The potential benefits of new guidance and technologies that have emerged should be considered by all users. Documents such as Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations Revision 1 (SP 800-161r1), Guide to Industrial Control Systems (ICS) Security Revision 3 (SP 800-82r3), the Secure Software Development Framework (SSDF) and the Risk Management Framework, and documents such as NISTIRs 8259/A/B and SPs 800-213/A can offer different perspectives that help inform the discussion of assessing and mitigating risk when IoT devices and systems are part of the equation. NIST's "Cybersecurity for IoT Program" will be hosting an event on June 22, 2022, to discuss the IoT landscape and the team’s next steps.
Devices with constraints may often, but not always, face different, possibly lower risk than other equipment. NIST heard that these challenges are compounded when IoT systems are assembled from many constrained devices (e.g., a distributed sensor network), possibly creating a larger scale break of expectations about the cybersecurity capabilities of the system and its components. Additionally, IoT devices and systems of constrained or highly distributed architectures may face challenges implementing common technical (e.g., cybersecurity state awareness) and non-technical (e.g., documentation) cybersecurity measures. NISTIR 8228 considers some of these aspects, but stakeholders may benefit from more specific considerations based on what NIST has learned.
Link to NIST Program
https://www.nist.gov/itl/applied-cybersecurity/nist-cybersecurity-iot-program
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |