. . . "That approach focuses on placement of intrusion detection and prevention systems within and between control networks and the business or other networks (e.g., zones 14, 16) with which those control network interface, e.g., at the site level and, more broadly, the enterprise level." . .