Cloud 101CircleEventsBlog
Master CSA’s Security, Trust, Assurance, and Risk program—download the STAR Prep Kit for essential tools to enhance your assurance!

Download Publication

New Security Guidance for Early Adopters of the IoT
New Security Guidance for Early Adopters of the IoT

New Security Guidance for Early Adopters of the IoT

Release Date: 04/20/2015

Working Group: Internet of Things

For the latest research on IoT security from CSA, please check out the IoT Working Group and their IoT Security Controls Framework.

The marketplace is seeing the beginning of widespread adoption of the Internet of Things (IoT) within the consumer sector. Wearables, smart home appliances, lighting, and other IoT devices are becoming mainstream. This surge of smart consumer devices is anticipated to continue to grow at a frenzied pace well into the future. 

As traditional enterprise security solutions do not sufficiently address the security needs of IoT, this document provides guidance for the secure implementation of IoT-based systems. This document was created using input from a number of security and mobility experts representing diverse industries. References and information from existing guidance in the field are incorporated into this paper whenever possible in order to promote alignment with the work of other industry bodies.

Key Takeaways:
  • Challenges posed by IoT, including: increased privacy concerns, platform security limitations, and ubiquitous mobility that hinders tracking and asset management
  • Examples of IoT threats and attack vectors to both individuals and organizations
  • Top challenges for organizations trying to secure IoT systems
Who It’s For: Anyone involved in the implementation of IoT-based systems
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
View translations
Related resources
Map the Transaction Flows for Zero Trust
Map the Transaction Flows for Zero Trust
AI Risk Management: Thinking Beyond Regulatory Boundaries
AI Risk Management: Thinking Beyond Regulatory ...
AI Organizational Responsibilities - Governance, Risk Management, Compliance and Cultural Aspects
AI Organizational Responsibilities - Governance...
A Vulnerability Management Crisis: The Issues with CVE
A Vulnerability Management Crisis: The Issues with CVE
Published: 11/21/2024
The Hidden Power of Zero Trust Thinking
The Hidden Power of Zero Trust Thinking
Published: 10/30/2024
How CSA Research Uses the Cloud Controls Matrix to Address Diverse Security Challenges
How CSA Research Uses the Cloud Controls Matrix to Address Diverse ...
Published: 10/25/2024
Reflections on NIST Symposium in September 2024, Part 2
Reflections on NIST Symposium in September 2024, Part 2
Published: 10/10/2024

Acknowledgements

Srinivas Tatipamula
Srinivas Tatipamula
Principal Security Advisor, Fairfax

Srinivas Tatipamula

Principal Security Advisor, Fairfax

C-CISO|CISSP|CISA|AWS CSS|AWS CSA|CDPSE|CISM|CGEIT|CRISC|ISO 27000LA|CCSK|ITIL-F|PMP|Bachelor of Economics (Hons)|Bachelor of Law| MS in Digital Forensics

Overall 30 plus years in IT and over 18 years in Cyber Security

Publications:

1. Cloud Security Alliance Internet of Things (IoT) Working Group IoT Security Controls Guide Version Published March 2019

2. CSA IoT Controls Matrix March 2019

3. ...

Read more

John Yeoh
John Yeoh
Global Vice President of Research, CSA

John Yeoh

Global Vice President of Research, CSA

With over 15 years of experience in research and technology, John excels at executive-level leadership, relationship management, and strategy development. He is a published author, technologist, and researcher with areas of expertise in cybersecurity, cloud computing, information security, and next generation technology (IoT, Big Data, SecaaS, Quantum). John specializes in risk management, third party assessment, GRC, data protection, incid...

Read more

Brian Russell
Brian Russell

Brian Russell

Brian Russell is co-author of the book “Practical Internet of Things Security” and is a Chief Engineer focused on Cyber Security Solutions for Leidos (www.leidos.com). He oversees the design and development of security solutions and the implementation of privacy and trust controls for customers. Brian leads efforts that include security engineering for Unmanned Aerial Systems (UAS) and Connected Cars, and the development of hig...

Read more

​Aaron Guzman
​Aaron Guzman

​Aaron Guzman

Aaron is a passionate information security professional specializing in IoT, embedded, and automotive security. He is co-author of the “IoT Penetration Testing Cookbook” and a technical editor for the "Practical Internet of Things Security” Packt Publishing books. Aaron is co-chair of CSA’s IoT working group as well as a leader for OWASP’s IoT and Embedded Application Security projects; providing practical guidance to address the most commo...

Read more

Srinivas Tatipamula
Srinivas Tatipamula
Principal Security Advisor, Fairfax

Srinivas Tatipamula

Principal Security Advisor, Fairfax

C-CISO|CISSP|CISA|AWS CSS|AWS CSA|CDPSE|CISM|CGEIT|CRISC|ISO 27000LA|CCSK|ITIL-F|PMP|Bachelor of Economics (Hons)|Bachelor of Law| MS in Digital Forensics

Overall 30 plus years in IT and over 18 years in Cyber Security

Publications:

1. Cloud Security Alliance Internet of Things (IoT) Working Group IoT Security Controls Guide Version Published March 2019

2. CSA IoT Controls Matrix March 2019

3. ...

