Zones, conduits, remote access

Network Segmentation Validation

A diagram shows intended architecture. Routes, firewall state, identity paths, vendor access, dual-homed hosts, and protocol behavior show the reachable architecture.

Water treatment and electrical utility infrastructure.

The engagement

Design intent, compared with the reachable network

Network segmentation validation compares design intent with observed traffic and carefully controlled reachability. GDF reviews the IT/OT boundary, cell and area zones, management networks, safety separation, wireless links, remote access, historian paths, and vendor support channels.

Operator-designated authority approves any active method, process condition, maintenance window, stop points, and rollback plan. A passive or configuration-only review is used where active validation would create unacceptable process risk. The engagement produces evidence, not a marketing certification.

Validation compares the intended zone-and-conduit design with rule sets, observed flows, remote-access paths, recorded exceptions, and any active checks approved by the operator. Findings identify where the boundary holds, where it does not, and what the operator needs to change.

Scope

  • IT/OT boundary and industrial DMZ

    Boundary architecture reviewed against ISA/IEC 62443 zone-and-conduit concepts and the client's own reference design. Broker and DMZ services are examined for direction, protocol, and identity.

  • Cell, area, and safety separation

    Cell and area zone boundaries, safety instrumented system separation, and management network isolation reviewed. Broadcast and multicast leakage between zones is identified.

  • Firewall rule, NAT, and route validation

    Firewall rules, NAT tables, static and dynamic routes, and access control lists compared with intended flows. Overly broad rules and stale exceptions are marked.

  • Remote access and vendor paths

    Jump hosts, VPN concentrators, vendor gateways, cellular modems, and out-of-band management paths reviewed. Session recording and identity binding are checked.

  • Dual-homed, wireless, and alternate paths

    Dual-homed hosts, wireless bridges, engineering laptops, and modem or serial back doors identified. Documented and undocumented paths are separated.

  • Identity and privilege paths

    Trust between IT and OT identity providers reviewed. Cross-domain accounts, service accounts, and shared credentials that traverse zones are marked for correction.

  • Remediation and retest plan

    Recommended changes identify affected owners, protocol, monitoring, safety dependencies, rollback conditions, maintenance windows, and expected risk reduction. Post-change validation covers the approved path.

Methodology

How segmentation validation runs

  1. Map

    Design documents, drawings, engineering files, and existing inventories are collected. Intended zones, conduits, and remote access are documented from the operator's perspective.

  2. Observe

    Configurations are exported. Passive traffic is collected at documented points. Identity and remote-access records are gathered for a defined observation window.

  3. Validate

    Observed reachability is compared with intended design. Where approved, controlled reachability tests confirm or reject specific paths under operator supervision.

  4. Recommend

    Findings are ranked by operational consequence. Remediation sequence, owner, protocol, monitoring, rollback, and window are documented. Post-change retest scope is defined.

Evidence commonly examined

Evidence reviewed

  • Firewall, router, and switch configuration exports
  • Passive traffic captures with documented collection points
  • Remote-access logs and identity provider records
  • Engineering drawings, network diagrams, and asset registers
  • Vendor access agreements and monitoring records
  • Controlled reachability tests approved by the operator

What you can expect

What you receive

  • Zone-and-conduit reachability map
  • Ranked findings with operational consequence
  • Recommended remediation sequence with owner and window
  • Post-change retest evidence for validated paths
  • Exception register for compensating controls

Frequently asked

Common questions

Is active testing safe in an OT environment?

Active testing requires operator-designated authority, an approved process condition, stop points, and recovery steps. Passive and configuration-based methods are used where active methods could create risk. The operator retains authority over process safety and change windows.

Does a passing test mean the boundary is fully isolated?

No. Post-change testing covers the approved path and date. It does not establish that every alternate route has been eliminated. The report identifies untested surface and the conditions under which the test was performed.

Can this work satisfy a NERC CIP or Part 500 requirement?

The technical record produced can be used as evidence in a compliance program. Applicability, attestation, and submission remain with the Registered Entity, covered entity, or accountable owner. GDF does not provide legal compliance opinions.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.