Passive inventory and visibility
No control can be built without knowing what runs on the OT network. The inventory is derived by listening to traffic rather than touching devices; protocol, vendor, firmware version and communication pattern all come from that listening.
- No packets are sent to devices; traffic is only observed
- Communication patterns establish the normal behavior baseline
- Legacy protocols run without authentication and are flagged
- The inventory is reconciled against maintenance records
Zone and conduit design
The boundary between OT and IT is not one firewall rule. Production zones are separated by function, movement between zones passes through a controlled conduit, and direct internet access is removed.
- Zones follow process function
- The protocol list crossing a conduit is short and justified
- Production zones hold no direct internet access
- An emergency path is designed rather than opened later
Controlled remote access
The vendor technician arriving for maintenance is the most used entry route into OT. Access opens against a work request, the session is recorded, and the connection is not left standing. Legacy routes such as modems and direct lines are closed.
- Vendor access is tied to a scheduled appointment
- Session records can be reviewed afterwards
- Standing modem and direct-line connections are closed
- Changes made during access are recorded
OT-aware monitoring
Monitoring is deployed so it cannot affect production, and alarm thresholds are tuned with process knowledge. An unexpected write command from an engineering workstation matters more than a typical IT alert.
- Alarm thresholds are tuned with the process engineer
- Write commands are watched separately from read traffic
- Incident flow follows the production shift pattern
- Compensating controls are planned where patching is impossible