DMZ
What is DMZ?
A demilitarized zone is a network segment that acts as a buffer between an organization's internal network and the external internet, hosting public-facing services.
Terms that appear alongside dmz
Each of these is named in at least one of the same controls as dmz. The number is how many controls name both.
- network segmentation 8 shared controls
- firewall 5 shared controls
- nist 5 shared controls
- zero trust 4 shared controls
- microsegmentation 4 shared controls
- remote access 4 shared controls
- remote access vpn 3 shared controls
- vlan 3 shared controls
Frameworks that govern dmz
What the standards actually require on dmz
Requirements naming dmz across 6 standards, quoted from the control text.
Segment IT and OT networks using firewalls, DMZs, and unidirectional gateways where feasible.
AWWA-G430-4 · Network Segmentation IT/OT →OT assets should not be directly accessible from the public internet; use jump hosts and DMZs.
CPG-2.G · Limit OT Connections to Public Internet →Design ICS network architecture using defined zones, a demilitarised zone (DMZ) between the control network and the corporate/enterprise network, and VLAN segmentation to separate functions and contain compromise.
CISA-ICS-DID-24 · ICS Network Architecture →UR E26 Goal 2 (Protect) requires network segmentation following IEC 62443 zones and conduits model. Ship networks must be segmented into zones based on criticality + function: Untrusted (internet + crew internet + guest networks);
IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-Boundary · IACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes →NSS-17 + NSS-42-G require facility computer security architecture organised by Computer Security Zones (CSZs) implementing IAEA zone model.
IAEA-NSS17-Architecture-Zones-DefenceInDepth-Segmentation · IAEA NSS-17 - Computer Security Architecture + Zone Model + Defence in Depth + Network Segmentation + Boundary →Asset owner segments IACS networks into zones and conduits based on risk, separating IACS from corporate IT via DMZ, restricting traffic to documented purposes, and protecting safety systems from other control systems.
62443-2-1-NSEG · Network Segmentation and Zone/Conduit Implementation →Questions people ask about dmz
What is DMZ?
Why is DMZ important for compliance?
Which compliance frameworks address DMZ?
Where can I learn more about DMZ?
See how DMZ applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.