What this domain asks
The design and maintained evidence for security zones, conduits, trust boundaries, routable paths, industrial DMZs, enforcement points, fail states, and allowed communication supporting physical operations.
The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.
Buyer questions
- Can the system reconstruct actual communication without assuming observed traffic is approved?
- How are process safety, control latency, multicast, redundancy, time, and vendor dependencies represented?
- Which product recommends policy and which device enforces it?
- How are emergency, maintenance, degraded, and failover states tested?
- Can every change be simulated, reviewed, approved, implemented, verified, and reversed?
Mapped workflows
Industrial Protocol Identification And Deep Packet Inspection
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for industrial protocol identification and deep packet inspection within this domain.
Topology, Communication, And Dependency Mapping
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for topology, communication, and dependency mapping within this domain.
Asset Criticality And Operational Context
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for asset criticality and operational context within this domain.
Network Segmentation Policy Modeling
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for network segmentation policy modeling within this domain.
Industrial Firewall And Policy Enforcement
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for industrial firewall and policy enforcement within this domain.
Unidirectional Transfer And Network Isolation
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for unidirectional transfer and network isolation within this domain.
Packet Capture And Forensic Evidence
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for packet capture and forensic evidence within this domain.
Compliance Mapping And Control Evidence
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for compliance mapping and control evidence within this domain.
Offline And Air-Gapped Environment Support
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for offline and air-gapped environment support within this domain.
Authority context
NIST SP 800-82 Rev. 3
NIST describes OT topologies, threats, vulnerabilities, safeguards, and risk-management considerations while recognizing performance, reliability, and safety requirements.
ISA/IEC 62443-3-2
Part 3-2 addresses system-level risk assessment and the use of zones, conduits, and target security levels in IACS design.
ISA/IEC 62443-3-3
Part 3-3 defines system security requirements and security levels for industrial automation and control systems.
Relevant operating models
- Industrial Network Security And Segmentation Platform
- OT Visibility And Threat-Detection Platform
- Unidirectional Gateway And Controlled-Transfer Platform
- Industrial OEM Security Portfolio
Evidence boundary
OT Defense Review is not a regulator, standards body, certification body, control-system integrator, safety authority, engineering firm, incident-response provider, insurer, or law firm. Its records support market research and decision review; they do not establish compliance, certification, security, safety, reliability, exploitability, or fitness for a specific operational environment. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.