NEC Annex G: Supervisory Control and Data Acquisition (SCADA)

NEC Annex G provides guidelines for the installation and maintenance of Supervisory Control and Data Acquisition (SCADA) systems, which are used for monitoring and controlling various operations, especially in critical infrastructure and industrial environments. Here is an overview of the key points in Annex G:

1. Purpose

Annex G aims to ensure that SCADA systems are installed and maintained to enhance the reliability and security of operations. These systems are critical for real-time data collection, monitoring, and control in various industries.

2. SCADA System Components

The annex outlines the essential components of SCADA systems, including:

  • Remote Terminal Units (RTUs)
  • Programmable Logic Controllers (PLCs)
  • Human-Machine Interfaces (HMIs)
  • Communication Infrastructure

3. Installation Guidelines

Details installation practices for SCADA components to ensure proper functionality and safety. This includes recommendations for:

  • Wiring MethodsEnsuring the use of appropriate wiring techniques to prevent interference and signal degradation.
  • Grounding and BondingProper grounding of SCADA components to protect against electrical faults.
  • Environmental ControlsMaintaining suitable environmental conditions to protect sensitive SCADA equipment.

4. Security Measures

Emphasizes the importance of securing SCADA systems against cyber threats and physical tampering. This includes implementing robust access controls, encryption, and regular security audits.

5. Maintenance and Testing

Outlines requirements for regular maintenance and testing of SCADA systems to ensure continuous and reliable operation. This includes routine inspections, functional tests, and updates to software and hardware components.

6. Documentation and Training

Requires comprehensive documentation of SCADA system design, installation, and maintenance procedures. Additionally, it mandates training for personnel on the operation and troubleshooting of SCADA systems to ensure effective management.

For more detailed information and specific guidelines, consulting the NEC Handbook and additional resources provided by the NFPA is highly recommended. Further insights can be found on NFPA’s official site and SunCam.

Key terms in plain language

Open a term for a concise explanation of language used on this page.

Cybersecurity

The practices and controls used to protect identities, devices, networks, applications, and data from unauthorized access, disruption, or manipulation.

Zero Trust

A security model that does not automatically trust a user or device because of its location. Access is continuously verified and limited to what is necessary.

SASE

Secure Access Service Edge combines networking and security capabilities in a cloud-delivered architecture so users and locations can receive consistent policy wherever they connect.

Identity and Access Management (IAM)

The systems and policies that determine who a user is, what resources they may access, and how that access is authenticated and reviewed.

Multi-Factor Authentication (MFA)

A login control requiring more than one form of verification, such as a password plus an authenticator app, security key, or biometric factor.

MDR / XDR

Security services and tools that monitor activity, investigate suspicious behavior, and help contain threats. MDR is managed detection and response; XDR correlates signals across multiple security layers.