Define the operating scope
Include OT applications, IACS security zones, remote users, Service and Route Endlets in a representative operating scope.
Protected OT boundaries · Briefing
Apply identity-centric segmentation across industrial automation and control system security zones and conduits.
Primary capability
Zero Trust
Operational outcome
Restrict unauthorized lateral movement and expose only approved operational service relationships.
Include OT applications, IACS security zones, remote users, Service and Route Endlets in a representative operating scope.
validated identity and machine state → Endlet admission → least-privilege service policy → enforcement across an approved OT conduit
Determine whether named users, workloads, and IACS zones receive only the minimum approved access.
Outcome readiness
Give network, security, and operational teams one service path to review and one decision to make.
Inputs
OT applications, IACS security zones, remote users, Service and Route Endlets, identity and policy services
Path
validated identity and machine state → Endlet admission → least-privilege service policy → enforcement across an approved OT conduit
Evidence
identity state, policy decision, allowed and denied flows, route visibility, session logs, and revocation timing
Quick answers
OT applications, IACS security zones, remote users, Service and Route Endlets, identity and policy services
Restrict unauthorized lateral movement and expose only approved operational service relationships.
Determine whether named users, workloads, and IACS zones receive only the minimum approved access.
Continue the evaluation path
Determine whether named users, workloads, and IACS zones receive only the minimum approved access.
Continue to Architecture