OT–IT Integration Security & Data Mapping Checklist

An interactive, practical checklist to plan secure OT–IT integrations: inventory assets, define data contracts, capture latency and safety constraints, specify access and segmentation, map fields and transforms, and record testing, monitoring, and ownership details.

Interactive Tool

OT–IT Integration Security & Data Mapping Checklist

This checklist helps planning teams and engineers ensure OT–IT integrations are secure, reliable, and safe. Use it to capture the minimum technical and operational details required before connecting PLC/SCADA signals to IT systems, dashboards, or analytics platforms. Be explicit about safety impacts, data contracts, latency requirements, access controls, segmentation, testing, monitoring, and ownership.

Tip: Save this form as a record for change control and handover to operations, security, and IT when the integration moves to implementation.

E.g., 'PLC-123 temperature tags -> Condition Monitoring DB'
Person responsible for questions and approvals
Have all source devices, tags, controllers, and network endpoints been listed?
Paste or summarize the asset list or reference an asset registry entry. Include PLC IDs, channel names, and locations.
Are the exact tag names, units, and data types specified?
Provide a short CSV or indicate a referenced schema document. Example heading: SourceTag,SourceType,Unit,DestinationField,Transform
Does the consumer require near-real-time data? Are there max acceptable delays?
Enter milliseconds or leave blank if not applicable
Does the integration read or write values that could affect safe operation?
If yes, additional safety engineering and approvals are required.
E.g., what happens on connectivity loss, stale data, invalid values? Specify safe defaults and interlock behavior.
Have roles, least-privilege rules, and authentication mechanisms been selected?
Choose the minimum necessary privilege
TLS or equivalent for all OT-IT communication
For data persisted in IT systems that may contain sensitive or regulated info
Has a network path with minimal exposure been designed? Include VLANs, firewalls, and jump hosts if needed.
Document recommended ports, allowed source/destination IPs, and jump-host requirements.
How will changes to data shape be managed and communicated?
Provide a small mapping table or paste CSV rows: SourceTag, SourceType, Unit, DestinationField, DestinationType, Transform/Notes, Owner
Are devices NTP-synced and is timestamp format agreed (UTC/ISO8601)?
What metrics will be monitored (latency, freshness, error rates)? Where do alerts go?
Who can access logs and for how long? Include log aggregation / correlation needs.
Describe unit tests, integration tests, data validation checks, and acceptance criteria.
Is there a documented process to deploy, roll back, and communicate changes to consumers?
Use this to prioritize approval and testing effort
List required approvals (OT engineer, IT security, safety, operations manager).
Paste links to diagrams, schemas, tickets, or confluence pages.
You can explore this tool now. Sign in or create an account to save your responses and return to them later.
Make this tool part of your work

Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.

Member customization and team collaboration are coming soon.

Discussion

Comments and conversation will live here.