21PacketsContact Us
Utilities

Control-system segmentation · Briefing

Define the operating requirements for control-system segmentation.

Apply least-privilege policy across industrial automation and control system security zones and conduits.

validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit. Evaluation evidence includes identity evidence, policy decisions, allowed and denied flows, session state, route exposure, and revocation.Utilities · Zero TrustControl-system segmentationVerified service path and review points01Validatedendpointidentity02Authorizedfabric admission03Least-privilegeservice policy04Enforcementacross anapprovedEvaluation evidenceidentity evidence · policy decisions · allowed and denied flowsEach control point and result is verified against the selected environment.

Primary capability

Zero Trust

Operational outcome

Define the operating constraint, systems, and decision.

Restrict unauthorized lateral movement while preserving approved control-system communications.

01

Define the operating scope

Include control applications, SCADA services, engineering workstations, IACS security zones in a representative operating scope.

02

Trace the protected path

validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit

03

Review the decision

Determine whether each operator, workload, and IACS zone can reach only its authorized control services.

Outcome readiness

Define the systems and constraints for control-system segmentation.

Give network, security, and operational teams one service path to review and one decision to make.

Include control applications in the selected scope.
Include SCADA services in the selected scope.
Include engineering workstations in the selected scope.
Include IACS security zones in the selected scope.
Include identity systems in the selected scope.
Include Endlets in the selected scope.

Inputs

control applications, SCADA services, engineering workstations, IACS security zones, identity systems, Endlets

Path

validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit

Evidence

identity evidence, policy decisions, allowed and denied flows, session state, route exposure, and revocation

Quick answers

Control-system segmentation FAQs

Which systems are in scope for control-system segmentation?+

control applications, SCADA services, engineering workstations, IACS security zones, identity systems, Endlets

What operational outcome should the team review?+

Restrict unauthorized lateral movement while preserving approved control-system communications.

What decision should the briefing support?+

Determine whether each operator, workload, and IACS zone can reach only its authorized control services.

Continue the evaluation path

See the architecture behind control-system segmentation.

Determine whether each operator, workload, and IACS zone can reach only its authorized control services.

Continue to Architecture