IEC 62443 Zones & Conduits

    Design OT/ICS security with IEC 62443 zones & conduits, then implement and enforce those boundaries in QuantLayer with staged enforcement.

    IEC 62443
    Segmentation
    OT/ICS
    8 min
    Last updated: 2026-01-22

    Overview

    IEC 62443 recommends partitioning the System Under Consideration into zones (groups of assets with similar security requirements) and conduits (controlled communication paths between zones). This limits blast radius and makes security requirements measurable per zone.

    How to build zones & conduits

    • Inventory assets by function (safety, control, supervisory, engineering, DMZ, enterprise), location, and criticality.
    • Group into zones using risk and operational constraints (e.g., Safety zone, Control zone, Site DMZ, Business/IT zone).
    • Define conduits for required communications between zones; default to deny by default and allow by exception.
    • Assign SL-T per zone/conduit based on threat environment and tolerable risk.

    OT reality check

    OT reality check
    Segmentation should follow operations. The goal is not “one zone per level,” but boundaries that are enforceable and reduce risk without breaking deterministic control traffic.

    Enforcing conduits with QuantLayer

    Define conduit policies as allow-lists by protocol, asset identity, role, and maintenance window.

    Start in Monitor mode and move to Alert/Enforce to avoid downtime.

    • Policy-as-Conduit: allowed service flows, remote support, jump hosts, break-glass procedures.
    • Zone posture: per-zone trust drift (patch gaps, tamper events, rogue identities).
    • Containment: quarantine or isolate compromised devices by revoking access and restricting egress.

    Reference patterns

    • Business Zone ↔ Site DMZ: Broker IT/OT data exchanges through DMZ services; restrict direct enterprise-to-control connectivity.
    • Engineering Workstations: Strong identity, step-up verification, and time-bound access to control networks and PLC tooling.
    • Vendor Remote Support: Session-based access with device attestation, recorded commands, and automatic revocation after maintenance windows.
    Implementation note
    IEC 62443 compliance is achieved through a combination of people, process, and technology controls. QuantLayer helps you operationalize the technical controls (identity, segmentation, integrity, telemetry, response) while producing audit-ready evidence to support your CSMS and assurance activities.