Zones & Conduits

« Back to Glossary Index

The security architecture framework from IEC 62443-3-2 that makes network segmentation practically workable – based on process logic, not technology tiers.

Technical Definition: Zones and Conduits is the design framework in IEC 62443-3-2 for structuring OT network security. A Security Zone is a logical or physical grouping of assets that share common security requirements and trust relationships. A Conduit is the controlled communication channel between zones – where security controls are applied and traffic is governed.

Why it improves on Purdue-based segmentation: Unlike the Purdue Model (which groups systems by technology tier), Zones and Conduits groups assets by what they do together and who needs to trust whom. A zone may span multiple Purdue levels if it serves a single production cell – reflecting how the facility actually operates, not how a diagram looks.

Key concepts:

  • Security Zone – defined by shared security requirements and trust, not by technology type or vendor.
  • Conduit – can be implemented as a firewall with rules, a data diode (unidirectional gateway), a DMZ with controlled services, or an air gap.
  • Security Level (SL 1–4) – SL1 = protection against unintentional violations. SL2 = simple intentional attacks. SL3 = sophisticated attack capability. SL4 = state-sponsored capability.
  • Zone boundary rule – all communication crossing a zone boundary must pass through a defined and controlled conduit. No exceptions.
  • SL inheritance – a zone’s required security level is determined by its most critical asset. A zone is never more secure than its most sensitive element.

The design process in brief: Inventory all assets → group by process function and operational trust → map all cross-zone communication → assign Security Level targets (SL-T) based on consequence analysis → select and implement conduit controls → document and verify.

HubMind’s view: A zone is defined by operational logic, not by which Purdue level an asset sits on. Getting this right – grounding zones in the facility’s actual dependencies and risk profile – is the foundation of an OT security architecture that works in practice, not just on paper.

External links: ISA/IEC 62443-3-2 (the standard). See also IEC 62443 and Purdue Model in the HubMind glossary.

« Back to Glossary Index
Contact us