| name | implementing-purdue-model-network-segmentation |
| description | Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate industrial control system networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise, enforcing strict traffic control between OT and IT domains. . Use when working with implementing purdue model network segmentation. |
| domain | cybersecurity |
| tags | ["ot-security","ics","purdue-model","network-segmentation","iec62443","defense-in-depth","dmz","scada"] |
| subdomain | ot-ics-security |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","DE.CM-01","ID.AM-05","GV.OC-02"] |
Implementing Purdue Model Network Segmentation
Overview
Cybersecurity skill for implementing purdue model network segmentation. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"implementing purdue model network segmentation"
-
"Implement network segmentation based on the Purdue Enterprise Reference Architec"
-
When designing or retrofitting network architecture for an ICS/SCADA environment
-
When implementing IEC 62443 zone and conduit requirements in a brownfield plant
-
When creating the IT/OT DMZ (Level 3.5) to control data flow between enterprise and control networks
-
When remediating audit findings about flat OT networks or direct IT-to-OT connectivity
-
When segmenting a converged IT/OT network after an acquisition or merger
Do not use for micro-segmentation within a single Purdue level (see implementing-zone-conduit-model-for-ics), for cloud-native environments without traditional ICS networks, or for network segmentation in purely IT environments.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Complete OT asset inventory with Purdue level classification for each device
- Network architecture diagram showing current topology, VLANs, and firewall placements
- Industrial firewalls capable of deep packet inspection for OT protocols (Palo Alto, Fortinet, Cisco)
- Understanding of required data flows between Purdue levels (historian replication, remote access, patch distribution)
- Change management approval from plant operations for network modifications
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def () -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}