Automation Glossary • Network conduit

What Is a Network Conduit Under IEC 62443?

Merobix Engineering • • 7 min read

Under IEC 62443, a conduit is the controlled pathway that carries traffic between two zones. Where a zone groups assets that share a security level, the conduit is the deliberate, guarded channel through which those zones are allowed to communicate. This page zooms in on the conduit specifically: what it is, what security controls sit on it, and how a team documents the flows it is allowed to carry.

Back to Blog

Network conduit in one line: In IEC 62443, a conduit is the defined communication pathway that connects zones and controls the traffic passing between them. It is not just a cable but a managed channel: every flow that crosses it should be intentional, limited to specific sources, destinations, and protocols, and protected by security controls appropriate to the trust difference between the zones it links.

The Conduit as a Controlled Pathway

The zones-and-conduits idea splits an OT system into zones of grouped assets and conduits that connect them, and the conduit is the connecting half. A conduit is every path by which one zone talks to another, treated as a single managed thing rather than as incidental wiring. Its defining property is control: traffic does not simply flow between zones, it flows through a conduit that governs what may cross.

This reframes an inter-zone link from a passive connection into an active boundary. A conduit has an inside and an outside, a set of flows it is meant to carry, and a set it is meant to refuse. Because a conduit joins two zones that may sit at different trust or security levels, it is the exact place where the difference between those levels is enforced, so the more trusted zone is protected from the less trusted one across it.

Thinking of the pathway as a distinct object is what makes it manageable. A conduit can be named, owned, assessed, and secured on its own terms, separate from the zones at either end. That lets a team reason about each inter-zone relationship deliberately, asking what this specific pathway is for, who relies on it, and what would happen if it were misused, rather than leaving the connections between zones as an unexamined web.

Security Controls That Sit on a Conduit

Because a conduit is where zones meet, it is where the enforcement lives. The most basic control is filtering: a device on the conduit, such as a firewall, permits only the specific sources, destinations, protocols, and directions that the connected zones are meant to exchange, and denies everything else. This turns the conduit into a chokepoint where the allowed conversation is small and explicit rather than open-ended.

Conduits also carry the controls appropriate to the risk they represent. A pathway crossing a large trust gap may warrant deeper inspection of the traffic, enforcement that connections only originate from the expected side, protections for the confidentiality and integrity of the data in transit, and logging so that what crosses can be reviewed. A conduit between two similar, low-risk zones may need far less. The controls are matched to the trust difference the conduit bridges.

Monitoring is part of the conduit's job as well. Because a conduit is the place traffic must pass to move between zones, it is the ideal spot to watch for anything unexpected, a flow that was never supposed to exist, a connection in the wrong direction, or a volume that does not fit the pathway's purpose. A well-instrumented conduit not only limits what crosses but also makes visible any attempt to cross in a way that was not agreed.

Documenting the Allowed Flows

A conduit is only as good as the record of what it is allowed to carry. The central artifact is a definition of the permitted flows: for each conversation the conduit supports, which zone or device is the source, which is the destination, which protocol and port it uses, and in which direction it may be initiated. This list is the specification the conduit's controls should enforce, and everything not on it should be denied.

Documenting flows this way turns segmentation from an aspiration into something checkable. With an explicit list of allowed flows per conduit, a firewall ruleset can be audited against the intended design, a new request to open a path can be evaluated against the existing set, and drift, where rules quietly accumulate beyond what was ever agreed, becomes visible. The document is the shared reference that keeps the actual configuration honest over time.

Good conduit documentation also captures the why, not just the what. Recording the purpose and owner of each allowed flow means that, when a rule is later questioned, someone can say what it is for and whether it is still needed, which is essential for pruning stale access. A conduit whose flows are written down, justified, and owned is one that can be reviewed and tightened deliberately, rather than a mystery of accreted rules nobody dares to touch.

Conduits, SCADA Data, and Cloud Monitoring

In a SCADA system, conduits are the governed channels along which process data travels upward and commands travel downward. The pathway that carries values from a control zone up to a supervisory zone is a conduit, and defining it well means the supervisory layer receives exactly the data it needs while the control zone is exposed to nothing more. Every legitimate movement of SCADA data across a zone boundary rides a conduit that was meant to carry it.

This is what makes safe cloud monitoring a matter of design rather than luck. The path that eventually feeds a cloud dashboard is a conduit, or a chain of conduits, whose allowed flows are written down: OT publishes specific values through a defined pathway toward a gateway or a buffer zone, and the connection outward to the cloud is likewise a documented, controlled flow. Because each hop is a conduit with an enforced flow list, the data can leave the plant without opening an uncontrolled route back in.

For field operations this means visibility and containment are engineered on the same pathways. The conduits that let operators watch a remote site's values from a dashboard are the very channels whose flow lists ensure nothing more than those values can cross, and whose monitoring would reveal any attempt to send something that was never agreed. Treating each inter-zone pathway as a documented, controlled conduit is what lets a plant share its data widely while keeping its zones firmly separated.

Frequently Asked Questions

What is a conduit in IEC 62443?

A conduit is the controlled communication pathway that connects two zones and governs the traffic passing between them. It is treated as a managed channel rather than incidental wiring, carrying only the flows the connected zones are meant to exchange and enforcing the security controls appropriate to the trust difference between them.

What security controls belong on a conduit?

At minimum, filtering that permits only specific sources, destinations, protocols, and directions and denies everything else, usually enforced by a firewall. Conduits crossing a larger trust gap may add deeper traffic inspection, enforcement of connection direction, protection of data in transit, and logging. Monitoring the conduit for unexpected flows is also part of its job. The controls scale to the risk.

How do you document a conduit's allowed flows?

List every permitted flow the conduit carries, recording the source, destination, protocol and port, and the direction in which a connection may be initiated, and treat everything not on the list as denied. Capturing the purpose and owner of each flow as well lets the list be audited against the firewall rules, evaluated for new requests, and pruned of stale access over time.

Sources & Further Reading

Primary references from the standards bodies and regulators that define this topic:

Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Flat network  •  Broadcast storm  •  Managed vs unmanaged switch  •  Hub-and-spoke  •  Dual-homed device  •  Link aggregation  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →