Purdue Model
The Purdue model is a hierarchical reference architecture that divides industrial systems into levels, from the physical process and controllers up to enterprise IT, and is widely used to plan OT network segmentation.
The Purdue model, derived from the Purdue Enterprise Reference Architecture developed at Purdue University, is a hierarchical reference model that divides industrial and enterprise systems into levels. Level 0 is the physical process with sensors and actuators, Level 1 holds basic control such as PLCs, Level 2 contains supervisory systems such as HMIs and SCADA, Level 3 covers site operations such as MES and historians, and Levels 4 and 5 hold business and enterprise systems such as ERP.
In OT security the model is used to plan network segmentation: each level or group of levels becomes a separate network, and traffic between them is restricted to defined, necessary flows. An industrial demilitarised zone, often called Level 3.5, is inserted between the enterprise and operations layers so that no traffic passes directly between IT and control networks. The levels also underpin the ISA-95 standard for enterprise-control integration and are commonly used to map IEC 62443 zones.
The model was conceived before cloud services and the industrial internet of things, which create data paths from field devices straight to cloud platforms. Critics argue that strict layering no longer reflects modern architectures, yet it remains a widely used vocabulary for describing where an asset sits and which communications are expected. Applied pragmatically, it is combined with zones and conduits, deny-by-default rules and monitoring of every crossing between levels.
Key points
- Derived from the Purdue Enterprise Reference Architecture developed at Purdue University
- Levels run from 0 (physical process) through control and operations to enterprise IT
- The industrial DMZ between IT and OT is often called Level 3.5
- Used to plan segmentation and expected data flows between levels
- Cloud and IIoT connectivity challenge its strict layering
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- Industrial DMZ (IDMZ)OT & Industrial Cybersecurity
- OT Network SegmentationOT & Industrial Cybersecurity
- Zones and ConduitsOT & Industrial Cybersecurity
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- Supervisory Control and Data Acquisition (SCADA)PLC & Industrial Control
- Programmable Logic Controller (PLC)PLC & Industrial Control
Terms that refer to Purdue Model
- Hybrid CloudCloud & AI Infrastructure
- Industrial EthernetPLC & Industrial Control
- ISA-95 (IEC 62264)PLC & Industrial Control
- IT vs OT SecurityOT & Industrial Cybersecurity
- Operational Technology (OT) SecurityOT & Industrial Cybersecurity
- Secure Remote Access for OTOT & Industrial Cybersecurity
- Smart FactoryIndustry 4.0 & Manufacturing Operations
- Zero Trust Architecture (ZTA)Cybersecurity & Compliance