Use when implement network segmentation based on the Purdue Enterprise
Scanned 9/8/2026
Install to Claude Code
npx -y skills add oyi77/1ai-skills --skill implementing-purdue-model-network-segmentation --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Implementing Purdue Model Network Segmentation?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/oyi77-implementing-purdue-model-network-segmentation)More formats (shields.io, HTML) on the badges page.
---
name: implementing-purdue-model-network-segmentation
description: Use when implement network segmentation based on the Purdue Enterprise
Reference Architecture (PERA) model to separate industrial control system networks
into hierarchical security zones from Level 0 physical process through Level 5 enterprise,
enforcing strict traffic control between OT and IT domains. . Use when working with
implementing purdue model network segmentation.
domain: cybersecurity
tags:
- ot-security
- ics
- purdue-model
- network-segmentation
- iec62443
- defense-in-depth
- dmz
- scada
subdomain: ot-ics-security
version: '1.0'
author: oyi77
license: Apache-2.0
nist_csf:
- PR.IR-01
- DE.CM-01
- ID.AM-05
- GV.OC-02
category: cybersecurity
---
# Implementing Purdue Model Network Segmentation
## Overview
Cybersecurity skill for implementing purdue model network segmentation. Follows industry best practices and security standards.
## When to Use
**Trigger phrases:**
- "implementing purdue model network segmentation"
- "Implement network segmentation based on the Purdue Enterprise Reference Architec"
- When designing or retrofitting network architecture for an ICS/SCADA environment
- When implementing IEC 62443 zone and conduit requirements in a brownfield plant
- When creating the IT/OT DMZ (Level 3.5) to control data flow between enterprise and control networks
- When remediating audit findings about flat OT networks or direct IT-to-OT connectivity
- When segmenting a converged IT/OT network after an acquisition or merger
**Do not use** for micro-segmentation within a single Purdue level (see implementing-zone-conduit-model-for-ics), for cloud-native environments without traditional ICS networks, or for network segmentation in purely IT environments.
## When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
## Prerequisites
- Complete OT asset inventory with Purdue level classification for each device
- Network architecture diagram showing current topology, VLANs, and firewall placements
- Industrial firewalls capable of deep packet inspection for OT protocols (Palo Alto, Fortinet, Cisco)
- Understanding of required data flows between Purdue levels (historian replication, remote access, patch distribution)
- Change management approval from plant operations for network modifications
## Workflow
```python
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```
1. **Assess Requirements** — Evaluate current environment and define purdue model network segmentation implementation requirements.
2. **Design Architecture** — Plan the purdue model network segmentation architecture, including components, integrations, and data flows.
3. **Configure Components** — Set up and configure each purdue model network segmentation component according to best practices.
4. **Test Integration** — Validate that all components work together. Run functional and security tests.
5. **Deploy to Production** — Roll out the implementation with monitoring and rollback capabilities.
6. **Validate and Document** — Verify the implementation meets requirements. Document configuration and runbooks.
## Tools
- **Configuration Management** — Infrastructure as code and automation
- **Monitoring Stack** — Observability and alerting
- **Documentation Platform** — Runbooks and architecture docs
## Process
1. **Prepare** — Gather requirements, verify prerequisites, set up environment
1. **Execute** — Run implementing purdue model network segmentation workflow with configured parameters
1. **Verify** — Validate output meets requirements, document results
## Verification
- [ ] All purdue model network segmentation procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization
## Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!