SCADA/ICS System Documentation
Identifies substantive SCADA and industrial-control-system documentation. Topic phrases are retained for discovery; enforcement requires point, tag, I/O, alarm, HMI, RTU, protocol-map, polling, or control-logic configuration content, and high confidence also requires a populated asset, node, address, register, outstation, or site detail.
- Type
- regex
- Engine
- boost_regex
- Confidence
- medium
- Confidence justification
- Medium confidence requires substantive control-system configuration content. High confidence adds a deployable asset, node, address, protocol register, outstation, or site value.
- Jurisdictions
- global
- Regulations
- Criminal Code Act 1995 (Cth), SOCI Act 2018 (Cth)
- Frameworks
- CIS Controls, ISO 27001, NIST CSF
- Data categories
- infrastructure, technology
- Scope
- narrow
- Risk rating
- 10
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported
Pattern
(?is)\b(?:SCADA\s+(?:system|configuration|network|architecture)\s+documentation|ICS\s+(?:system|configuration|network|architecture)\s+documentation|industrial\s+control\s+system\s+(?:documentation|configuration\s+manual)|SCADA/ICS\s+(?:documentation|architecture))\b
Should match
SCADA system documentation— Low-tier probe - document topic without configuration contentSCADA configuration documentation: tag database, I/O mapping, alarm configuration, HMI screen, and Modbus register map— Medium-tier probe - substantive configuration content without populated live valuesSCADA system documentation for production RTU node RTU-07 at 10.24.8.15: protocol register map contains Modbus register 40017, and the tag database maps PUMP_RUN to HMI node HMI-02— High-tier probe - configuration content with populated asset, address, register, tag, and node details
Should not match
Remote control for the television— Non-match 1System documentation for the website— Generic IT documentation outside industrial controlThe vendor guide introduces SCADA system architecture.— Product overview without a configuration recordTraining example: SCADA system documentation for RTU-07 at 10.24.8.15, Modbus register 40017— Explicit training content must not enforce
Known false positives
- Vendor manuals, standards, and engineering courses discuss SCADA, PLCs, HMIs, RTUs, and OT protocols without exposing a live system configuration. Mitigation: Keep document topics discovery-only and require point, tag, I/O, alarm, HMI, RTU, polling, protocol-map, or control-logic content for enforcement.
- Training labs can include realistic asset IDs, IP addresses, register numbers, tags, and node names. Mitigation: Reject explicit template, demo, tutorial, sample-data, and training-example framing from enforcing tiers.