EN-GUIDE-04 · SCADA END-TO-END EVIDENCE
SCADA Observation, Command & Physical Readback Evidence
A correct-looking value or a successful command response does not prove the field state. Reconcile point identity, quality and time, then connect one authorized request to its actual field output and independent physical readback.
DECISION SUMMARY
A responsive HMI is observation—not proof of safe actuation or operational release.
OBSERVABLE SYMPTOMS
Conditions that reopen the end-to-end evidence chain
- A stale, substituted or uncertain value is shown as if it were current and good.
- The source, gateway, SCADA and historian disagree on units, scaling, state or event order.
- An alarm appears, clears, acknowledges or confirms differently after reconnect or restart.
- A command is accepted but the field device, process or independent feedback does not change.
- Feedback mirrors the command bit or logic state rather than a separate physical indication.
- Communication loss or recovery creates a gap, duplicate event, stale state or unexplained alarm transition.
STOP-WORK CONDITIONS
Hold when identity, trust, authority or independent feedback is missing.
The source, address, data type, unit, scale, normal state or active configuration is not reconciled.
Status/quality, timestamp meaning or the time source cannot be observed or trusted.
The operator, session, local/remote mode, permit, approval or final release owner is open.
Output, interlock, inhibit, bypass, permissive, safety or process consequence has not been reviewed.
The only feedback is the command or software state, with no separate field or process indication.
The test requires live work, motion, process consequence or a bypass without a qualified method and authorization.
DATA TO COLLECT
Make each displayed state traceable to its source and physical consequence.
| Evidence group | Minimum record | Decision supported |
|---|---|---|
| System identity | Site/process boundary, source device, controller/gateway, SCADA/server/client, versions and active topology | Fixes the actual system under review. |
| Point contract | Source/tag/address, data type, unit, scale, normal state, update/report behavior and active mapping revision | Defines what the point is expected to mean. |
| Observation quality | Value, status/quality, source timestamp, server timestamp, time source and clock-quality note | Separates current source evidence from a cached or uncertain display. |
| Alarm condition | Condition/event identity, active/inactive, acknowledged/confirmed, retained/branch state and operator comment where supported | Preserves alarm lifecycle rather than screen color alone. |
| Command authority | Named operator/session, role, local/remote mode, permit, permissive/interlock/inhibit and bounded test approval | Shows who could request what, under which boundary. |
| Command transaction | Requested point/value, request time, service and operation result, diagnostic detail and intermediate/asynchronous state | Separates request acceptance from completion at the data source. |
| Physical proof | Field output, independent auxiliary/limit/status indication, process response and time-aligned observation | Closes the loop at the actual equipment and process. |
| Failure/recovery | Link/server/client loss, buffer/queue behavior, reconnect/restart, gap/duplicate reconciliation, rollback and as-left result | Tests whether trust survives the defined failure states. |
DECISION GATES
Do not advance on a green screen or a single “Good” result.
| Gate | Required evidence | Result |
|---|---|---|
| Hold | Unknown mapping, hidden quality/time, unsafe boundary, unclear authority or missing independent feedback. | Maintain or restore safe state; do not command. |
| Observe | Reconciled point contract, value/status/time, alarm lifecycle and defined loss/recovery behavior. | The displayed state can be interpreted within its documented limits. |
| Controlled command | One authorized request, expected effect, interlock/permissive state, stop/rollback, command result and qualified observer. | Run one bounded test without expanding the operating scope. |
| Release | Independent physical readback, process outcome, failure/recovery proof, as-left records and named acceptance. | Return only the accepted operating scope. |
SIX-STEP PROCEDURE
Move from point identity to an accepted physical result.
- 01Fix the system and safety boundary.
Name the source, controllers, gateways, servers, clients, process consequence, safety functions, modes and decision authorities.
- 02Preserve the active point contract.
Export or record source/tag/address, type, unit, scale, normal state, update/report behavior, mapping revision and as-found topology.
- 03Prove trustworthy observation.
Compare source and SCADA values with status/quality, source/server timestamps, clock basis, alarm lifecycle and communication state visible.
- 04Authorize one bounded command.
State the operator/session, mode, requested point/value, expected effect, interlock/permissive, stop condition, rollback and approval.
- 05Trace request to physical readback.
Record service and operation result, field output, independent feedback, actual process response and event order. A software echo alone is not proof.
- 06Test failure and hand over the as-left state.
Verify the approved loss/reconnect/restart scenarios, reconcile gaps or duplicates, restore the accepted configuration and name open limitations.
EXPERT REVIEW
Questions for the responsible control, operations and cybersecurity reviewers
- Does the point contract match the active source configuration and exact protocol/profile implementation?
- Can the operator distinguish value, quality/status, source time, server time and stale/substituted states?
- Are alarm active, acknowledged, confirmed, shelved/suppressed and retained states implemented and recovered as expected?
- Does the result prove only server acceptance, or also update of the underlying data source and physical equipment?
- Is feedback independent of the command path, and does it represent the intended physical or process state?
- Which failure modes, residual uncertainties and operating restrictions remain after the test?
HANDOVER PACKAGE
Leave enough evidence to reproduce each observation and command decision.
- Approved topology and complete endpoint/version inventory
- Point contract and active mapping revision
- Original values, status/quality, timestamps and alarm records
- Time-source and clock-quality statement
- Authority, session, mode, permit and command transaction
- Independent field/process readback and time-aligned outcome
- Loss/recovery/restart test, gaps, duplicates and reconciliation
- As-left exports, rollback, limitations, owner and acceptance
OFFICIAL PRIMARY SOURCES
Use each standard within its protocol, product, country and site scope.
- NIST SP 800-82 Rev. 3 — Guide to Operational Technology Security
- OPC UA Part 4 — DataValue, StatusCode, SourceTimestamp and ServerTimestamp
- OPC UA Part 4 — Write service and operation-level results
- OPC UA Part 9 — Acknowledgeable Condition model
NIST SP 800-82 is United States government guidance. OPC UA constructs are protocol-specific and do not describe every SCADA protocol or product implementation. Confirm the country, authority having jurisdiction, site permits, qualified-person requirements, cybersecurity program, actual protocol profile and product version, OEM instructions and responsible engineering/operations approval. This page does not authorize scanning, connection, command, bypass, energization or restart.