Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.7
Related:
Clause 8
|
IEC 62443-2-3 Patch Management
|
4-1 Security Update Management
|
System Hardening
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management
Automated software management (ASM) inventories, distributes and verifies software and patches on hosts. It is the tooling layer; the process layer is IEC 62443-2-3 patch management.
Unknown software inventory, unpatched COTS, and inconsistent versions across a fleet of engineering stations and servers.
Patch and software distribution servers aimed at Windows fleets, with test rings before production. Controllers and embedded devices are usually out of scope of IT ASM.
The ASM tool itself adds attack surface (a compromised patch server is catastrophic). Unneeded updates can break vendor-supported systems. Production-first deployment is a common failure.
Review closely as COTS grows on IACS networks. Define which updates are actually required before automating them.