A demilitarized zone (DMZ) in network architecture provides indirect (controlled and monitored) access to the Internet or untrusted networks, usually by isolating publicly accessible services (like web servers) from internal control networks. This prevents direct exposure of sensitive IACS assets to external threats. While DMZs can support secure data transfer, their primary function is segmentation and indirect access.
[Reference: ISA/IEC 62443-3-3:2013, Section 4.2.3; ISA/IEC 62443-1-1:2007, Section 3.2.6 (Network Security Architectures and DMZ)., ]
Submit