# What is an Industrial Demilitarized Zone (IDMZ)?

> An industrial demilitarized zone (IDMZ) is a controlled network zone placed between enterprise IT and operational technology networks to prevent direct communication across their boundary.

- Canonical URL: https://yellowcube.eu/glossary/industrial-demilitarized-zone/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Services in the IDMZ mediate necessary exchanges — such as replicated historian data, remote-access sessions, file transfer, replicated or proxied authentication support, update staging, or application proxies — while separate enforcement points restrict traffic on each side.

An IDMZ is useful because compromise of one environment should not provide an unrestricted path into the other. Connections should terminate or be relayed in the zone where practical, and rules should permit only the required source, destination, protocol, direction, and time.

### Key points

- **Use two controlled boundaries:** Separate the IDMZ from both enterprise and OT networks, administer those boundaries deliberately, and prevent routes that bypass the zone.
- **Place mediation services carefully:** Use hardened jump services, proxies, transfer mechanisms, replicated data services, or remote-access gateways rather than dual-homed general-purpose hosts that bridge networks.
- **Constrain every flow:** Document ownership and purpose, default-deny unnecessary traffic, control outbound as well as inbound communication, and review temporary rules promptly.
- **Monitor and recover:** Centralize relevant boundary events, protect administrative access, test backups and rebuild procedures, and plan how essential operations continue if IDMZ services fail.
- **Important limitation:** An IDMZ is not an air gap or a guarantee of safety. Weak credentials, vulnerable services, permissive rules, shared administration, direct maintenance links, or an availability failure in a critical broker can defeat the boundary or disrupt operations.

### Related terms

[Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/>) · [Firewall](<https://yellowcube.eu/glossary/firewall/>) · [Data diode / unidirectional gateway](<https://yellowcube.eu/glossary/data-diode-unidirectional-gateway/>) · [Purdue model](<https://yellowcube.eu/glossary/purdue-model/>) · [Secure remote access](<https://yellowcube.eu/glossary/secure-remote-access/>) · [Information technology and operational technology convergence (IT/OT convergence)](<https://yellowcube.eu/glossary/information-technology-and-operational-technology-convergence/>)

### Sources

[NIST SP 800-82 Rev. 3: Guide to Operational Technology Security](https://csrc.nist.gov/pubs/sp/800/82/r3/final) · [CISA: Layering Network Security Through Segmentation](https://www.cisa.gov/sites/default/files/publications/layering-network-security-segmentation_infographic_508_0.pdf) · [CISA: Primary Mitigations to Reduce Cyber Threats to Operational Technology](https://www.cisa.gov/sites/default/files/2025-05/fact-sheet-primary-mitigations-to-reduce-cyber-threats-to-operational-technology-508c.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

