Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 9.1
Related:
Clause 9
|
System Hardening
|
8.6 Host configuration management
|
4-2 Host device requirements
|
2-1 COMP
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 9 pages: Cl. 9 | 9.1 Server/workstation OS | 9.2 Real-time/embedded OS | 9.3 Web technologies
Windows- and Unix-class operating systems used as HMI, historian, engineering workstation, domain or application servers. They bring COTS convenience and COTS vulnerabilities.
Unnecessary services, default accounts and an unhardened OS image are the usual entry points onto plant servers. OS security is the base for almost every other control in Clauses 5–8.
Vendor-supported images on dedicated hosts, ideally not used for general office work or internet browsing. See System Hardening for the longer baseline (services, accounts, patches, USB, shares).
Guidance is highly dependent on the product and environment. Vendor support may forbid standard IT hardening. Shared operator accounts and leftover default passwords remain common.
Treat OS hardening as mandatory on every configurable host, then add compensating zone controls where the vendor image cannot be changed.
Two general directives from the TR, kept explicit: