Glossary · OT cybersecurity
Demilitarized zone (DMZ) for OT
Also known as: OT DMZ, Perimeter network
German: Demilitarisierte Zone (DMZ) für OT
In OT network security, a demilitarized zone (DMZ) is a separate network segment between two networks of different trust, typically between the enterprise IT network and the production network, in which shared services are placed so that no direct traffic has to pass between the two.
- OT security
In one sentence
An OT DMZ is a separate network segment between IT and production networks that hosts shared services so no direct traffic crosses between them.
Example
Instead of letting office users query the plant historian directly, a replica of the historian runs in the DMZ, and the firewall only allows the plant historian to push data to it.
How it applies
- Engineering: Typical DMZ services are historian replicas, patch and antivirus distribution servers, file transfer services and Jump server hosts for remote access. Firewalls on both sides allow only the flows needed for these services.
- Operation: A well-designed DMZ lets connections from both sides end in the DMZ; a connection that passes straight through defeats its purpose.
- Maintenance: DMZ servers are exposed to both networks and must be hardened, patched and monitored with high priority.
- Documentation: Network drawings and security documentation should show the DMZ with its services, the allowed flows and their owners. Product manuals should state which services of a product are meant to sit in a DMZ, and which ports they need.
DMZ for OT vs. industrial DMZ (IDMZ)
The terms are often used interchangeably. "DMZ" is the general network security concept; the Industrial demilitarized zone (IDMZ) names the specific DMZ between enterprise and manufacturing zones, often described as level 3.5 of the Purdue reference model.