The IDMZ
Also referred to as a perimeter network, the IDMZ is a buffer zone in the ICS network architecture that enforces data-sharing security and allows a fine-grained control over interactions between a trusted network (the Industrial Zone) and an untrusted network (the Enterprise Zone). The IDMZ adds an additional layer in the defense-in-depth (DiD) model, used to securely share ICS-related data and network services between two (or more) security zones.
The following diagram presents an overview of the IDMZ within the Purdue model:
Using a DMZ to separate security zones has been a commonplace practice in traditional IT networks for years. Implementing a DMZ between an Enterprise (business) network and an Industrial (production) network is also a recommended best practice by several industrial security standards, including the National Institute of Standards and Technology (NIST), IEC-62443, and...