Read more

Jean Pawluk Headshot Missing
Jean Pawluk

Jean Pawluk

David Lingenfelter
David Lingenfelter
Security and Compliance, MaaS360

David Lingenfelter

Security and Compliance, MaaS360

David is a seasoned security professional with nearly 20 years of experience in risk management, information security, compliance, and policy development. Throughout his career David has performed risk and vulnerability assessments along with making recommendations on network and system design improvements. David’s career has spanned from traditional hardware based security architectures to cloud technologies and virtual environments.

Read more

Michele Drgon Headshot Missing
Michele Drgon

Michele Drgon

K S Abhiraj Headshot Missing
K S Abhiraj

K S Abhiraj

Drew Van Duren Headshot Missing
Drew Van Duren

Drew Van Duren

Valmiki Mukherjee Headshot Missing
Valmiki Mukherjee

Valmiki Mukherjee

Eiji Sasahara
Eiji Sasahara
Board of Director at CSA Japan Chapter

Eiji Sasahara

Board of Director at CSA Japan Chapter

Cesare Garlati
Cesare Garlati
Chief Security Strategist at prpl Foundation

Cesare Garlati

Chief Security Strategist at prpl Foundation

Cesare Garlati is an internationally renowned leader in information security. Former Vice President of mobile security at Trend Micro, Cesare currently serves as Chief Security Strategist at prpl Foundation and Co-chair of the Mobile Working GroupCloud Security Alliance. Prior to Trend Micro, Mr. Garlati held director positions within leading mobility companies such as iPass, Smith Micro Software and W...

Read more

Girish Bhat Headshot Missing
Girish Bhat

Girish Bhat

Guido Sanchidrian Headshot Missing
Guido Sanchidrian

Guido Sanchidrian

Larry Hughes Headshot Missing
Larry Hughes

Larry Hughes

Robert de Monts Headshot Missing
Robert de Monts

Robert de Monts

Tim Owen
Tim Owen
Chief Engineer and Director of Advanced Programs, Secure Missions Solutions

Tim Owen

Chief Engineer and Director of Advanced Programs, Secure Missions Solutions

Tim Owen, Chief Engineer and Director of Advanced Programs for Secure Missions Solutions, a Parsons Company, has spent 30 years developing, implementing, operating, and assuring complex, high-performance networking and computing environments. Hespent the last 14 years supporting some of the highest value components of the US Federal government enterprise designing and deploying next generation protoco...

Read more

Nader Henein Headshot Missing
Nader Henein

Nader Henein

Arlene Mordeno Headshot Missing
Arlene Mordeno

Arlene Mordeno

Tom Donahoe Headshot Missing
Tom Donahoe

Tom Donahoe

Megan Bell Headshot Missing
Megan Bell

Megan Bell

James Hunter Headshot Missing
James Hunter

James Hunter

Mats Naslund Headshot Missing
Mats Naslund

Mats Naslund

Chinmoy Rajpal Headshot Missing
Chinmoy Rajpal

Chinmoy Rajpal

Jarrod Stenberg Headshot Missing
Jarrod Stenberg

Jarrod Stenberg

Gene Anderson Headshot Missing
Gene Anderson

Gene Anderson

Kyle Boyce Headshot Missing
Kyle Boyce

Kyle Boyce

Poonlarb Chatchawalkhosit Headshot Missing
Poonlarb Chatchawalkhosit

Poonlarb Chatchawalkhosit

Michael Cook Headshot Missing
Michael Cook

Michael Cook

Chris Drake Headshot Missing
Chris Drake

Chris Drake

Gregory Johnson Headshot Missing
Gregory Johnson

Gregory Johnson

Alberto Manfredi
Alberto Manfredi
President and Country Leader, CSA Italy

Alberto Manfredi

President and Country Leader, CSA Italy

MSc in Computer Science and Master of Science in Computer Science from the University of Milan with the highest marks and honors, he has been working in the Information Technology market for over 30 years, of which more than 20 in the field of Cyber and Information Security. Since 2002 he has been working at Leonardo SpA, where in recent years he has held the role of Divisional CISO and Senior Advisor in the Corporate Security function and ...

Read more

Javier Nieto Headshot Missing
Javier Nieto

Javier Nieto

Aniket Rastogi Headshot Missing
Aniket Rastogi

Aniket Rastogi

Shankar Subramaniyan Headshot Missing
Shankar Subramaniyan

Shankar Subramaniyan

Thriveni T K Headshot Missing
Thriveni T K

Thriveni T K

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training