Host-Based Security System
HBSS is the name the U.S. Department of Defense gave to a bundle of commercial security software that was deployed on individual computers and servers across DoD networks. It was designed to watch for, detect, and respond to threats at the level of each host system. The suite was built around commercial-off-the-shelf products rather than being custom-developed by the DoD.
HBSS is a Department of Defense program name for a suite of commercial-off-the-shelf (COTS) host-level security applications mandated for use across DoD Enterprise Network systems. According to the evidence, it was based on McAfee's ePolicy Orchestrator (ePO) management framework together with point products such as the Host Intrusion Prevention System (HIPS), and it provided capabilities to monitor, detect, and counter threats on individual hosts. As a host-based defense approach it generally combined functions such as intrusion prevention with centralized policy management. Note: the evidence does not establish the specific deployment timeline, current status, or successor programs; readers should verify against current DoD and DISA authoritative sources, as endpoint security programs and DoD directives change over time.
Why it matters
HBSS represented one of the Department of Defense's large-scale efforts to standardize host-level security across its enterprise network by mandating a common suite of commercial-off-the-shelf tools rather than allowing individual commands and components to field disparate, uncoordinated endpoint defenses. For compliance officers and information system security managers operating within DoD environments, HBSS matters because it illustrates a central principle of DoD endpoint security: centralized policy management combined with host-level detection and prevention capabilities that can be enforced uniformly across many systems. Where HBSS was mandated, its deployment and configuration typically became part of the security control implementation evidence that authorizing officials and assessors reviewed.
Understanding HBSS is also important for reading legacy documentation, older System Security Plans, and prior authorization packages that reference the program by name. Because HBSS was built around McAfee's ePolicy Orchestrator framework and associated point products such as the Host Intrusion Prevention System, references to these components in DoD artifacts are best understood as parts of a DoD program rather than as independent, ad hoc tool choices. Practitioners inheriting or reviewing older systems may encounter HBSS terminology and need to map it to the host-based protection controls their current baseline requires.
A critical caution: the evidence digest here does not establish HBSS's current status, deployment timeline, or any successor programs, and DoD endpoint security programs and directives change over time. Readers should not assume that a system described as running HBSS reflects the current DoD-mandated toolset, nor should they treat the presence of HBSS as evidence of an active, valid authorization. Compliance is time-bound and tied to continuous monitoring, and endpoint security mandates evolve; the authoritative current requirements must be verified against present-day DoD and DISA sources rather than inferred from the HBSS program name.
Who it's relevant to
Inside HBSS
Common questions
Answers to the questions practitioners most commonly ask about HBSS.