Scenario / Evaluation model
Illustrative deployment scenario
Critical Infrastructure Monitoring
An illustrative evaluation model in which defined operational data from a protected facility are released one way so that an external monitoring environment can continuously review necessary status information.
This content is only for identifying source, hardware-enforced one-way boundary, and destination conditions.

Scenario context image; not a record of a product deployment.
Photo: Krafla power plant - Kröflustöð - alternativeAuthor: Villy Fink IsaksenLicense: CC BY-SA 4.0Source:Wikimedia Commons
Source → boundary → destination
Complete Data Path
Source / Source Zone
Source Zone systems and data
- Sources
- Facility monitoring systems, Defined PLC and RTU data sources
- Data
- Equipment status and alarms, Approved operational telemetry
Hardware-enforced boundary
Hardware-enforced one-way boundary
Source Modulesource-to-destination one-way fiber data transferReceiving ModuleWithin the listed hardware version, topology, and test scope, the Source Module receives approved facility-monitoring data and sends it across the specified physical one-way link as source-to-destination one-way fiber data transfer; the Receiving Module then receives the data and provides a monitoring interface usable by destination systems.
Destination / Destination Zone
Destination Zone systems and uses
- Destinations
- Centralized monitoring environments, Historian and analytics systems
- Use
- For the Destination Zone to review equipment status, alarms, and approved representations of operational data.
Evaluation inputs
Evaluation Considerations
- 01
Define the status, alarm, and telemetry data that need to leave the protected security zone.
- 02
Confirm source polling behavior and freshness requirements for the one-way data path.
- 03
Confirm how Destination Zone monitoring systems will use the data interface provided by the Receiving Module.
