IDMZ (industrial demilitarized zone)
A buffer network between the plant's industrial zone and the enterprise network, where traffic from each side terminates instead of passing straight through.
The network analogy
A classic DMZ with a stricter rule: no session crosses it end to end, so data is brokered by servers in the middle.
Why it matters for wireless
If one wireless network serves both enterprise clients and control devices without passing through the IDMZ, it creates exactly the direct path the IDMZ exists to prevent.
The CPwE design guides define the IDMZ as a buffer that enforces data security policies between a trusted network (Industrial Zone) and an untrusted network (Enterprise Zone), where all IACS traffic from either side terminates and none traverses it directly. It may also mark the boundary where IT and OT responsibilities meet.
NIST likewise recommends a DMZ to separate the OT environment from the enterprise network. The difference from an ordinary DMZ is the termination rule.
About this page
Built from 4 sources: 2 standards bodies and labs and 2 vendor documents. Researched and drafted with AI assistance, then reviewed and approved by Ben Rutter on . How pages are made
- First published
- Last updated
Cite this page
Plain
Ben Rutter. "IDMZ (industrial demilitarized zone)." OT Wireless, published October 5, 2026. https://otwireless.com/glossary/industrial-dmz/
APA 7
Rutter, B. (2026, October 5). IDMZ (industrial demilitarized zone). OT Wireless. https://otwireless.com/glossary/industrial-dmz/
BibTeX
@misc{rutter2026industrialdmz,
author = {Rutter, Ben},
title = {{IDMZ (industrial demilitarized zone)}},
year = {2026},
howpublished = {\url{https://otwireless.com/glossary/industrial-dmz/}},
organization = {OT Wireless},
}