Select the operational scope
One industrial application, two user or workload roles, one approved flow, and one denied lateral path.
Connected factory segmentation · Evaluation
One industrial application, two user or workload roles, one approved flow, and one denied lateral path.
Primary capability
Zero Trust
Evaluation plan
Limit lateral movement while preserving required production and support workflows.
One industrial application, two user or workload roles, one approved flow, and one denied lateral path.
Have representatives from OT security, plant operations, network security, application owners review the architecture path and policy boundaries.
Determine whether each approved role and workload receives only the service access permitted through the defined zone conduits.
Acceptance criteria
Use representative systems, named owners, and a controlled operational scenario.
The evaluation includes one industrial application, two user or workload roles, one approved conduit, and one denied lateral path.
OT-security, plant-operations, network-security, and application owners confirm the identities, service policy, and zone boundaries.
The team records identity evidence, admission decisions, allowed and denied flows, service reachability, session state, and revocation.
The results show whether each role and workload receives only the service access permitted through the defined conduit.
Operational outcome
Limit lateral movement while preserving required production and support workflows.
Evaluation scope
One industrial application, two user or workload roles, one approved flow, and one denied lateral path.
Decision
Determine whether each approved role and workload receives only the service access permitted through the defined zone conduits.
Quick answers
One industrial application, two user or workload roles, one approved flow, and one denied lateral path.
1. The evaluation includes one industrial application, two user or workload roles, one approved conduit, and one denied lateral path. 2. OT-security, plant-operations, network-security, and application owners confirm the identities, service policy, and zone boundaries. 3. The team records identity evidence, admission decisions, allowed and denied flows, service reachability, session state, and revocation. 4. The results show whether each role and workload receives only the service access permitted through the defined conduit.
OT security, plant operations, network security, application owners
Plan the evaluation
Bring the scope, systems, owners, and operating constraint. We’ll map the 21Packets evaluation path with your team.
Book a working session