---
title: "IEC 62443 security zones and conduits: a practical introduction | Edge SDN"
description: "What security zones and conduits are in IEC 62443, the two traffic rules, seven steps to create zones in a plant, common mistakes, and a free 14-page white paper."
url: https://www.edge-sdn.com/resources/iec-62443-security-zones/
last_updated: 2026-10-04
---

IEC 62443 · IT and OT teams

# Create security zones and conduits by IEC 62443

By Aldo Campi, co-founder and CEO of Stoorm5 · White paper published 31 October 2024

What are security zones and conduits in IEC 62443?

A security zone is a logical or physical area of an industrial control system that groups assets with the same security needs, under its own rules. A conduit is the communication path between two zones, physical or virtual, protected by its own measures. Together they limit how far an attack can spread, so a compromised zone stops one part of the process, not the plant.

## Two rules for the traffic

An industrial network has two directions of traffic, and each gets one rule.

- **North-South**, between the field and central or external services: control it, with perimeter firewalls, DMZs, VPNs and role-based access.
- **East-West**, between devices at the same level, often inside one VLAN: block it or control it. Attackers use it to move sideways and raise their privileges.

## Create the zones in seven steps

1. **Identify the critical resources.** Machines, automation systems, databases, servers and the processes that depend on them.
2. **Analyse the risk.** Threats and vulnerabilities that can hit those resources, with their impact and likelihood.
3. **Define the zones.** Split the network into logical or physical zones by function, criticality and sensitivity.
4. **Write the policies.** Access control, credential management and monitoring rules for each zone.
5. **Put the measures in place.** Firewalls, intrusion detection, access controls and segmentation rules on the switches.
6. **Test and validate.** Check that every measure works and that critical resources are protected.
7. **Monitor and maintain.** Keep the zones in line with changes in the plant and with new threats.

Protect the critical processes and assets first. The rest can share zones without specific protection, as long as a compromise there does not touch operational continuity or operator safety.

## Avoid five common mistakes

- Grouping assets by type instead of by process, for example all the PLCs of one vendor in one zone.
- Leaving IT assets inside OT zones, such as an office PC on the corporate domain next to a production line.
- Treating VLANs or IP subnets as security zones. Addressing reflects past choices; zones follow the production process.
- Drawing zones only around today's vulnerabilities. The result is fine-grained, hard to maintain and changes with every scan.
- Leaving boundaries vague, so policies overlap or parts of the process sit in no zone at all.

## What the white paper adds

The 14 pages walk through a reference architecture, best practice for grouping assets, the layered "onion" model and a worked example: one production line, its traffic to maintenance, SCADA, application servers and IT services, the zones drawn around it and the traffic matrix between them. Part 3-2 of the [ISA/IEC 62443 series](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards) is the reference for partitioning a system into zones and conduits.

[Download the white paper (PDF)](https://www.edge-sdn.com/wp-content/uploads/2024/11/IEC-62443-Security-Zone%5FEN.pdf) · [Apply the zones with the Edge SDN platform](https://www.edge-sdn.com/products/edge-sdn/) · [Check your switches](https://www.edge-sdn.com/products/edge-sdn/compatibility/)

## Frequently asked questions

### Is a VLAN a security zone?

No. A VLAN or an IP subnet is a way to address the network. A security zone groups assets by production process and security need, and one process can span several VLANs.

### How many security zones should a plant have?

As few as the risk analysis needs. Each zone should be one element of the production process, so that a compromised zone stops only that element. Too many layers and details make the design hard to run.

### Where should Wi-Fi and Bluetooth go?

In a zone of their own. Radio links are always exposed, so the white paper recommends isolating them.

### What is the difference between North-South and East-West traffic?

North-South traffic goes between the field and central or external services; it must be controlled. East-West traffic goes between devices at the same level, often inside one VLAN; it must be blocked or controlled, because attackers use it to move sideways.

Last updated 4 October 2026

## Draw the zones of your plant with us

Bring the list of lines and machines. In a first call we sketch the zones, the conduits between them and what the switches you have can enforce.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
