Search the field guide, causes, requirements, and glossary

Security

These clauses segment the wireless network, keep authentication on the plant side of every outside link, and make every key and session timer a recorded, tested number, because security settings change the roam and can drop a vehicle on a schedule.

Security settings shape the roam and set timers that can end a session on schedule. These clauses put wireless devices in their own segment, keep the authentication server close to the floor, choose security and roaming together, record every rekey and session timer, and watch for access points you do not own. They sit inside your security program; they do not replace it.

Free to copy into any specification (CC0). A starting point for your own wording, not a certified design. All clause groups

  1. 6.1 Wireless in its own segment shall

    Wireless devices shall sit in their own network segment, and access points shall connect through a boundary protection device that enforces the owner's security policy between the wireless segment and the rest of the control network.

    Where this comes from

  2. 6.2 Authentication inside the plant shall

    Authentication of plant floor clients shall not depend on any link outside the plant. The authentication server, or a local proxy or replica of it, shall sit inside the plant's network zone, and its round trip multiplied by the number of exchanges in one full authentication shall be counted in the outage budget for every join and reauthentication.

    Where this comes from

  3. 6.3 Security chosen together with roaming shall

    The security configuration of each SSID that carries control traffic shall be one under which every client model on it completes a fast transition, and roam time under that configuration shall be measured on the production client before the configuration is approved.1

    Where this comes from

  4. 6.4 Key and session timers recorded and tested shall

    The design shall record every key and session timer on control SSIDs and the authentication server: group key rekey, pairwise rekey, 802.1X reauthentication period, RADIUS Session-Timeout and Termination-Action, and idle timeout. Where a session timeout is sent, the Termination-Action shall request reauthentication rather than end the session. Each client model shall pass several cycles of every timer before rollout.2

    Where this comes from

  5. 6.5 Unapproved access points detected, never jammed shall

    The wireless system shall detect access points and networks it does not own in production areas, alert a named person to any heard on a control channel or connected to the wired network, and shall not deauthenticate, contain, or jam networks the owner does not own.

    Where this comes from

About this page

Built from 12 sources: 4 standards bodies and labs, 1 regulator or government source, 1 protocol owner or alliance and 6 vendor documents. Researched and drafted with AI assistance, then reviewed and approved by Ben Rutter on . How pages are made

First published
Last updated
Change history (1)
  • First published
Cite this page

Plain

Ben Rutter. "Security." OT Wireless, published October 6, 2026, updated October 5, 2026. https://otwireless.com/clauses/security/

APA 7

Rutter, B. (2026, October 6). Security. OT Wireless. https://otwireless.com/clauses/security/

BibTeX

@misc{rutter2026security,
  author = {Rutter, Ben},
  title = {{Security}},
  year = {2026},
  howpublished = {\url{https://otwireless.com/clauses/security/}},
  organization = {OT Wireless},
}