21PacketsContact Us
Utilities

Control-system segmentation · Architecture

Map the service path for control-system segmentation.

Apply least-privilege policy across industrial automation and control system security zones and conduits.

validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit. Evaluation evidence includes identity evidence, policy decisions, allowed and denied flows, session state, route exposure, and revocation.Utilities · Zero TrustControl-system segmentationVerified service path and review points01Validatedendpointidentity02Authorizedfabric admission03Least-privilegeservice policy04Enforcementacross anapprovedEvaluation evidenceidentity evidence · policy decisions · allowed and denied flowsEach control point and result is verified against the selected environment.

Primary capability

Zero Trust

How it works

Trace the protected service path from admission to evidence.

Restrict unauthorized lateral movement while preserving approved control-system communications.

01

Establish identity and scope

Identify control applications, SCADA services, engineering workstations, IACS security zones; validate participating Endlets before admission.

02

Build the protected service path

validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit

03

Capture decision evidence

Review identity evidence, policy decisions, allowed and denied flows, session state, route exposure with the responsible teams.

Architecture flow

Trace the protected service path and its control points.

01

validated endpoint identity

02

authorized fabric admission

03

least-privilege service policy

04

enforcement across an approved zone-to-zone conduit

Inputs

control applications, SCADA services, engineering workstations, IACS security zones, identity systems, Endlets

Path

validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit

Evidence

identity evidence, policy decisions, allowed and denied flows, session state, route exposure, and revocation

Quick answers

Control-system segmentation FAQs

Which technical path should the team review?+

validated endpoint identity → authorized fabric admission → least-privilege service policy → enforcement across an approved zone-to-zone conduit

Which evidence should reviewers collect?+

identity evidence, policy decisions, allowed and denied flows, session state, route exposure, and revocation

Who should review the architecture?+

OT security, SCADA owners, network security, grid operations

Continue the evaluation path

Evaluate control-system segmentation with a representative scope.

Determine whether each operator, workload, and IACS zone can reach only its authorized control services.

Continue to Evaluation