← Home

IEC 62443-3-1 Clause 8.7 – Automated Software Management Tools

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.7
Related: Clause 8 | IEC 62443-2-3 Patch Management | 4-1 Security Update Management | System Hardening

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management


What it is

Automated software management (ASM) inventories, distributes and verifies software and patches on hosts. It is the tooling layer; the process layer is IEC 62443-2-3 patch management.


Vulnerabilities addressed

Unknown software inventory, unpatched COTS, and inconsistent versions across a fleet of engineering stations and servers.


Typical deployment

Patch and software distribution servers aimed at Windows fleets, with test rings before production. Controllers and embedded devices are usually out of scope of IT ASM.


Known issues and weaknesses

The ASM tool itself adds attack surface (a compromised patch server is catastrophic). Unneeded updates can break vendor-supported systems. Production-first deployment is a common failure.


Use in IACS

Review closely as COTS grows on IACS networks. Define which updates are actually required before automating them.


Recommendations