Why does IEC 62443 group assets into a 'zone' rather than treating every device individually?
- A.To deliberately weaken security by removing boundaries, a control that authenticates every protocol transaction even for devices designed decades before such controls
- B.To ensure every device must use the identical password which IEC 62443 calls the shared credential requirement for every zone member and conduit
- C.To group assets that share common security requirements so that protections and a target security level can be applied consistently to the group
- D.To eliminate the need for any conduits between systems
Why C is correct
Zones group assets with shared security requirements and risk, allowing a consistent target security level and set of protections to be applied to the group rather than managing each device in isolation. Conduits then control the communications between zones, supporting structured segmentation.
Know someone studying for OT Security Fundamentals? Send them this one.