AVEVA PI System - Purdue Model Architecture

aws · network diagram.

About This Architecture

Five-layer AVEVA PI System architecture implements the ISA-95 Purdue Model for secure OT/IT convergence in industrial environments. Field devices (PLCs, sensors, actuators) at Level 0-1 feed SCADA and HMI systems at Level 2, which connect through PI Interface Nodes and protocol connectors (OPC UA, Modbus, MQTT) to the core PI Data Archive Collective in a DMZ at Level 3.5. Enterprise systems (Power BI, Data Lake, ERP, MES) at Level 4 access historian data through load-balanced PI Vision and PI Web API servers, with dual firewalls enforcing security boundaries between process, OT, and IT networks. This reference architecture demonstrates defense-in-depth for critical infrastructure, ensuring operational data flows securely from shop floor to boardroom while maintaining network segmentation and high availability through collective members and buffer subsystems. Fork this diagram on Diagrams.so to customize for your plant's specific SCADA vendors, protocol mix, or cloud integration requirements (AWS, Azure). Download as .drawio, .svg, or .png for compliance documentation, or embed in your ICS security policies and digital transformation roadmaps.

People also ask

How do you architect AVEVA PI System following the Purdue Model for secure OT/IT integration in industrial plants?

Implement five layers: Level 0-1 field devices (PLCs, sensors) → Level 2 SCADA/HMI → Level 3 PI Interface Nodes with protocol connectors → Level 3.5 PI Data Archive Collective in DMZ → Level 4 enterprise systems (Power BI, ERP, MES). Use dual firewalls between OT and IT networks, PI Buffer Subsystem for resilience, and load-balanced PI Vision/Web API for secure data access.

AVEVA PI System - Purdue Model Architecture

AWSadvancedAVEVA PI SystemPurdue ModelOT/IT IntegrationIndustrial IoTSCADAISA-95
Domain: Data EngineeringAudience: industrial IoT architects and OT/IT integration engineers implementing Purdue Model architectures
1 views0 favoritesPublic

Created by

February 15, 2026

Updated

March 24, 2026 at 3:23 AM

Type

network

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI