Glossary · OT cybersecurity
System hardening
Also known as: Host hardening, OS hardening
German: Systemhärtung
In cybersecurity, system hardening is the application of hardening measures to a complete system, such as an industrial PC with its operating system, runtime and applications or an entire control system, by removing unneeded software and services, restricting interfaces and accounts and enforcing secure configuration settings.
- OT security
In one sentence
System hardening secures a complete system, such as an industrial PC or control system, by removing unneeded software and enforcing secure settings.
Example
The SCADA server is hardened according to the vendor's guide: unused Windows roles removed, USB storage blocked, application allowlisting enabled and remote desktop restricted to the jump server.
How it applies
- Engineering: System hardening combines operating system settings, service and port reduction, account and password policies, removable media control, Application allowlisting and secure configuration of the automation software. Vendor guidelines and published security baselines are good starting points, but must be checked against the automation vendor's support statements.
- Commissioning: Hardening is applied and verified before handover and recorded as part of the Configuration baseline.
- Maintenance: Updates, new software and service work can undo hardening. Periodic checks against the baseline detect drift.
- Documentation: A system hardening guide lists each measure, its purpose and its effect on functions, and says which settings the automation software requires (for example specific services or ports). Integrators need this to harden without breaking the system.
System hardening vs. hardening
Hardening is the general practice applied to any single element, such as a switch or a PLC. System hardening addresses a whole system and the interplay of its parts.