In IEC 62443, zones group assets with similar cybersecurity needs and conduits are the controlled communication paths between those zones.
In the context of industrial cybersecurity, especially IEC 62443, zone and conduit refers to a structured way of segmenting operational technology (OT) environments and controlling communication between those segments.
A zone is a logical or physical group of assets that share similar cybersecurity requirements, such as security level, trust level, or functional role. A zone can include:
Zones are usually defined during risk assessment and architecture design. Each zone typically has:
A zone does not have to be a single VLAN, room, or cabinet, although it may map to these. It is primarily a grouping concept based on security requirements, not just topology.
A conduit is a defined communication path that connects two or more zones. It represents:
Conduits are designed to enforce the required cybersecurity posture between zones. In many architectures, critical functions such as remote access, cross-site replication, or MES/ERP integration are modeled as conduits between a control zone and a higher-level business or DMZ zone.
In regulated manufacturing and other industrial operations, defining zones and conduits is a common step in:
Zones and conduits are usually captured in network and security architecture diagrams, and referenced in site standards, operating procedures, and change control documentation.
IEC 62443 introduces the concepts of zones and conduits as core elements of secure industrial automation and control system architecture. The standard uses them to:
While implementations vary, using zones and conduits aligns with IEC 62443-style approaches to designing and documenting OT cybersecurity controls.
In the context of IEC 62443 guidance for asset owners, zoning and conduits are typically introduced when applying parts such as IEC 62443-3-2, where sites identify industrial control system assets, group them into zones with defined security levels, and specify conduits that manage and protect communications between those zones.