Protection IED Cybersecurity FAT and SAT Checklist

A practical IEC 62351-aligned checklist for procurement, FAT, commissioning and handover of protection and control IEDs.

Printable checklist availableDownload the formatted A4 checklist with status boxes, evidence fields, project details and approval record.

Download PDF checklist A4 PDF · 2 pages

This checklist complements, rather than replaces, an organisation’s security policy. Apply controls according to consequence and the approved substation architecture.

Asset and trust baseline

  • Record manufacturer, exact model, serial number, order code, firmware and option licences.
  • List enabled services, listening ports, protocols, user roles and certificate dependencies.
  • Confirm approved firmware source, signature or integrity verification and rollback plan.

Identity and access

  • Remove or change default credentials before energisation.
  • Use named roles where supported; separate engineering, operation and audit privileges.
  • Control local front-port, USB, Bluetooth, Wi-Fi and maintenance access.
  • Document emergency access and credential recovery without creating a permanent bypass.

Network and protocol controls

  • Disable unused services and legacy protocols.
  • Verify segmentation, engineering-station routes, firewall rules and remote-access path.
  • Check IEC 62351 capabilities against the project’s interoperable profile.
  • Test loss, delay and restoration without compromising protection dependability.

Logging and monitoring

  • Synchronise time and verify event timestamps.
  • Record authentication, configuration and firmware events.
  • Confirm log extraction, retention, capacity and behaviour when storage fills.

Handover evidence

Deliver the authorised configuration, firmware hash, user/role list, certificates and expiry dates, open vulnerabilities, network diagram, backup/restore evidence and named owner for future security advisories.

LearnSwitchgear

Search the engineering library