Design and operate OT network architecture per NIST SP 800-82 Rev 3 Chapter 6 (OT Security Architecture). Apply the Purdue Enterprise Reference Architecture as the foundational structure: Level 0 Physical Process + Level 1 Basic Control + Level 2 Area Supervisory Control + Level 3 Site Operations + Level 3.5 DMZ + Level 4 Site Business + Level 5 Enterprise Business. Implement IEC 62443 zoned and conduit architecture: every zone has documented assets + trust level + security requirements + access policy + connected conduits with explicit traffic policy. Network segmentation must enforce (a) IT-OT separation with documented gateway + DMZ + protocol-aware firewall + unidirectional gateway (data diode) for highest-criticality boundaries, (b) intra-OT segmentation isolating safety instrumented systems + critical control loops from general OT, (c) remote vendor access via jump host + privileged access management + session recording + just-in-time access + multi-factor authentication, (d) wireless and field communications isolation per Chapter 6 Section 6.7 with cryptographic protection where appropriate. Document the network architecture + asset inventory + zone-conduit matrix + maintain authoritative diagrams. Apply defence-in-depth across perimeter + network + host + application + data layers.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.