Network segmentation

The first step in designing a security conscious ICS network architecture is defining network segmentation. A network segment, also known as a network security zone, is a logical grouping of information and automation systems in an ICS network. The ICS network should be divided into manageable network segments in order to limit the broadcast domain, restrict bandwidth usage, and reduce the attack surface. A network security zone has a well-defined perimeter and strict boundary protection. Security zones are given a security trust level (high, low, or medium). Within the context of an ICS network, the Industrial Zone is considered the high security zone and the Enterprise Zone the low security zone. This allows systems ...

Get Industrial Cybersecurity now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.