IoT Device Security
IoT device security is the design, configuration, and lifecycle work that keeps connected devices and their data under intended control. It covers identity, access, software updates, data protection, monitoring, and retirement.
itComputer architecture and hardware | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
IoT Device Security
An IoT device is part of a larger product and system. It has hardware and software, but it also has local interfaces, network services, an update path, a management service, users, and an owner. Security has to hold across those connections. A secure device is not a device with one security feature switched on.
NIST's IoT device cybersecurity capability core baseline gives you a useful starting map. It groups device capabilities into identification, configuration, data protection, logical access to interfaces, software update, cybersecurity state awareness, and device security. The baseline is a starting point, not a universal checklist. Your device's function, deployment, users, physical access, and consequences of failure decide what the profile must add.
Start with the product boundary
List the device, its firmware, its boot process, every local and network interface, the mobile or web application, cloud services, installers, operators, and support staff. Then list the assets that matter: credentials, cryptographic keys, device configuration, firmware images, commands, telemetry, and personal or operational data.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/ir/8259/a/final
Supports
- NIST IoT device cybersecurity capability core baseline and its seven technical capabilities
- Device identification, configuration, data protection, logical interface access, software update, state awareness, and device security claims
- https://www.nist.gov/itl/applied-cybersecurity/nist-cybersecurity-iot-program/nistir-8259-series
Supports
- Core baselines as a starting point requiring tailoring through profiles or extensions
- Relationship of NISTIR 8259 series publications
- https://csrc.nist.gov/pubs/ir/8259/r1/final
Supports
- Manufacturer cybersecurity activities before IoT products are sold to customers
- Product lifecycle support information and customer securability
- https://pages.nist.gov/IoT-Device-Cybersecurity-Requirement-Catalogs/
Supports
- NIST technical capability catalog and manufacturer supporting capability categories
- https://www.nist.gov/itl/applied-cybersecurity/nist-cybersecurity-iot-program/faqs
Supports
- Cybersecurity state awareness for monitoring, investigation, and troubleshooting
- https://www.etsi.org/deliver/etsi_en/303600_303699/303645/03.01.02_20/en_303645v030102a.pdf
Supports
- Consumer IoT provisions for unique or user-defined passwords, vulnerability handling, updates, sensitive parameters, communication, attack surface, and software integrity
- https://nmap.org/nsedoc/scripts/ssl-enum-ciphers.html
Supports
- Nmap ssl-enum-ciphers script enumerating supported SSL and TLS cipher suites
- https://github.com/fkie-cad/awesome-embedded-and-iot-security
Supports
- Curated discovery of embedded and IoT security resources
- https://github.com/OWASP/IoTGoat
Supports
- OWASP IoTGoat as deliberately insecure firmware for authorized security education
