EN-GUIDE-04 · SCADA END-TO-END EVIDENCE

SCADA Observation, Command & Physical Readback Evidence

A correct-looking value or a successful command response does not prove the field state. Reconcile point identity, quality and time, then connect one authorized request to its actual field output and independent physical readback.

  • Reviewed: 23 July 2026
  • Audience: owner · OEM · integrator · operations
  • Output: point and command validation record
SCADA evidence chain from source equipment through trustworthy observation and authorized command to independent physical readback
Explanatory evidence structure, not a customer system, field value, work permit or control authorization.

A responsive HMI is observation—not proof of safe actuation or operational release.

Trust the point. Authorize the request. Prove the physical result.

Keep source identity, point contract, value, status, source/server time, alarm state, session and authority, command request/result, field output and independent readback on one event record. This guide defines evidence gates; it does not supply universal thresholds, timeouts, alarm priorities, network architecture or release values.

Conditions that reopen the end-to-end evidence chain

  • A stale, substituted or uncertain value is shown as if it were current and good.
  • The source, gateway, SCADA and historian disagree on units, scaling, state or event order.
  • An alarm appears, clears, acknowledges or confirms differently after reconnect or restart.
  • A command is accepted but the field device, process or independent feedback does not change.
  • Feedback mirrors the command bit or logic state rather than a separate physical indication.
  • Communication loss or recovery creates a gap, duplicate event, stale state or unexplained alarm transition.

Hold when identity, trust, authority or independent feedback is missing.

Mapping unknown

The source, address, data type, unit, scale, normal state or active configuration is not reconciled.

Quality or time hidden

Status/quality, timestamp meaning or the time source cannot be observed or trusted.

Authority unknown

The operator, session, local/remote mode, permit, approval or final release owner is open.

Control impact unknown

Output, interlock, inhibit, bypass, permissive, safety or process consequence has not been reviewed.

No independent readback

The only feedback is the command or software state, with no separate field or process indication.

Hazardous test unapproved

The test requires live work, motion, process consequence or a bypass without a qualified method and authorization.

Make each displayed state traceable to its source and physical consequence.

Evidence groupMinimum recordDecision supported
System identitySite/process boundary, source device, controller/gateway, SCADA/server/client, versions and active topologyFixes the actual system under review.
Point contractSource/tag/address, data type, unit, scale, normal state, update/report behavior and active mapping revisionDefines what the point is expected to mean.
Observation qualityValue, status/quality, source timestamp, server timestamp, time source and clock-quality noteSeparates current source evidence from a cached or uncertain display.
Alarm conditionCondition/event identity, active/inactive, acknowledged/confirmed, retained/branch state and operator comment where supportedPreserves alarm lifecycle rather than screen color alone.
Command authorityNamed operator/session, role, local/remote mode, permit, permissive/interlock/inhibit and bounded test approvalShows who could request what, under which boundary.
Command transactionRequested point/value, request time, service and operation result, diagnostic detail and intermediate/asynchronous stateSeparates request acceptance from completion at the data source.
Physical proofField output, independent auxiliary/limit/status indication, process response and time-aligned observationCloses the loop at the actual equipment and process.
Failure/recoveryLink/server/client loss, buffer/queue behavior, reconnect/restart, gap/duplicate reconciliation, rollback and as-left resultTests whether trust survives the defined failure states.

Do not advance on a green screen or a single “Good” result.

Four SCADA evidence gates: hold, observe, controlled command and release
The gates organize evidence and authority. They do not imply universal thresholds, command permission or acceptance values.
GateRequired evidenceResult
HoldUnknown mapping, hidden quality/time, unsafe boundary, unclear authority or missing independent feedback.Maintain or restore safe state; do not command.
ObserveReconciled point contract, value/status/time, alarm lifecycle and defined loss/recovery behavior.The displayed state can be interpreted within its documented limits.
Controlled commandOne authorized request, expected effect, interlock/permissive state, stop/rollback, command result and qualified observer.Run one bounded test without expanding the operating scope.
ReleaseIndependent physical readback, process outcome, failure/recovery proof, as-left records and named acceptance.Return only the accepted operating scope.

Move from point identity to an accepted physical result.

  1. 01
    Fix the system and safety boundary.

    Name the source, controllers, gateways, servers, clients, process consequence, safety functions, modes and decision authorities.

  2. 02
    Preserve the active point contract.

    Export or record source/tag/address, type, unit, scale, normal state, update/report behavior, mapping revision and as-found topology.

  3. 03
    Prove trustworthy observation.

    Compare source and SCADA values with status/quality, source/server timestamps, clock basis, alarm lifecycle and communication state visible.

  4. 04
    Authorize one bounded command.

    State the operator/session, mode, requested point/value, expected effect, interlock/permissive, stop condition, rollback and approval.

  5. 05
    Trace request to physical readback.

    Record service and operation result, field output, independent feedback, actual process response and event order. A software echo alone is not proof.

  6. 06
    Test failure and hand over the as-left state.

    Verify the approved loss/reconnect/restart scenarios, reconcile gaps or duplicates, restore the accepted configuration and name open limitations.

Questions for the responsible control, operations and cybersecurity reviewers

  • Does the point contract match the active source configuration and exact protocol/profile implementation?
  • Can the operator distinguish value, quality/status, source time, server time and stale/substituted states?
  • Are alarm active, acknowledged, confirmed, shelved/suppressed and retained states implemented and recovered as expected?
  • Does the result prove only server acceptance, or also update of the underlying data source and physical equipment?
  • Is feedback independent of the command path, and does it represent the intended physical or process state?
  • Which failure modes, residual uncertainties and operating restrictions remain after the test?

Leave enough evidence to reproduce each observation and command decision.

  • Approved topology and complete endpoint/version inventory
  • Point contract and active mapping revision
  • Original values, status/quality, timestamps and alarm records
  • Time-source and clock-quality statement
  • Authority, session, mode, permit and command transaction
  • Independent field/process readback and time-aligned outcome
  • Loss/recovery/restart test, gaps, duplicates and reconciliation
  • As-left exports, rollback, limitations, owner and acceptance
Download the reviewed PDF

Use each standard within its protocol, product, country and site scope.

  1. NIST SP 800-82 Rev. 3 — Guide to Operational Technology Security
  2. OPC UA Part 4 — DataValue, StatusCode, SourceTimestamp and ServerTimestamp
  3. OPC UA Part 4 — Write service and operation-level results
  4. OPC UA Part 9 — Acknowledgeable Condition model
Application limit

NIST SP 800-82 is United States government guidance. OPC UA constructs are protocol-specific and do not describe every SCADA protocol or product implementation. Confirm the country, authority having jurisdiction, site permits, qualified-person requirements, cybersecurity program, actual protocol profile and product version, OEM instructions and responsible engineering/operations approval. This page does not authorize scanning, connection, command, bypass, energization or restart.