Skip to main content
Category: Configuration & Endpoint Security

Host-Based Security System

Also known as: HBSS, Host Based Security System
Simply put

HBSS is the name the U.S. Department of Defense gave to a bundle of commercial security software that was deployed on individual computers and servers across DoD networks. It was designed to watch for, detect, and respond to threats at the level of each host system. The suite was built around commercial-off-the-shelf products rather than being custom-developed by the DoD.

Formal definition

HBSS is a Department of Defense program name for a suite of commercial-off-the-shelf (COTS) host-level security applications mandated for use across DoD Enterprise Network systems. According to the evidence, it was based on McAfee's ePolicy Orchestrator (ePO) management framework together with point products such as the Host Intrusion Prevention System (HIPS), and it provided capabilities to monitor, detect, and counter threats on individual hosts. As a host-based defense approach it generally combined functions such as intrusion prevention with centralized policy management. Note: the evidence does not establish the specific deployment timeline, current status, or successor programs; readers should verify against current DoD and DISA authoritative sources, as endpoint security programs and DoD directives change over time.

Why it matters

HBSS represented one of the Department of Defense's large-scale efforts to standardize host-level security across its enterprise network by mandating a common suite of commercial-off-the-shelf tools rather than allowing individual commands and components to field disparate, uncoordinated endpoint defenses. For compliance officers and information system security managers operating within DoD environments, HBSS matters because it illustrates a central principle of DoD endpoint security: centralized policy management combined with host-level detection and prevention capabilities that can be enforced uniformly across many systems. Where HBSS was mandated, its deployment and configuration typically became part of the security control implementation evidence that authorizing officials and assessors reviewed.

Understanding HBSS is also important for reading legacy documentation, older System Security Plans, and prior authorization packages that reference the program by name. Because HBSS was built around McAfee's ePolicy Orchestrator framework and associated point products such as the Host Intrusion Prevention System, references to these components in DoD artifacts are best understood as parts of a DoD program rather than as independent, ad hoc tool choices. Practitioners inheriting or reviewing older systems may encounter HBSS terminology and need to map it to the host-based protection controls their current baseline requires.

A critical caution: the evidence digest here does not establish HBSS's current status, deployment timeline, or any successor programs, and DoD endpoint security programs and directives change over time. Readers should not assume that a system described as running HBSS reflects the current DoD-mandated toolset, nor should they treat the presence of HBSS as evidence of an active, valid authorization. Compliance is time-bound and tied to continuous monitoring, and endpoint security mandates evolve; the authoritative current requirements must be verified against present-day DoD and DISA sources rather than inferred from the HBSS program name.

Who it's relevant to

DoD Information System Security Managers (ISSMs) and ISSOs
Security personnel responsible for DoD systems may encounter HBSS references in existing System Security Plans, configuration baselines, and authorization artifacts. Understanding that HBSS was a mandated COTS suite built on ePolicy Orchestrator helps them interpret legacy documentation and map host-based protection functions to their current control requirements. They should verify against present DoD and DISA guidance whether HBSS-era tooling remains the mandated standard.
Authorizing Officials and Assessors
Officials making risk determinations and assessors evaluating control implementation may see HBSS cited as evidence of host-level intrusion prevention and centralized policy management. They should treat such references as historical program terminology, confirm what tooling is actually deployed and currently required, and remember that the presence of any endpoint suite does not by itself constitute a valid, time-bound authorization or ongoing continuous monitoring.
DoD Contractors and System Administrators
Administrators supporting DoD Enterprise Network systems and contractors inheriting older environments may need to operate, migrate from, or document HBSS components. Because HBSS was a DoD-specific program name applied to commercial products, they should confirm the exact modules, policies, and any successor toolsets applicable to their systems through current DoD and DISA authoritative sources rather than relying on the program name alone.

Inside HBSS

ePolicy Orchestrator (ePO)
The centralized management console historically used to deploy, configure, and monitor HBSS point products across enrolled endpoints. It generally serves as the administrative hub for policy distribution and reporting, though specific product naming and vendor branding have changed over time and should be verified against current DoD baselines.
Host Intrusion Prevention System (HIPS)
A component intended to detect and block malicious or anomalous activity at the host level. In most implementations it provides signature-based and behavioral protections, but its effectiveness depends on tuning and current policy configuration.
Endpoint Anti-Malware / Antivirus Modules
Point products that provide malware detection and remediation on individual hosts. These modules generally require current definitions and coordinated policy management through the central console.
Policy Auditor and Compliance Reporting
Functionality used to assess host configuration against defined policy and to generate compliance and status reporting for administrators and assessors. Reporting supports, but does not by itself constitute, continuous monitoring.
Device and Data Protection Controls
Modules addressing controls such as removable media and host firewall functions. The specific set of enabled modules typically varies by organizational tailoring and applicable baseline.
Managed Agent Framework
Agents installed on enrolled endpoints that communicate with the central console to receive policy and report status. The agent-to-console architecture is central to how HBSS enforces and monitors host-level protections.

