Zones, conduits, remote access
Network Segmentation Validation
A diagram shows intended architecture. Routes, firewall state, identity paths, vendor access, dual-homed hosts, and protocol behavior show the reachable architecture.
The engagement
Design intent, compared with the reachable network
Network segmentation validation compares design intent with observed traffic and carefully controlled reachability. GDF reviews the IT/OT boundary, cell and area zones, management networks, safety separation, wireless links, remote access, historian paths, and vendor support channels.
Operator-designated authority approves any active method, process condition, maintenance window, stop points, and rollback plan. A passive or configuration-only review is used where active validation would create unacceptable process risk. The engagement produces evidence, not a marketing certification.
Validation compares the intended zone-and-conduit design with rule sets, observed flows, remote-access paths, recorded exceptions, and any active checks approved by the operator. Findings identify where the boundary holds, where it does not, and what the operator needs to change.
Scope
IT/OT boundary and industrial DMZ
Boundary architecture reviewed against ISA/IEC 62443 zone-and-conduit concepts and the client's own reference design. Broker and DMZ services are examined for direction, protocol, and identity.
Cell, area, and safety separation
Cell and area zone boundaries, safety instrumented system separation, and management network isolation reviewed. Broadcast and multicast leakage between zones is identified.
Firewall rule, NAT, and route validation
Firewall rules, NAT tables, static and dynamic routes, and access control lists compared with intended flows. Overly broad rules and stale exceptions are marked.
Remote access and vendor paths
Jump hosts, VPN concentrators, vendor gateways, cellular modems, and out-of-band management paths reviewed. Session recording and identity binding are checked.
Dual-homed, wireless, and alternate paths
Dual-homed hosts, wireless bridges, engineering laptops, and modem or serial back doors identified. Documented and undocumented paths are separated.
Identity and privilege paths
Trust between IT and OT identity providers reviewed. Cross-domain accounts, service accounts, and shared credentials that traverse zones are marked for correction.
Remediation and retest plan
Recommended changes identify affected owners, protocol, monitoring, safety dependencies, rollback conditions, maintenance windows, and expected risk reduction. Post-change validation covers the approved path.
Methodology
How segmentation validation runs
-
Map
Design documents, drawings, engineering files, and existing inventories are collected. Intended zones, conduits, and remote access are documented from the operator's perspective.
-
Observe
Configurations are exported. Passive traffic is collected at documented points. Identity and remote-access records are gathered for a defined observation window.
-
Validate
Observed reachability is compared with intended design. Where approved, controlled reachability tests confirm or reject specific paths under operator supervision.
-
Recommend
Findings are ranked by operational consequence. Remediation sequence, owner, protocol, monitoring, rollback, and window are documented. Post-change retest scope is defined.
Evidence commonly examined
Evidence reviewed
- Firewall, router, and switch configuration exports
- Passive traffic captures with documented collection points
- Remote-access logs and identity provider records
- Engineering drawings, network diagrams, and asset registers
- Vendor access agreements and monitoring records
- Controlled reachability tests approved by the operator
What you can expect
What you receive
- Zone-and-conduit reachability map
- Ranked findings with operational consequence
- Recommended remediation sequence with owner and window
- Post-change retest evidence for validated paths
- Exception register for compensating controls
Frequently asked
Common questions
Is active testing safe in an OT environment?
Active testing requires operator-designated authority, an approved process condition, stop points, and recovery steps. Passive and configuration-based methods are used where active methods could create risk. The operator retains authority over process safety and change windows.
Does a passing test mean the boundary is fully isolated?
No. Post-change testing covers the approved path and date. It does not establish that every alternate route has been eliminated. The report identifies untested surface and the conditions under which the test was performed.
Can this work satisfy a NERC CIP or Part 500 requirement?
The technical record produced can be used as evidence in a compliance program. Applicability, attestation, and submission remain with the Registered Entity, covered entity, or accountable owner. GDF does not provide legal compliance opinions.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189