Policy model configuration

Manage zones, conduits, devices, and ranges.

Policy model planning

To plan the policy model, establish the following:
  • Zones and their security requirements. See Zones.
  • Conduits to define trust relationships between policy model components. See Conduits.
  • Devices, their IP addresses, and zone assignments. See Devices.
Discover
FactoryTalk Policy Manager
capabilities to plan advanced configuration for the policy model. See Policy management capabilities

Policy model auditing

FactoryTalk System Services
generate diagnostic messages upon specific actions and log them to
FactoryTalk Diagnostics
. These messages can be later reviewed as a part of an audit.
The diagnostic messages are divided into these categories:
Model deployment
Sent when you deploy a security policy model or cancel deployment.
Model creation
Sent when you create a security policy model.
Model editing
Sent when you edit the security policy model.

Policy model example

Policy model example
Policy model example
Diagram description - policy model example
Item
Name
Description
1
CIP and OPC UA
zone
Contains
OPC UA
devices and
CIP
devices.
2
Secure
conduit
Connects
CIP and OPC UA
zone with
OPC UA
zone.
3
Trusted unsecure
conduit
Connects
OPC UA
zone with
CIP Security
zone.
4
OPC UA
zone
Contains
OPC UA
devices only, including two
OPC UA
clients and one
OPC UA
server.
5
CIP Security
zone
Contains three
CIP
devices.
6
Onboarding Area
container
Contains devices found by Automatic Policy Deployment that can be added to the policy model.
There are no devices found by Automatic Policy Deployment in this example.
7
Unassigned
container
Contains devices added to the policy model but not added to any zone in the policy model.
There are two unassigned devices in this example.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal