Blueprint review report: Smart Souq Al-Mubarakiya, IoT and OT trust zones
| Source | smart-mubarakiya.hisn |
| Framework | iec62443 |
| Date | 2026-09-03 |
| Tool | Hisn 0.7.0 |
Summary
- 0 high, 0 medium, 0 low
- controls named on 93% of elements, 20 of 23 components and 23 of 23 flows
- sensitive flows with a named control: 2 of 2
- Framework coverage: 100% (6 / 6)
Findings
Nothing to flag
Framework coverage: IEC 62443
| Area | By controls | |
|---|---|---|
| SR 1 Identification and authentication control | yes | SR 1.1, SR 1.2 |
| SR 2 Use control and authorization enforcement | yes | SR 2.1 |
| SR 3 System integrity of the control path | yes | SR 3.1 |
| SR 5 Restricted data flow between zones | yes | SR 5.1, SR 5.2 |
| SR 6 Timely response to events | yes | SR 6.1, SR 6.2 |
| SR 7 Resource availability | yes | SR 7.1, SR 7.3 |
Zones
| Zone | Trust | Components |
|---|---|---|
| Public and partners | untrusted | Visitor phone, public app, Merchant portal user, Kuwait Fire Force dispatch |
| Exposed services | dmz | Web application firewall, Public API and open data |
| Operations center | management | Ops analyst, Operations dashboard, Ops access gateway, SOC monitoring |
| Data platform | restricted | MQTT broker, Time series store, Digital twin and asset registry, Device identity CA, Analytics and alerting |
| Local unit | restricted | Local firewall and conduit, Local unit, store and forward, LoRaWAN network server |
| Field sensing | secure | LoRaWAN gateways, Environmental and safety sensors, Anonymized footfall counters |
| OT and life safety | secure | OT conduit firewall, Lighting controller, Fire panel and PA |
Named controls and what they cover
| Control | Components | Flows |
|---|---|---|
| SR 1.1 | Public API and open data, Operations dashboard, Ops access gateway | opsuser → dash, merchant → waf |
| SR 1.2 | MQTT broker, Device identity CA, LoRaWAN network server, LoRaWAN gateways, Environmental and safety sensors | sensors → gateway, gateway → lns, lns → edgenode, pki → edgefw |
| SR 2.1 | Public API and open data, Operations dashboard, Digital twin and asset registry, Lighting controller | tsdb → twin, opsgw → dash, opsuser → dash, twin → api, edgenode → otfw, otfw → lighting |
| SR 3.1 | Local unit, store and forward, Environmental and safety sensors, Lighting controller, Fire panel and PA | otfw → lighting, otfw → firepanel |
| SR 4.1 | Time series store, LoRaWAN network server, Anonymized footfall counters | sensors → gateway, counters → gateway, gateway → lns, edgefw → broker, analytics → opsgw, twin → api, merchant → waf |
| SR 4.3 | Device identity CA | pki → edgefw |
| SR 5.1 | MQTT broker, Local firewall and conduit, OT conduit firewall | edgenode → edgefw, edgenode → otfw |
| SR 5.2 | Kuwait Fire Force dispatch, Web application firewall, Ops access gateway, Local firewall and conduit, OT conduit firewall | edgefw → broker, analytics → opsgw, waf → api, visitor → waf, api → kff |
| SR 6.1 | Analytics and alerting | broker → analytics, opsgw → dash, api → kff, firepanel → edgenode |
| SR 6.2 | SOC monitoring | opsgw → siem |
| SR 7.1 | Local unit, store and forward, Fire panel and PA | otfw → firepanel |
| SR 7.3 | Time series store | broker → tsdb |
What this report means
Naming a control on an element records where it belongs in the design. It is not evidence that the control is implemented. Framework coverage says the blueprint names a control for every area a drawing can show. It is a design check, not a certification, and implementation is a matter for testing and independent assessment.
Sign off
| Reviewer | Date | Decision |
|---|---|---|
| accepted / accepted with conditions / rejected |
Reviewer notes:
Generated by Hisn from the blueprint source. Part of an educational experience; no entity named is involved.
© 2026 Ali AlEnezi. All rights reserved. · Site@hotmail.com · 3li.info