Section 3: Network Segmentation in the Purdue Model
In the Model, each level of the industrial architecture is not only functionally distinct but also logically and physically separated through dedicated security mechanisms
- Each level is segmented by firewalls or data diodes.
- Limits access across levels based on necessity.
- Minimizes risk of lateral movement from IT to OT.

