Note

Building an evidence pack before we arrive

Daniel Khoo

Two colleagues discussing documents at a work table

We can start from a blank page. We would rather not. The quality of a control-application audit tracks the quality of what you can show us in the first two days.

A useful pack is boring:

  • A network sketch that includes the broker, the gateways, and the operator devices, even if it is a photo of a whiteboard.
  • A list of control applications (vendor name, version, who pays the licence).
  • Role names as the app knows them, not as HR knows them.
  • One example of a change ticket, even a messy one.
  • MQTT or API documentation if it exists; a capture if it does not.
  • Named contacts for operations, IT, and the integrator, with who can authorise a test write.

Do not wait for a perfect CMDB. Do not redact so hard that we cannot see a hostname. Mark secrets and give them to us on paper at the site if you prefer; we do not need passwords in email.

If you are requesting a scoping conversation, you do not need this pack yet. If you have already booked a command-path audit, sending it a week ahead means we spend the first morning on the line instead of reconstructing how the tablet talks to the pump.

All notes