SCADA Security Audit Checklist
Use this checklist to assess SCADA security controls, identify gaps, and document remediation priorities for the environment in scope.
Audit Context
Site or Facility Name
*
Audit Date
*
 -
Month
 -
Day
Year
Date
Audit Type or Scope
*
Full Site Audit
Network Segment Audit
Control Room Audit
Remote Access Review
Incident Follow-up
SCADA Environment Type
*
Electric Utility
Water/Wastewater
Manufacturing
Oil and Gas
Other
Primary System Owner or Department
*
System Inventory and Architecture
Number of Control Centers or Sites Covered
*
Key Assets and Components in Scope
*
Network Segmentation Status
*
Properly segmented
Partially segmented
Not segmented
Unknown
Critical Assets Register
*
Access Control and Authentication
Privileged account management status
*
Implemented
Partially implemented
Not implemented
Not applicable
Unique user accounts enforced
*
Yes
No
Shared accounts used for operations
*
Yes
No
Password policy strength
*
Please Select
Strong
Moderate
Weak
Not documented
Not applicable
Multi-factor authentication for remote or privileged access
*
Implemented for both remote and privileged access
Implemented for remote access only
Implemented for privileged access only
Not implemented
Not applicable
Least privilege access enforcement
*
Poor
1
2
3
4
Excellent
5
1 is Poor, 5 is Excellent
Exceptions or compensating controls
Remote Access and Third-Party Connectivity
Is remote access enabled?
*
Yes
No
Remote access method in use
*
VPN
Jump host
Vendor remote tool
Direct RDP/SSH
Other
Are remote sessions approved and logged?
*
Yes
No
Is third-party or vendor access present?
*
Yes
No
Describe controls over vendor access, session monitoring, and time-based restrictions
Network Security and Monitoring
Firewall between IT and OT zones
*
Yes
No
Partial
Planned
Allowlisting for SCADA communications
*
Yes
No
Partial
Planned
Detection and monitoring coverage for OT network traffic
*
Comprehensive
Partial
Minimal
None
Log collection and retention for SCADA devices
*
Centralized with long-term retention
Centralized with limited retention
Device-local only
Not retained
Backup of security devices and configurations
*
Yes
No
Overall visibility into OT network activity
*
1
2
3
4
5
Endpoint, Server, and Control Device Hardening
Patch management process for SCADA servers and workstations
*
Documented and regularly followed
Partially documented or inconsistently followed
Ad hoc or not formally defined
Not applicable for this environment
Current patch status for critical systems
*
Fully up to date
Minor updates pending
Significant updates pending
Not patched due to operational constraints
Not applicable
Antivirus or endpoint protection where supported
*
Installed and actively managed
Installed but not consistently managed
Not installed
Not supported on some devices
Not applicable
Unnecessary services disabled
*
Yes, consistently disabled
Partially disabled
No
Not verified
Not applicable
Removable media restrictions
*
Blocked by policy and enforced
Restricted with exceptions
Allowed with controls
Not restricted
Not applicable
Notes for exceptions, unsupported devices, or compensating controls
Backup, Recovery, and Resilience
Frequency of Backups for SCADA Servers/Configurations
*
Daily
Weekly
Monthly
After Major Changes
Other
Backup Storage Location
*
Please Select
Offline
Onsite
Offsite
Cloud
Mixed
Last Successful Restore Test Date
 -
Month
 -
Day
Year
Date
Can Critical Configurations Be Restored Within Required Time?
*
Yes
No
Partially
Not Tested
Recovery Gaps or Dependencies
Vulnerability and Change Management
Was vulnerability scanning performed in the OT environment?
*
Yes
No
Partial
Primary method used for vulnerability identification
*
Passive
Authenticated
Maintenance-window
Vendor advisory review
Other
Is formal approval required for SCADA changes?
*
Yes
No
Is emergency change logging in place?
*
Yes
No
Open vulnerabilities, pending changes, or deferred remediation items
Physical Security and Environmental Controls
Restricted access to control rooms/cabinets
*
Yes
No
Partial
N/A
Visitor logging in place
*
Yes
No
Partial
N/A
CCTV or intrusion monitoring present
*
Yes
No
Partial
N/A
Environmental alarms for power, temperature, or water
*
Yes
No
Partial
N/A
Physical security observations
Audit Findings and Overall Rating
Overall Security Posture Rating
*
1
2
3
4
5
Risk Level
*
Low
Moderate
High
Critical
Priority of Remediation
*
Immediate
High
Medium
Low
Key Findings and Recommendations
Findings Log
Submit Audit
Should be Empty: