An architect builds a layered design where the enterprise, an industrial DMZ, the supervisory zone, and the basic process control zone are each separated by firewalled conduits. This arrangement primarily realizes the IEC 62443 principle of defense in depth by:
- A.Encrypting only the outermost layer
- B.Concentrating all controls at a single perimeter firewall
- C.Removing the need for component-level security
- D.Distributing independent controls across multiple zones so a single breach is contained
Why D is correct
Layering zones and conduits with independent controls means a compromise of one layer does not automatically grant access to deeper, more critical zones. This containment through distributed, independent protections is the core of defense in depth in IEC 62443.
Know someone studying for ISA/IEC 62443? Send them this one.