Direct implementation supportHigh confidence
Why: Logical segmentation's core work — defining zones, placing enforcement points between them, and deciding what crosses — is boundary protection at the key internal boundaries this requirement names. The practice builds the monitored chokepoints the requirement expects communications to pass through.
What this does not claim: Supports implementation of the requirement; it does not satisfy it on its own. The requirement also covers the external boundary — internet edge, partner connections — and the monitoring of communications, not only their restriction; an assessor evaluates both halves across the full defined boundary, not just the internal zones the segmentation effort drew.
Practice-side activities- Define zones from the asset inventory and business function, then place enforcement points between them
- Restrict inter-zone traffic to documented flows
- Review inter-zone rules on a cadence, pruning what no longer has an owner
Evidence this produces- Zone model and network diagram with enforcement points marked
- Inter-zone rule exports with dated reviews
- Denied-traffic logs at internal boundaries for a sampled period
Where this holds: Strongest where the network is being deliberately re-architected into zones; external-boundary work often predates this practice and is evaluated on its own evidence.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06
Partial implementation supportModerate confidence
Why: Strict OT segmentation — zones and conduits separating business networks from production — establishes exactly the key internal boundary this requirement cares most about in a manufacturing environment, with an enforcement point governing what crosses it.
What this does not claim: May partially address the requirement, and only where OT assets fall within the assessed CUI boundary — much OT never touches CUI at all. The external-boundary and communications-monitoring expectations sit mostly with the IT estate, and no boundary change in OT can be allowed to interrupt safety systems or production interlocks: firewall work between IT and OT happens in planned windows with safety review and rollback, not on a normal change ticket.
Practice-side activities- Model zones and conduits between business and production networks
- Enforce the IT/OT boundary with a firewall or industrial DMZ, allowing only qualified flows
- Review what actually crosses the boundary against what was designed to
Evidence this produces- IT/OT boundary diagram with conduits identified
- Boundary rule exports with justifications
- Boundary change records showing safety review and scheduled windows
Where this holds: Holds only for OT segments inside the assessed CUI boundary; elsewhere the practice is sound engineering without bearing on this requirement.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06