An industrial manufacturing facility needs to secure its operational technology (OT) network housing Programmable Logic Controllers (PLCs) from the corporate IT network. Unauthorized network scanning originating from corporate workstations recently reached the shop floor. The security architect must permit authorized engineering personnel to conduct remote maintenance on PLCs while preventing direct network routing between IT endpoints and OT devices. Which of the following network architecture designs best meets these security requirements?
- APlace the PLCs and corporate engineering workstations on the same VLAN to eliminate routing overhead during maintenance operations.
- Deploy a jump box in a segmented DMZ requiring multifactor authentication and session recording for management traffic between IT and OT networks.Answer
- CRely on an edge perimeter firewall between the corporate WAN and OT network while permitting unrestricted internal routing across internal subnets.
- DConfigure an inline honeypot within the OT network to act as a detective control that actively drops incoming SSH traffic targeting PLCs.
Answer
Deploying a jump box in a segmented DMZ requiring multifactor authentication and session recording for management traffic between IT and OT networks.
Deploying a jump box within a demilitarized zone (DMZ) between corporate IT and industrial control OT networks prevents direct network connectivity between endpoints. Requiring strong authentication and session logging ensures remote maintenance traffic is securely managed, authorized, and audited without exposing PLCs directly to enterprise network risks.
Step-by-Step Solution
Key Concept
Secure Network Design and Segmentation using DMZ and Jump Servers
Estimated Time:1m 30s