Glossary

OT cybersecurity, defined.

The terms that come up on a plant floor, in an audit, and in a proposal.

Defense-in-Depth
Defense-in-Depth is the practice of layering independent security controls so that no single failure exposes the process. In OT it typically combines network segmentation, governed access, hardened devices, monitoring, and response procedures.
DMZ (Demilitarized Zone)DMZ
A DMZ is a separate network segment placed between two networks of different trust so that systems needing exposure to the less trusted side can be reached without opening the more trusted side. At the internet edge it hosts public servers; inside an industrial company, the industrial DMZ separates IT from OT.
EtherNet/IP
EtherNet/IP is an industrial Ethernet protocol that carries the Common Industrial Protocol (CIP) over standard TCP/IP and UDP. Managed by ODVA and widely used with Rockwell Automation controllers, it is one of the three protocols most often found on cement, mining, and aggregates plant floors.
Industrial DMZiDMZ
An industrial DMZ is a buffer network placed between the plant control network and the enterprise network so that no traffic passes directly between the two. Servers in the iDMZ, such as patch relays, historian mirrors, and remote-access brokers, terminate connections from each side.
ISA/IEC 62443
ISA/IEC 62443 is the international series of standards for the security of industrial automation and control systems. It defines zones and conduits for segmenting a plant, security levels (SL 0 to 4) for how much protection each zone needs, and seven foundational requirements that controls are measured against.
IT/OT Segmentation
IT/OT segmentation is the separation of the plant control network (OT) from the corporate network (IT) so that an incident on one cannot spread to the other. It is enforced with firewalls, VLANs, and an industrial DMZ, and documented as zones and conduits.
Modbus
Modbus is a simple, open industrial protocol introduced by Modicon in 1979 for reading and writing registers in controllers. Modbus TCP runs it over Ethernet on port 502 and Modbus RTU over serial lines; both are still everywhere because nearly every device speaks them.
NIST CSF 2.0
The NIST Cybersecurity Framework 2.0, published in 2024, organizes a security program into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is a management framework for deciding and communicating priorities rather than a technical standard.
NIST SP 800-82 Rev. 3
NIST SP 800-82 Revision 3 is the US National Institute of Standards and Technology's Guide to Operational Technology Security, published in 2023. It explains how to apply risk management and security controls to OT environments where availability and safety come before confidentiality.
OT Asset Inventory
An OT asset inventory is a maintained record of every device on the control network: controllers, HMIs, switches, servers, and remote-access endpoints, each with make, model, firmware, network location, and support status. It is the first control in any OT security program because nothing can be segmented, patched, or monitored unless it is known.
OT Network Monitoring
OT network monitoring is the continuous, passive observation of traffic on a control network to maintain an accurate asset inventory, detect anomalies and misconfigurations, and catch security events before they affect production. It is built around industrial protocols and around the rule that availability comes first.
OT Service Owner
OT Service Owner is Potenza's term for a named, accountable party that owns OT security across an operator's plants as an operational service: governance, change control, vendor access, and continuous risk awareness. Its defining rule is structural independence: the OT Service Owner cannot be the OT Vendor.
Profinet
Profinet is an industrial Ethernet standard maintained by PROFIBUS & PROFINET International and commonly used with Siemens automation. It carries real-time I/O between controllers and field devices on standard Ethernet hardware and is the successor to the serial Profibus fieldbus.
Purdue ModelPERA
The Purdue Model is a reference architecture that organizes an industrial network into levels, from the physical process at Level 0 up to enterprise IT at Level 5. It is the common map for deciding what may talk to what, and it underlies ISA/IEC 62443 zoning and NIST SP 800-82 guidance.
Structural Independence
Structural Independence is Potenza's term for the principle that the party assessing and governing an OT network should have no equipment to sell on it and no vendor quota to meet. It is a separation of roles, not a judgment of any vendor: the same reason auditors do not keep the books.
Topology of Record
Topology of Record is Potenza's term for the authoritative, maintained map of an OT network: assets, VLANs, zones, traffic flows, and remote paths, kept current through change control. It is the artifact every later decision depends on, from segmentation design to incident response.
Zero Trust in OT
Zero Trust is a security model in which no user, device, or connection is trusted by default because of where it sits on the network; every access is verified and limited to what is needed. Applied to OT it means brokered, least-privilege access to controllers rather than a flat trusted plant network.

See these terms applied to your plant

A scoped Topology Assessment turns the vocabulary into an inventory, a topology of record, and a segmentation plan for your own OT network.

Schedule a Conversation