Common questions

Answers to the questions practitioners most commonly ask about HBSS.

Is HBSS still the current DoD endpoint security standard?
Not in the way it once was. HBSS was the DoD's mandated host-based endpoint security suite for a number of years, but the department has been transitioning to newer endpoint security capabilities. Treating HBSS as the perpetual, current standard is a common mistake; readers should verify the presently mandated endpoint security solution and configuration requirements against current DoD CIO and DISA guidance rather than assuming HBSS remains the required baseline.
Does deploying HBSS by itself make a system compliant?
No. Deploying HBSS is not equivalent to achieving compliance or security. HBSS is a set of host-based tools that can help satisfy portions of applicable control requirements, but compliance depends on how the tools are configured, monitored, maintained, and documented, as well as on many other controls outside HBSS's scope. Conflating the presence of a security product with compliance, or with security, is an error experts routinely correct.
What types of security functions does HBSS generally provide?
HBSS was designed as a suite of host-based security capabilities intended to support functions such as endpoint protection, host intrusion prevention, and policy enforcement on individual systems, managed through a central console. The exact modules and capabilities depend on the version and configuration deployed. Consult current authoritative documentation for the specific components and functions applicable to your environment.
How does HBSS relate to the controls a DoD system must satisfy under the RMF?
HBSS can help support implementation of certain host-based technical controls that a DoD system addresses under the Risk Management Framework, but it does not by itself satisfy the full control baseline. Which specific controls a given HBSS configuration supports depends on tailoring, the system's impact level, and organizational implementation decisions. Map any HBSS capabilities to the applicable controls in your System Security Plan and verify the mapping against current authoritative guidance.
Who is responsible for maintaining and monitoring an HBSS deployment?
Responsibility generally rests with the organization operating the system, including roles such as system administrators and the Information System Security Manager, under the oversight of the responsible authorizing official. Maintenance typically includes keeping components updated, sustaining policy configurations, and continuously monitoring the tools' output. Specific responsibilities and division of duties should be confirmed against your organization's policies and current DoD guidance.
How should HBSS-related evidence be handled during an assessment or authorization?
Assessors generally expect to see documentation and artifacts demonstrating that host-based capabilities are configured, operating, and monitored as intended, rather than merely that a product is installed. Because assessment is distinct from authorization, evidence supports the assessor's evaluation of control effectiveness, which in turn informs the authorizing official's risk decision. Confirm the required artifacts and their format against the applicable assessment procedures and current authoritative sources.

Common misconceptions

HBSS is a single antivirus product.
HBSS generally refers to a suite of centrally managed host-level security capabilities, such as intrusion prevention, anti-malware, policy auditing, and device controls, managed through a central console, rather than a single point product. The exact composition depends on the deployed baseline and organizational tailoring, which should be verified against current DoD guidance.
Deploying HBSS makes a system compliant or secure.
Compliance and security are not equivalent, and deploying a tool does not by itself satisfy either. HBSS supports specific control objectives, but it must be properly configured, monitored, and assessed within the system's overall authorization and continuous monitoring program. Reporting from HBSS informs, but does not replace, assessment and authorization activities.
HBSS terminology and product names are fixed and current.
The tooling, vendor branding, and DoD enterprise host security approach have evolved over time, and terminology may differ from newer endpoint security initiatives. Practitioners should confirm the current authoritative naming, mandated products, and applicable baseline against official DoD sources rather than assuming historical terms remain in effect.

Best practices

Confirm the currently mandated host security tooling, module set, and baseline against official DoD guidance before assuming HBSS terminology or products still apply, since the enterprise approach has evolved over time.
Manage host protections centrally through the management console and enforce consistent, tailored policies across all enrolled endpoints rather than relying on per-host configuration.
Tune HIPS and anti-malware policies to the operational environment to reduce false positives while maintaining protection, and revisit tuning as conditions change.
Use HBSS compliance and status reporting to feed the system's continuous monitoring program rather than treating a report as evidence of authorization or assessment completion.
Verify that agents are deployed, communicating, and reporting on all in-scope hosts, and investigate endpoints that are unmanaged or out of contact with the console.
Coordinate HBSS-supported controls with the system's overall control implementation and authorization documentation so that tool coverage maps clearly to the applicable control objectives.