Skip to content

DMZ

What is DMZ?

A demilitarized zone is a network segment that acts as a buffer between an organization's internal network and the external internet, hosting public-facing services.

Information Security

Each of these is named in at least one of the same controls as dmz. The number is how many controls name both.

What the standards actually require on dmz

Requirements naming dmz across 6 standards, quoted from the control text.

Segment IT and OT networks using firewalls, DMZs, and unidirectional gateways where feasible.

AWWA-G430-4 · Network Segmentation IT/OT

OT assets should not be directly accessible from the public internet; use jump hosts and DMZs.

CPG-2.G · Limit OT Connections to Public Internet

Design ICS network architecture using defined zones, a demilitarised zone (DMZ) between the control network and the corporate/enterprise network, and VLAN segmentation to separate functions and contain compromise.

CISA-ICS-DID-24 · ICS Network Architecture

UR E26 Goal 2 (Protect) requires network segmentation following IEC 62443 zones and conduits model. Ship networks must be segmented into zones based on criticality + function: Untrusted (internet + crew internet + guest networks);

IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-Boundary · IACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes
IEC 624431 control

Asset owner segments IACS networks into zones and conduits based on risk, separating IACS from corporate IT via DMZ, restricting traffic to documented purposes, and protecting safety systems from other control systems.

62443-2-1-NSEG · Network Segmentation and Zone/Conduit Implementation

Questions people ask about dmz

What is DMZ?
A demilitarized zone is a network segment that acts as a buffer between an organization's internal network and the external internet, hosting public-facing services.
Why is DMZ important for compliance?
DMZ is a key concept in Information Security. Understanding dmz helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address DMZ?
DMZ appears in the requirement text of AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, CISA Industrial Control Systems (ICS) Security Guidance, IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems, IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1). Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about DMZ?
Explore our compliance framework pages to see how dmz applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how DMZ applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.