← Home

IEC 62443-3-1 Clause 8.6 – Host Configuration Management Tools

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.6
Related: Clause 8 | System Hardening | 2-1 Clause 7 Configuration Management | 2-1 Clause 9 Component Security | Change Management

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management


What it is

Host configuration management (HCM) tools baseline, compare and enforce the configuration of servers and workstations (services, accounts, patches, hardening settings). They are how “gold image” policy is kept true over time.


Vulnerabilities addressed

Configuration drift, forgotten services, and undocumented local admin changes that reopen the attack surface after hardening.


Typical deployment

IT HCM suites (difference packages, desired-state tools) against Windows/Unix fleets. IACS use is limited by vendor images and by the risk of enforcing an IT baseline onto a control host.


Known issues and weaknesses

IT packs are not automatically safe on vendor-supported IACS images. Enforcement can break required services. Cost is only justified where administration and security policy are strong enough to use the output.


Use in IACS

The TR expected IT HCM to be ported as COTS increased. Operators should first decide which admin and security tasks would benefit, and write the policy, before buying a tool. Link System Hardening for the baseline content HCM would enforce.


Recommendations