Scoping conversation
A call or a visit to name the applications, the processes they can touch, and whether we may perform supervised write tests.
Methodology
This is the house sequence for an IoT control-application audit. It is not a maturity model and it is not a certificate. It is how we keep operations, IT, and the integrator looking at the same object.
We treat as in-scope any software that can change, or authorise a change to, a process value: operator apps, HMIs in a browser, MQTT or API command topics, edge rule engines, cloud device methods, and the accounts that can reach them.
We treat as out of scope, unless you add them in writing: safety-instrumented systems that have no IoT path, corporate email, and general IT hygiene that does not touch the control application. If a finding in the control app depends on a weak plant VLAN, we will say so without turning the week into a network redesign.
Where the engagement includes a command-path audit, we only issue a test write with a named operations person in the room, on a window they choose, on equipment they accept. If the site cannot authorise a write, we stop at observation and say so in the pack. We do not run unsolicited exploits against your plant.
A command inventory (or a tag-path dossier, depending on the service), a privilege matrix, evidence notes, and a remediation order split into “before the next vendor login” and “next planned window”. The pack is a document. You do not need our software to read it.
A call or a visit to name the applications, the processes they can touch, and whether we may perform supervised write tests.
Network sketch, role lists, broker or API notes, and a named operations contact. We will work from a whiteboard photo if that is what exists.
On site or on a staged system, we follow commands, identities, and a sample of tags until they meet the field device or the software loop.
Operations and IT hear the same record. We separate what can wait for a planned window from what should be constrained before the next vendor login.
Command inventory, privilege matrix, evidence notes, and a remediation order. No dashboard login is required to read it.