Define the operating scope
Include control applications, SCADA services, engineering workstations, IACS security zones in a representative operating scope.
Control-system segmentation · Briefing
Apply least-privilege policy across industrial automation and control system security zones and conduits.
Primary capability
Zero Trust
Operational outcome
Restrict unauthorized lateral movement while preserving approved control-system communications.
Include control applications, SCADA services, engineering workstations, IACS security zones in a representative operating scope.
validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit
Determine whether each operator, workload, and IACS zone can reach only its authorized control services.
Outcome readiness
Give network, security, and operational teams one service path to review and one decision to make.
Inputs
control applications, SCADA services, engineering workstations, IACS security zones, identity systems, Endlets
Path
validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit
Evidence
identity evidence, policy decisions, allowed and denied flows, session state, route exposure, and revocation
Quick answers
control applications, SCADA services, engineering workstations, IACS security zones, identity systems, Endlets
Restrict unauthorized lateral movement while preserving approved control-system communications.
Determine whether each operator, workload, and IACS zone can reach only its authorized control services.
Continue the evaluation path
Determine whether each operator, workload, and IACS zone can reach only its authorized control services.
Continue to Architecture