Search the field guide, causes, requirements, and glossary

IDMZ (industrial demilitarized zone)

A buffer network between the plant's industrial zone and the enterprise network, where traffic from each side terminates instead of passing straight through.

The network analogy

A classic DMZ with a stricter rule: no session crosses it end to end, so data is brokered by servers in the middle.

Why it matters for wireless

If one wireless network serves both enterprise clients and control devices without passing through the IDMZ, it creates exactly the direct path the IDMZ exists to prevent.

The CPwE design guides define the IDMZ as a buffer that enforces data security policies between a trusted network (Industrial Zone) and an untrusted network (Enterprise Zone), where all IACS traffic from either side terminates and none traverses it directly. It may also mark the boundary where IT and OT responsibilities meet.

NIST likewise recommends a DMZ to separate the OT environment from the enterprise network. The difference from an ordinary DMZ is the termination rule.

All terms, A to Z

About this page

Built from 4 sources: 2 standards bodies and labs and 2 vendor documents. Researched and drafted with AI assistance, then reviewed and approved by Ben Rutter on . How pages are made

First published
Last updated
Cite this page

Plain

Ben Rutter. "IDMZ (industrial demilitarized zone)." OT Wireless, published October 5, 2026. https://otwireless.com/glossary/industrial-dmz/

APA 7

Rutter, B. (2026, October 5). IDMZ (industrial demilitarized zone). OT Wireless. https://otwireless.com/glossary/industrial-dmz/

BibTeX

@misc{rutter2026industrialdmz,
  author = {Rutter, Ben},
  title = {{IDMZ (industrial demilitarized zone)}},
  year = {2026},
  howpublished = {\url{https://otwireless.com/glossary/industrial-dmz/}},
  organization = {OT Wireless},
}