Zones and Conduits
Zones and conduits are the IEC 62443 method for partitioning an OT system for security. A zone groups assets that share the same security requirements; a conduit is the controlled communication path between zones. Each zone is assigned a target security level based on a risk assessment, and conduits enforce what may cross the boundary.
How it works
The process is defined in IEC 62443-3-2 and adapted for rail in TS 50701 and IEC 63452. The system under consideration is first described, then divided into zones according to criteria such as function, criticality, physical location, ownership and safety relevance. Signaling, onboard control, passenger systems and enterprise IT, for example, would normally fall into different zones.
Every communication between zones is captured as a conduit, with the protocols, directions and endpoints it must carry. A detailed risk assessment then sets a target security level for each zone and conduit, and the controls, firewalls, data diodes, authentication, monitoring, are chosen to meet it. The model is documented and maintained as the system evolves.
Why it matters for security
Zones and conduits turn the vague goal of segmentation into a documented design that can be reviewed, tendered against and audited. Rail regulators and standards now expect operators to have such a model for their signaling, rolling stock and fixed installations.
The hard part is not drawing the model but keeping it true. Networks change, suppliers add remote access, and undocumented flows appear. Comparing the intended zones and conduits with the traffic actually observed on the network is how operators find where the design and reality have drifted apart.
Related solution
Aligning rail OT security with IEC 62443-3-3
Validating zones and conduits against the traffic that actually flows between them.
See the solution →

