheads, separators, water injection, offshore platforms and onshore production facilities. Remote well pads often run on PLCs or remote terminal units (RTUs) reporting to SCADA. A platform or a large production facility usually has an integrated control and safety system, which combines a DCS, an SIS and a fire and gas system under one engineering umbrella.
  • Midstream moves product: pipelines, compressor and pump stations, storage and terminals. SCADA is the main system here, with RTUs at each station, leak detection, and flow computers at metering points.
  • Downstream is refining and petrochemicals. These are large continuous plants, and a DCS runs them, often with advanced process control layered on top and an independent SIS beneath.
Control and safety systems in oil and gas
Control and safety systems in oil and gas

The DCS: control for a process plant

A DCS is built for plants where hundreds or thousands of loops run continuously and must be operated from one control room. Compared with a set of PLCs, it gives you one engineering database, one alarm system, controller and network redundancy as standard, and operator graphics that are generated from the same configuration as the control logic.

The daily work is regulatory control: PID loops, cascades (a level controller setting a flow controller's setpoint), ratio control, split-range control of two valves from one output, and override selection when two constraints compete. On top of that come sequences for start-up, shutdown and batch operations.

The major platforms you will see named in job adverts include Emerson DeltaV, Yokogawa CENTUM VP, Honeywell Experion PKS, ABB System 800xA and Siemens PCS 7. Our DCS training guide explains how a distributed control system is organised and how to learn one. Each has its own vocabulary, but the ideas carry over: control modules, function blocks, I/O assignment, faceplates, alarm priorities and historian tags.

Two operator-side standards matter wherever a DCS runs. [ISA-18.2](https://www.isa.org/standards-and-publications/isa-standards/isa-18-series-of-standards) (published internationally as IEC 62682) covers alarm management: every alarm should need an operator action, and a flood of nuisance alarms is treated as a design fault. [ISA-101](https://www.isa.org/standards-and-publications/isa-standards/isa-101-standards) covers HMI design, including the move away from brightly coloured graphics towards grey screens where colour is reserved for abnormal conditions.

SCADA: supervising assets spread over distance

A pipeline or a field of well pads cannot be wired back to one control room. SCADA collects data from RTUs or PLCs at each site over radio, cellular, satellite or fibre links, usually reporting by exception to save bandwidth. The protocols you will meet include Modbus, DNP3 and IEC 60870-5-104.

The pipeline sector has its own recommended practices from the American Petroleum Institute. API RP 1165 covers pipeline SCADA displays, API RP 1167 covers pipeline SCADA alarm management, and API RP 1130 covers computational pipeline monitoring, the software methods used to detect leaks from flow, pressure and temperature data. Metering at custody transfer points follows the API Manual of Petroleum Measurement Standards (MPMS), with flow computers calculating corrected volumes.

If SCADA is new to you, the free platforms and courses are compared in free SCADA courses with certificate.

Safety systems: SIS, ESD and fire and gas

The process sector's functional safety standard is [IEC 61511](https://webstore.iec.ch/en/publication/24241), which applies the principles of IEC 61508 to process plants. Its core idea is independence: the SIS protects the plant when the BPCS fails, so it must not share the failure. That usually means separate sensors, a separate safety logic solver and separate final elements such as shutdown valves. Safety PLCs, SIL and SIS explained covers the logic solver side in more detail.

To check what you took from the video, work through these steps on one shutdown you know:

  1. Name the hazard, for example overpressure of a separator.
  2. Name the initiator: which transmitters, and how they vote. Three transmitters voting two out of three (2oo3) is common where both safety and freedom from spurious trips matter.
  3. State the trip point and the safe state, for example close the inlet shutdown valve.
  4. State the response time the process allows.
  5. Write it as one sentence: on this measurement, at this value, do this action, to this safe state, in this time. That sentence is a safety instrumented function (SIF).
  6. Ask what the BPCS shares with it. A shared transmitter, card or power supply is a common cause that quietly defeats the separation.

The SIL each SIF needs comes from a risk analysis, commonly a layer of protection analysis (LOPA), and is then proved by a probability-of-failure-on-demand calculation and by periodic proof testing. Most shutdown systems are designed de-energise to trip, so loss of power or a broken wire drives the plant to its safe state.

