An industrial DMZ creates a controlled zone between the OT network and enterprise systems so direct unrestricted connectivity is avoided.
In the Purdue model it is commonly described as Level 3.5, between manufacturing operations and the enterprise network.
Controlled publish/subscribe exchange across zones.
Authentication, authorization, routing, limits and logging.
Controlled and auditable administrative access.
Controlled transfer of historian, file or other approved data.
Allow only the required source, destination, protocol, port and operation. Avoid broad unrestricted paths between OT and IT.