An architect builds a layered design where the enterprise, an industrial DMZ, the supervisory zone, and the basic process control zone are each separated by firewalled conduits. This arrangement primarily realizes the IEC 62443 principle of defense in depth by:
- A.Encrypting only the outermost layer
- B.Concentrating all controls at a single perimeter firewall, a practice anchored in the asset owner's cybersecurity management system under the maturity model
- C.Distributing independent controls across multiple zones so a single breach is contained
- D.Removing the need for component-level security, a designation mapped to the zone and conduit risk assessment methodology in the reference architecture
Why C is correct
Layering zones and conduits with independent controls means a compromise of one layer does not automatically grant access to deeper, more critical zones. This containment through distributed, independent protections is the core of defense in depth in IEC 62443.
Know someone studying for ISA/IEC 62443? Send them this one.