Operational Process Monitoring
Definition
Monitoring physical parameters and operator actions related to an operational environment.
Synonyms: Supervisory Control Monitoring .How it works
While some Operational Technology systems are designed to operate without human intervention, most systems are designed with the ability to monitor and modify the physical process with user input.
This technique detects adversarial risks to operational processes by observing physical events and operator actions and analyzing event logs.
Key steps in operational process security monitoring are:
Read logs generated by controllers, and HMIs, through DAU's and DA agents;
Produce digital event records;
Display the aggregated data to a device such as an HMI or process historian, and write those records to event logs and/or to the OT process data historian for traceability and incident reconstruction.
Monitor the procees and detect incidents or indicators of tampering such as:
- malfunctions
- unauthorized commands,
- unsafe setpoint changes,
- alarm suppression, and
- anomalous mode transitions;
References
The following references were used to develop the Operational Process Monitoring knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)