Glossary · Industrial cybersecurity
Zones and conduits
Also known as: Zone and conduit model
German: Zonen und Übergänge
In IEC 62443, zones and conduits is the model for segmenting an industrial automation and control system: assets with common security requirements are grouped into zones, and communication between zones is only allowed through defined conduits, each with a target security level.
- Cybersecurity
- Standards
In one sentence
In IEC 62443, zones group assets with common security needs, and conduits are the defined, controlled communication paths between them.
Example
A bottling plant defines a safety system zone, a line control zone and a DMZ, with a firewall-protected conduit carrying only OPC UA traffic to the MES.
How it applies
- Engineering: The zone and conduit model is created in the security risk assessment per IEC 62443-3-2 and implemented with network segmentation, firewalls and access control.
- Operation: Changes to machines, remote connections or data flows must be checked against the model; an undocumented connection can bypass a conduit.
- Documentation: Machine builders should document which communication a machine needs (ports, protocols, direction), so operators can place it in their zone model; the documentation team should keep this list per release.
- Security levels: Each zone and conduit gets a target security level that guides the selection of countermeasures.
Zone vs. conduit
A Security zone groups assets; a Conduit is the path between zones. Both are needed: a zone without controlled conduits is not segmented.