Emergency shutdown systems are usually arranged in a hierarchy, from a single unit trip up to a full facility shutdown. The number of levels and their names differ from one operator to the next, so learn the principle rather than one company's numbering.

Fire and gas systems detect flammable or toxic gas, flame and heat, then start executive actions: alarms, ventilation changes, deluge, and initiation of the ESD. ISA's technical report ISA TR84.00.07 gives guidance on judging whether detector coverage is effective.

Hazardous areas and cybersecurity

Much of the equipment sits in areas where a flammable atmosphere can occur. The IEC 60079 series defines hazardous area zones and the protection concepts for equipment used in them, and certification schemes such as IECEx and ATEX apply them. A control engineer does not need to be an Ex inspector, but must know why a transmitter in Zone 1 is not a like-for-like swap with a standard one.

Remote sites connected by public networks also make oil and gas an early focus for OT security. ISA/IEC 62443 gives the zones and conduits model most operators now use to separate control, safety and business networks; our guide to OT cybersecurity explains it. The 2026 PLC cyber attacks attributed to Iranian-affiliated actors, which knocked a small UK power generator offline, show why energy sites take it seriously.

A free oil and gas automation learning route

A learning order for oil and gas control
A learning order for oil and gas control
  1. Start with Industrial Instrumentation and Process Control: transmitters, control valves, 4-20 mA loops, P&IDs, HART and calibration.
  2. Add PID Control for loop tuning, cascade and split-range.
  3. Take one DCS course in depth: Emerson DeltaV, Yokogawa CENTUM VP, Honeywell Experion PKS, Siemens PCS 7 or ABB System 800xA. All are listed under free DCS courses.
  4. Learn safety properly with Safety Instrumented Systems and SIL to IEC 61511, which needs no software.
  5. Finish with OT and ICS Cybersecurity with ISA/IEC 62443.

The process control path groups the instrumentation, PID and drives courses with a PLC course if you want a single starting bundle.

Be clear about one limit. DCS software is licensed and is rarely available to individuals, so the DCS courses teach from lessons recorded on training systems. You will understand the architecture and the engineering workflow, and be able to talk about both in an interview. Hands-on configuration comes later, on an employer's system or in a classroom.

Start the courses

Every course above is free in full: video lessons from independent creators credited on each course page, written notes, a practice task per module and one final assessment of 15 questions (60% to pass, three attempts). Create a free account so your progress is saved.

The optional EDWartens Certificate of Completion is issued after you pass. It is a small one-off fee that follows the course level: US$8.99 for a beginner course such as instrumentation, and more for an intermediate one such as the DCS courses or an advanced one such as the SIS course. Anyone can check it at edwartens.com/verification. It is not a vendor certification such as a DeltaV or CENTUM qualification, and it is not a functional safety certification or an accredited award.

Take the free course

Questions

Is DCS or SCADA used more in oil and gas?

Both, in different places. A DCS usually runs process plants such as refineries, gas plants and platform topsides, while SCADA supervises assets spread over distance, such as pipelines, well pads and terminals.

What is the difference between ESD and SIS?

An emergency shutdown (ESD) system is one kind of safety instrumented system. SIS is the general IEC 61511 term for any system of sensors, logic solver and final elements that takes a process to a safe state; ESD names the shutdown function it performs.

Why is the safety system kept separate from the DCS?

So that a single failure cannot take out both the control and the protection. IEC 61511 expects the safety layer to be independent of the basic process control system, including its sensors, logic and valves where the risk analysis requires it.

Can I learn a DCS without access to a real one?

You can learn the concepts, the architecture and the engineering workflow from recorded lessons on training systems, which is how the free DeltaV, CENTUM VP, Experion, PCS 7 and 800xA courses work. Hands-on configuration of a real system needs a licensed engineering station, usually at an employer or a training centre.

What does SIL mean?

Safety Integrity Level: a measure, from SIL 1 to SIL 4, of how much risk reduction a safety instrumented function must provide. It is set by a risk analysis such as LOPA and then proved by calculation and proof testing.

Sources

Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.