ISA/IEC 62443 defines “defense in depth” as a layered approach to security. This can be accomplished by implementing zones within zones (sometimes called subzones), where each zone or subzone provides an additional security barrier or control layer. This segmentation restricts an attacker's ability to move laterally and ensures that compromise of one zone does not automatically result in compromise of the entire system.
[Reference: ISA/IEC 62443-1-1:2007, Section 4.3.3 (“Zones and Conduits”); ISA/IEC 62443-3-2:2020, Section 4.4.3 (“Layered security using zones and subzones”)., , ]
Submit