# What is the Purdue Model?

> The Purdue model is a layered reference model for organizing manufacturing and control functions from the physical process and basic control through supervisory and site operations to enterprise systems.

- Canonical URL: https://yellowcube.eu/glossary/purdue-model/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It originated in work on computer-integrated manufacturing and influenced the functional hierarchy used by ISA-95 and IEC 62264. Security architects commonly adapt the layers to reason about trust boundaries, communication paths, and placement of an industrial DMZ.

The model is a way to describe functions, not a mandatory network blueprint. Layer numbering and the familiar “Level 3.5” DMZ vary among implementations, and a modern environment may include cloud services, edge computing, wireless systems, IIoT devices, remote operations, and shared platforms that do not fit a simple vertical hierarchy. Architecture decisions should follow actual functions, hazards, ownership, and data flows.

### Key points

- **Map what exists:** Place assets by operational function and dependency rather than by device name, supplier, IP range, or an idealized diagram.
- **Identify required flows:** Document source, destination, direction, protocol, timing, purpose, and failure behavior before designing boundaries.
- **Enforce separation:** Use firewalls, proxies, unidirectional gateways, an IDMZ, or other suitable controls to prevent unnecessary direct communication between distant trust levels.
- **Document exceptions:** Record cloud, remote, safety, mobile, and cross-site connections that bypass or extend the hierarchy, assign owners, and apply compensating controls.
- **Important limitation:** A Purdue diagram is not evidence of segmentation or safety. Flat routes, shared credentials, unmanaged maintenance links, vulnerable boundary services, or poorly designed failure behavior can defeat the intended architecture and disrupt operations.

### Related terms

[Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/>) · [Industrial demilitarized zone (IDMZ)](<https://yellowcube.eu/glossary/industrial-demilitarized-zone/>) · [IEC 62443](<https://yellowcube.eu/glossary/iec-62443/>) · [Industrial control system (ICS)](<https://yellowcube.eu/glossary/industrial-control-system/>)

### Sources

[ISA: ISA-95 Enterprise-Control System Integration Standards](https://www.isa.org/standards-and-publications/isa-standards/isa-95-standard) · [NIST SP 800-82 Rev. 3: Guide to Operational Technology Security](https://csrc.nist.gov/pubs/sp/800/82/r3/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

