Glossary · OT cybersecurity
Industrial demilitarized zone (IDMZ)
Also known as: IDMZ, Level 3.5
German: Industrielle demilitarisierte Zone (IDMZ)
In OT network architecture, the industrial demilitarized zone (IDMZ) is the buffer network between the enterprise zone and the manufacturing or industrial zone. All data exchange between the two passes through services in the IDMZ, and no direct connection from enterprise to plant control networks is allowed.
- OT security
In one sentence
The industrial DMZ (IDMZ) is the buffer network between enterprise and manufacturing zones through which all data exchange must pass.
Example
ERP orders reach the MES via a file broker in the IDMZ, and remote service technicians connect to a jump server there before reaching any machine.
How it applies
- Engineering: In the Purdue reference model the IDMZ is often called level 3.5, between site operations (level 3) and enterprise systems (level 4). It typically hosts replicated historians, patch servers, remote access gateways and brokers for file and data transfer.
- Operation: A basic rule is that connections terminate in the IDMZ: traffic from either side ends at a service there, which then talks to the other side.
- Maintenance: IDMZ components are high-value targets and need priority patching, monitoring and strict change control.
- Documentation: Architecture documents should show the IDMZ services, their data flows and owners. Product documentation for MES, historian or remote service tools should state which components are intended for the IDMZ and which ports are needed in each direction.
IDMZ vs. DMZ
The IDMZ is a specific application of the general Demilitarized zone (DMZ) for OT idea, placed between enterprise IT and industrial control networks. Plants may have further DMZs, for example for supplier connections.