← Home

IEC 62443-3-1 Clause 9.1 – Server and Workstation Operating Systems

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 9.1
Related: Clause 9 | System Hardening | 8.6 Host configuration management | 4-2 Host device requirements | 2-1 COMP

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 9 pages: Cl. 9 | 9.1 Server/workstation OS | 9.2 Real-time/embedded OS | 9.3 Web technologies


What it is

Windows- and Unix-class operating systems used as HMI, historian, engineering workstation, domain or application servers. They bring COTS convenience and COTS vulnerabilities.


Vulnerabilities addressed

Unnecessary services, default accounts and an unhardened OS image are the usual entry points onto plant servers. OS security is the base for almost every other control in Clauses 5–8.


Typical deployment

Vendor-supported images on dedicated hosts, ideally not used for general office work or internet browsing. See System Hardening for the longer baseline (services, accounts, patches, USB, shares).


Known issues and weaknesses

Guidance is highly dependent on the product and environment. Vendor support may forbid standard IT hardening. Shared operator accounts and leftover default passwords remain common.


Use in IACS

Treat OS hardening as mandatory on every configurable host, then add compensating zone controls where the vendor image cannot be changed.


Recommendations

Two general directives from the TR, kept explicit: