SCADA and HMI Systems

Read revision 3

Revision 3 · Aug 26, 2026 +12 −12

Corpus sync: neutrality remakes, note hygiene, datasheet relocation, transformer-split cross-refs
Showing changes from Rev 2 to Rev 3 in SCADA and HMI Systems.
---
title: SCADA and HMI Systems
199 unchanged lines
### A client/server architecture separates the SCADA server(s) and historian from multiple thin or full HMI clients, allowing many operator workstations to share one authoritative database and scaling to large plants; it is the standard for process and water/wastewater facilities. {note}
+### The architecture shall be selected for the size and criticality of the process and shall be [[drawing: as indicated on the control system architecture drawing]].
+
```datasheet
label: System Architecture
6 unchanged lines
```
### The architecture shall be selected for the size and criticality of the process and shall be [[drawing: as indicated on the control system architecture drawing]].
### A loss of the SCADA layer shall not by itself stop the process, because real-time regulatory control and interlocks reside in the field controllers ([[sync/programmable-logic-controllers]]) and continue to run independently of the SCADA.
2 unchanged lines
### Server redundancy protects continuous monitoring and supervisory control against the failure of a single server. {note}
+### For critical process and water/wastewater facilities, the SCADA servers shall be configured as a redundant hot-standby (active/standby) pair.
+
```datasheet
label: SCADA Server Redundancy
6 unchanged lines
```
### For critical process and water/wastewater facilities, the SCADA servers shall be configured as a redundant hot-standby (active/standby) pair.
### The standby server shall maintain a synchronized copy of the real-time database and shall assume control automatically on failure of the primary, with no operator intervention required.
27 unchanged lines
## Remote Operator Access {toc}
### Remote operator access shall be provided only through the secured remote-access path coordinated with [[sync/process-control-networks]]. {note}
+### Remote operator access shall be provided only through the secured remote-access path coordinated with [[sync/process-control-networks]].
```datasheet
12 unchanged lines
### Remote access shall be logged and shall be subject to the same role-based permissions as local access.
### Unsecured remote access to a process SCADA system is among the most exploited attack vectors on critical infrastructure; remote access shall never bypass the security architecture established in [[sync/process-control-networks]]. {note}
+### Unsecured remote access to a process SCADA system is among the most exploited attack vectors on critical infrastructure; remote access shall never bypass the security architecture established in [[sync/process-control-networks]].
# HMI Design and Graphics {toc}
60 unchanged lines
### An alarm philosophy document shall be established defining what constitutes an alarm, the priority scheme, the design of alarm presentation, and the performance metrics used to manage the alarm system.
### An alarm shall be defined as an audible and/or visible indication of an abnormal condition that requires a timely operator response; status changes and information that require no response shall not be configured as alarms. {note}
+### An alarm shall be defined as an audible and/or visible indication of an abnormal condition that requires a timely operator response; status changes and information that require no response shall not be configured as alarms.
### Every alarm shall be rationalized — justified, prioritized, and documented — before it is configured, and the rationalized alarm list shall be a submittal.
56 unchanged lines
### The historian shall be capable of backfilling from controller or local buffers after a communication or server interruption so that no recorded data is lost during the outage.
### Loss of the SCADA link must not create a permanent gap in the historical record; backfill from controller buffers on restoration closes the gap that would otherwise compromise regulatory reporting. {note}
+### Loss of the SCADA link must not create a permanent gap in the historical record; backfill from controller buffers on restoration closes the gap that would otherwise compromise regulatory reporting.
## Historian Configuration {toc}
25 unchanged lines
### The historian retention period shall meet or exceed the longest applicable regulatory recordkeeping requirement for the facility.
### Water and wastewater facilities have regulatory reporting obligations that depend on the historical record; the retention period shall be confirmed against the governing permit and regulatory requirements. {note}
+### Water and wastewater facilities have regulatory reporting obligations that depend on the historical record; the retention period shall be confirmed against the governing permit and regulatory requirements.
## Trending {toc}
24 unchanged lines
### Where the field architecture is geographically distributed (remote pump stations, lift stations, well sites, tanks), a report-by-exception telemetry protocol such as DNP3 (IEEE 1815) shall be used to conserve communication bandwidth.
### Open protocols shall be preferred over proprietary drivers so that the Owner is not locked to a single vendor for future expansion; this requirement is coordinated with [[sync/process-control-networks]]. {note}
+### Open protocols shall be preferred over proprietary drivers so that the Owner is not locked to a single vendor for future expansion; this requirement is coordinated with [[sync/process-control-networks]].
## Polling and Scan Rate {toc}
205 unchanged lines
### The software manufacturer shall provide security patches and updates for the warranty term, and the integrator shall apply approved patches under a coordinated change-management procedure.
### Patches shall be tested before application to the production system, because an untested patch can break a working SCADA configuration as readily as it fixes a vulnerability. {note}
+### Patches shall be tested before application to the production system, because an untested patch can break a working SCADA configuration as readily as it fixes a vulnerability.
# Spare Parts and Software {toc}
17 unchanged lines
### Where the Owner elects to stock spare workstation hardware, one spare of each workstation type shall be provided, pre-loaded or imaged so it can replace a failed unit quickly.
### The recovery package shall be sufficient for the Owner, or a different integrator, to rebuild the system; the Owner shall not be dependent on a single integrator for disaster recovery. {note}
+### The recovery package shall be sufficient for the Owner, or a different integrator, to rebuild the system; the Owner shall not be dependent on a single integrator for disaster recovery.

View current revision