Establish identity and scope
Identify control applications, SCADA services, engineering workstations, IACS security zones; validate participating Endlets before admission.
Control-system segmentation · Architecture
Apply least-privilege policy across industrial automation and control system security zones and conduits.
Primary capability
Zero Trust
How it works
Restrict unauthorized lateral movement while preserving approved control-system communications.
Identify control applications, SCADA services, engineering workstations, IACS security zones; validate participating Endlets before admission.
validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit
Review identity evidence, policy decisions, allowed and denied flows, session state, route exposure with the responsible teams.
Architecture flow
Inputs
control applications, SCADA services, engineering workstations, IACS security zones, identity systems, Endlets
Path
validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit
Evidence
identity evidence, policy decisions, allowed and denied flows, session state, route exposure, and revocation
Quick answers
validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit
identity evidence, policy decisions, allowed and denied flows, session state, route exposure, and revocation
OT security, SCADA owners, network security, grid operations
Continue the evaluation path
Determine whether each operator, workload, and IACS zone can reach only its authorized control services.
Continue to Evaluation