{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T23:31:46Z","timestamp":1777591906206,"version":"3.51.4"},"reference-count":31,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2026,3,12]],"date-time":"2026-03-12T00:00:00Z","timestamp":1773273600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100005416","name":"The Research Council of Norway","doi-asserted-by":"publisher","award":["326717"],"award-info":[{"award-number":["326717"]}],"id":[{"id":"10.13039\/501100005416","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>The IEC 62443 standard defines that, based on risk assessment, different parts of an Industrial Automation and Control System (IACS) may have different security levels, and that parts with the same security level can be designated as separate zones. Furthermore, communication between different zones, both intra-IACS and inter-IACS, can be done via conduits. In this article, we argue that zones and particularly conduits can benefit from more detailed discussions of their architecture and implementation. Consequently, as novel contributions we (1) describe detailed principles for implementing conduits; (2) outline a process for connecting zones with potentially different Security Levels (SLs), expressed in the form of a flow chart; and (3) discuss challenges related to the application of zones and conduits in practice.<\/jats:p>","DOI":"10.3390\/jcp6020052","type":"journal-article","created":{"date-parts":[[2026,3,12]],"date-time":"2026-03-12T14:46:31Z","timestamp":1773326791000},"page":"52","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Security Aspects of Zones and Conduits in IEC 62443"],"prefix":"10.3390","volume":"6","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7127-6694","authenticated-orcid":false,"given":"Martin Gilje","family":"Jaatun","sequence":"first","affiliation":[{"name":"Department of Software Engineering, Safety and Security, SINTEF Digital, P.O. Box 4760, Torgarden, 7465 Trondheim, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9045-6815","authenticated-orcid":false,"given":"Mary Ann","family":"Lundteigen","sequence":"additional","affiliation":[{"name":"Department of Engineering Cybernetics, Norwegian University of Science and Technology, 7491 Trondheim, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1853-0950","authenticated-orcid":false,"given":"Christoph","family":"Thieme","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Safety and Security, SINTEF Digital, P.O. Box 4760, Torgarden, 7465 Trondheim, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3069-6788","authenticated-orcid":false,"given":"Lars Halvdan","family":"Fl\u00e5","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Safety and Security, SINTEF Digital, P.O. Box 4760, Torgarden, 7465 Trondheim, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9109-5401","authenticated-orcid":false,"given":"Karin","family":"Bernsmed","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Safety and Security, SINTEF Digital, P.O. Box 4760, Torgarden, 7465 Trondheim, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Roald","family":"Lygre","sequence":"additional","affiliation":[{"name":"Aker BP, P.O. Box 480, Sentrum, 4002 Stavanger, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fredrik","family":"Gratte","sequence":"additional","affiliation":[{"name":"Atina, \u00d8konomisenteret, P.O. Box 70, 3441 R\u00f8yken, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,3,12]]},"reference":[{"key":"ref_1","unstructured":"(2009). Security for Industrial Automation and Control Systems\u2014Part 1-1: Terminology, Concepts and Models (Standard No. \n            IEC\/TS 62443-1-1:2009\n          )."},{"key":"ref_2","unstructured":"DesRuisseaux, D. (2018). Practical Overview of Implementing IEC 62443 Security Levels in Industrial Control Applications, Schneider Electric Whitepaper."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Leander, B., \u010cau\u0161evi\u0107, A., and Hansson, H. (2019, January 26\u201329). Applicability of the IEC 62443 standard in Industry 4.0\/IIoT. Proceedings of the Proceedings of the 14th International Conference on Availability, Reliability and Security, Canterbury, UK.","DOI":"10.1145\/3339252.3341481"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Kern, M., Taspolatoglu, E., Scheytt, F., Glock, T., Liu, B., Betancourt, V.P., Becker, J., and Sax, E. (November, January 12). An Architecture-based Modeling Approach Using Data Flows for Zone Concepts in Industry 4.0. Proceedings of the 2020 IEEE International Symposium on Systems Engineering (ISSE), Vienna, Austria.","DOI":"10.1109\/ISSE49799.2020.9272013"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Tonetta, S., Schoitsch, E., and Bitsch, F. (2017). A Security Architecture for Railway Signalling. Computer Safety, Reliability, and Security SAFECOMP 2017; Lecture Notes in Computer Science, Springer.","DOI":"10.1007\/978-3-319-66266-4"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Jaatun, M.G., Onwubiko, C., Rosati, P., Rege, A., Hindy, H., Erola, A., and Bellekens, X. (2025). Implementation of Zones and Conduits in Industrial Control and Automation Systems. Proceedings of the International Conference on Cybersecurity, Situational Awareness and Social Media, Springer.","DOI":"10.1007\/978-981-96-0401-2"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1016\/0166-3615(94)90017-5","article-title":"The Purdue enterprise reference architecture","volume":"24","author":"Williams","year":"1994","journal-title":"Comput. Ind."