Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.6
Related:
Clause 8
|
System Hardening
|
2-1 Clause 7 Configuration Management
|
2-1 Clause 9 Component Security
|
Change Management
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management
Host configuration management (HCM) tools baseline, compare and enforce the configuration of servers and workstations (services, accounts, patches, hardening settings). They are how “gold image” policy is kept true over time.
Configuration drift, forgotten services, and undocumented local admin changes that reopen the attack surface after hardening.
IT HCM suites (difference packages, desired-state tools) against Windows/Unix fleets. IACS use is limited by vendor images and by the risk of enforcing an IT baseline onto a control host.
IT packs are not automatically safe on vendor-supported IACS images. Enforcement can break required services. Cost is only justified where administration and security policy are strong enough to use the output.
The TR expected IT HCM to be ported as COTS increased. Operators should first decide which admin and security tasks would benefit, and write the policy, before buying a tool. Link System Hardening for the baseline content HCM would enforce.