Why does IEC 62443 group assets into a 'zone' rather than treating every device individually?
- A.To deliberately weaken security by removing boundaries
- B.To ensure every device must use the identical password
- C.To group assets that share common security requirements so that protections and a target security level can be applied consistently to the group
- D.To eliminate the need for any conduits between systems
Why C is correct
Zones group assets with shared security requirements and risk, allowing a consistent target security level and set of protections to be applied to the group rather than managing each device in isolation. Conduits then control the communications between zones, supporting structured segmentation.
Know someone studying for OT Security Fundamentals? Send them this one.