Conceptual design turns assessment outcomes into a workable protection approach per zone and per conduit. With zones and conduits identified, review the risk-assessment results, confirm Target Security Level (SL-T), identify physical and cyber access points, and develop a multi-faceted strategy — typically using the Five Ds — for each access point.
This page is Part 3-2 teaching for the design-for-assessment workflow. It is not a separate ZCR. Normative zone partitioning, SL-T and CRS content live in Clause 4; Part 3-3 supplies the technical requirement catalogue when sizing measures to SL-T. The Automation Solution lifecycle Design phase points here from Part 2-2.
Related: ZCR 3 – Zones and Conduits | ZCR 5 | ZCR 6 – CRS | Part 3-3 Security Levels | Four Ts | Five Ds | Conceptual Design Specification | Vulnerabilities / access points | Defence in Depth
For each zone and conduit, develop a physical and cyber protection strategy based on the risk-assessment results, SL-T and the CRS. Apply the Five Ds (Deter, Detect, Delay, Deny, Defeat) so the strategy is multi-faceted. Harmonise physical and cyber policies (Part 2-1 ORG 3).
Use a 5D strategy map: list threats (or access-point scenarios) in the left column, then record at least one mitigation under each D where risk justifies it.
| Threat | Deter | Detect | Delay | Deny | Defeat |
|---|---|---|---|---|---|
| Unauthorised remote access | Warning banner on remote login; policies stating prosecution of intruders | Host intrusion detection (HIDS); event / authentication logs; SIEM alerts | Security hardening of jump hosts; patching; encryption; session / access controls | Firewall rules; VPN with allow-lists; least-privilege access; IPS | Incident-response procedures; revoke sessions / isolate hosts; preserve forensic evidence |
| Malware introduction | Acceptable-use and media policies; warning banners | Anti-virus; IDS; email / URL filtering; SIEM | Patching; hardening; network segmentation; honeypot | Application whitelisting; firewall; removable-media controls | Malware removal tools; IR playbooks; containment via IPS |
Repeat the map for every high-risk threat and access point in that zone or conduit, then carry planned countermeasures into the conceptual design specification and CRS. Full Five D definitions and cyber tool lists: Five Ds of Treating Risk.
Different partitions face different threats, consequences and SL-T values. A plant-wide control set either over-protects low-risk areas or under-protects high-risk ones. Strategy per zone and conduit keeps protection proportionate and makes access-point ownership clear for designers and operators.