The security architecture framework from IEC 62443-3-2 that makes network segmentation practically workable – based on process logic, not technology tiers.
Technical Definition: Zones and Conduits is the design framework in IEC 62443-3-2 for structuring OT network security. A Security Zone is a logical or physical grouping of assets that share common security requirements and trust relationships. A Conduit is the controlled communication channel between zones – where security controls are applied and traffic is governed.
Why it improves on Purdue-based segmentation: Unlike the Purdue Model (which groups systems by technology tier), Zones and Conduits groups assets by what they do together and who needs to trust whom. A zone may span multiple Purdue levels if it serves a single production cell – reflecting how the facility actually operates, not how a diagram looks.
Key concepts:
- Security Zone – defined by shared security requirements and trust, not by technology type or vendor.
- Conduit – can be implemented as a firewall with rules, a data diode (unidirectional gateway), a DMZ with controlled services, or an air gap.
- Security Level (SL 1–4) – SL1 = protection against unintentional violations. SL2 = simple intentional attacks. SL3 = sophisticated attack capability. SL4 = state-sponsored capability.
- Zone boundary rule – all communication crossing a zone boundary must pass through a defined and controlled conduit. No exceptions.
- SL inheritance – a zone’s required security level is determined by its most critical asset. A zone is never more secure than its most sensitive element.
The design process in brief: Inventory all assets → group by process function and operational trust → map all cross-zone communication → assign Security Level targets (SL-T) based on consequence analysis → select and implement conduit controls → document and verify.
HubMind’s view: A zone is defined by operational logic, not by which Purdue level an asset sits on. Getting this right – grounding zones in the facility’s actual dependencies and risk profile – is the foundation of an OT security architecture that works in practice, not just on paper.
External links: ISA/IEC 62443-3-2 (the standard). See also IEC 62443 and Purdue Model in the HubMind glossary.
« Back to Glossary Index