},{"key":"ref_8","unstructured":"(2004). Part 1 (IEC 61511-1 Mod)\u2014Functional Safety: Safety Instrumented Systems for the Process Industry Sector\u2014Part 1: Framework, Definitions, System, Hardware and Software Requirements (Standard No. ISA 84.00.01-2004)."},{"key":"ref_9","unstructured":"(2023). Chapter: Segment the Network into Smaller Trust Zones. Industrial Automation Security Design Guide 2.0, Cisco."},{"key":"ref_10","unstructured":"(2023). Railway Applications: Cybersecurity (Standard No. ICLC TS 50701:2023)."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"92312","DOI":"10.1109\/ACCESS.2023.3309005","article-title":"Cybersecurity Considerations for Communication Based Train Control","volume":"1","author":"Soderi","year":"2023","journal-title":"IEEE Access"},{"key":"ref_12","unstructured":"(2026, March 05). CDS-Forum\u2014Industry Forum for Cybersecurity of Industrial Automation and Control Systems. Available online: https:\/\/cds-forum.com\/."},{"key":"ref_13","unstructured":"(2026, March 05). Cybersecurity Barrier Management. Available online: https:\/\/www.sintef.no\/en\/projects\/2021\/cybersecurity-barrier-management\/."},{"key":"ref_14","unstructured":"(2020). Security for Industrial Automation and Control Systems\u2014Part 3-2: Security Risk Assessment for System Design (Standard No. IEC 62443-3-2:2020)."},{"key":"ref_15","unstructured":"ISA-GCA (2026, March 05). Security Lifecycles in the ISA\/IEC 62443 Series\u2014Security of Industrial Automation and Control Systems. Available online: https:\/\/21577316.fs1.hubspotusercontent-na1.net\/hubfs\/21577316\/2022%20ISA%20Website%20Redesigns\/ISASecure\/PDFs\/Miscellaneous%20PDFs\/Documents-Articles-and-Technical-Papers\/ISAGCA-Security-Lifecycles-whitepaper.pdf."},{"key":"ref_16","unstructured":"(2013). Industrial Communication Networks\u2014Network and system security\u2014Part 3-3: System Security Requirements and Security Levels (Standard No. IEC 62443-3-3:2013)."},{"key":"ref_17","unstructured":"(2025). Security for Industrial Automation and Control Systems\u2014Part 2-2: IACS Security Protection (Standard No. IEC 62443-2-2 ED1)."},{"key":"ref_18","unstructured":"(2018). Security for Industrial Automation and Control Systems\u2014Part 4-1: Secure Product Development Lifecycle Requirements (Standard No. IEC 62443-4-1:2018)."},{"key":"ref_19","unstructured":"(2010). Industrial Communication Networks\u2014Network and System Security\u2014Part 2-1: Establishing an Industrial Automation and Control System Security Program (Standard No. IEC 62443-2-1:2010)."},{"key":"ref_20","unstructured":"IEC (2026, March 05). Understanding IEC 62443. Available online: https:\/\/www.iec.ch\/blog\/understanding-iec-62443."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"\u00d8ien, K., Hauge, S., Jaatun, M.G., Fl\u00e5, L., and Bodsberg, L. (2022, January 13\u201316). A Survey on Cybersecurity Barrier Management in Process Control Environments. Proceedings of the 2022 IEEE International Conference on Cloud Computing Technology and Science, Bangkok, Thailand.","DOI":"10.1109\/CloudCom55334.2022.00026"},{"key":"ref_22","unstructured":"(2026, March 05). ISA Global Cybersecurity Alliance|ISAGCA. Available online: https:\/\/isagca.org\/."},{"key":"ref_23","unstructured":"Gordon, J. (2026, March 05). The Essential Guide to the IEC 62443 Industrial Cybersecurity Standards. Available online: https:\/\/industrialcyber.co\/features\/the-essential-guide-to-the-iec-62443-industrial-cybersecurity-standards\/."},{"key":"ref_24","unstructured":"Kobes, P. (2023). Guideline Industrial Security\u2014IEC 62443 Is Easy, VDE VERLAG GMBH."},{"key":"ref_25","unstructured":"Lundteigen, M.A. (2026). TTK4175 Lecture Notes, NTNU."},{"key":"ref_26","unstructured":"(2026, March 05). Regulations Relating to Health, Safety, and the Environment in the Petroleum Activities and at Certain Onshore Facilities (The Framework Regulations). Available online: https:\/\/www.havtil.no\/contentassets\/f18375b7184d4cd68fc1c733b318b3dc\/rammeforskriften20_e.pdf."},{"key":"ref_27","unstructured":"(2021). Industrial Automation and Control Systems (Standard No. NORSOK I-002:2021)."},{"key":"ref_28","unstructured":"(2018). Industrial Communication Networks\u2014Installation of Communication Networks in Industrial Premises (Standard No. IEC Standard 61918:2018)."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"94","DOI":"10.1145\/291469.291479","article-title":"Action research","volume":"42","author":"Avison","year":"1999","journal-title":"Commun. ACM"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Lundteigen, M.A., Omang, E., Ottermo, M.V., Hauge, S., and Lee, S. (2023, January 3\u20138). Industry 4.0 for the process industry: Using OPC UA to implement an information model for follow-up of safety instrumented systems. Proceedings of the 33rd European Safety and Reliability Conference (ESREL 2023), Southampton, UK.","DOI":"10.3850\/978-981-18-8071-1_P148-cd"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Pascoe, C., Quinn, S., and Scarfone, K. (2024). The NIST Cybersecurity Framework (CSF) 2.0, National Institute of Standards and Technology.","DOI":"10.6028\/NIST.SP.1301.fre"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/6\/2\/52\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T05:13:35Z","timestamp":1773724415000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/6\/2\/52"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,12]]},"references-count":31,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2026,4]]}},"alternative-id":["jcp6020052"],"URL":"https:\/\/doi.org\/10.3390\/jcp6020052","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,12]]}}}