IEC 62443 Zones & Conduits
Design OT/ICS security with IEC 62443 zones & conduits, then implement and enforce those boundaries in QuantLayer with staged enforcement.
IEC 62443
Segmentation
OT/ICS
8 min
Last updated: 2026-01-22Overview
IEC 62443 recommends partitioning the System Under Consideration into zones (groups of assets with similar security requirements) and conduits (controlled communication paths between zones). This limits blast radius and makes security requirements measurable per zone.
How to build zones & conduits
- Inventory assets by function (safety, control, supervisory, engineering, DMZ, enterprise), location, and criticality.
- Group into zones using risk and operational constraints (e.g., Safety zone, Control zone, Site DMZ, Business/IT zone).
- Define conduits for required communications between zones; default to deny by default and allow by exception.
- Assign SL-T per zone/conduit based on threat environment and tolerable risk.
OT reality check
OT reality check
Segmentation should follow operations. The goal is not “one zone per level,” but boundaries that are enforceable and reduce risk without breaking deterministic control traffic.
Enforcing conduits with QuantLayer
Define conduit policies as allow-lists by protocol, asset identity, role, and maintenance window.
Start in Monitor mode and move to Alert/Enforce to avoid downtime.
- Policy-as-Conduit: allowed service flows, remote support, jump hosts, break-glass procedures.
- Zone posture: per-zone trust drift (patch gaps, tamper events, rogue identities).
- Containment: quarantine or isolate compromised devices by revoking access and restricting egress.
Reference patterns
- Business Zone ↔ Site DMZ: Broker IT/OT data exchanges through DMZ services; restrict direct enterprise-to-control connectivity.
- Engineering Workstations: Strong identity, step-up verification, and time-bound access to control networks and PLC tooling.
- Vendor Remote Support: Session-based access with device attestation, recorded commands, and automatic revocation after maintenance windows.
Implementation note
IEC 62443 compliance is achieved through a combination of people, process, and technology controls. QuantLayer helps you operationalize the technical controls (identity, segmentation, integrity, telemetry, response) while producing audit-ready evidence to support your CSMS and assurance activities.