CSA Official Press Release
CSA Launches New Security Guidance for Early Adopters of the IoT
Cross-Industry Guidance Highlights Key Challenges and Recommended IoT Security Controls. These controls have been tailored to IoT-specific characteristics to allow early adopters to mitigate many of the risks associated with this new technology. San Francisco, CA – April 20, 2015 – The Cloud Security Alliance (CSA) today unveiled a new guidance report titled, New Security Guidance for Early Adopters of the IoT, aimed at helping early adopters understand the security challenges surrounding the Internet of Things (IoT), and providing recommended security controls and sample use-cases for organizations implementing IoT capabilities. These controls have been tailored to IoT-specific characteristics to allow early adopters to mitigate many of the risks associated with this new technology. The IoT provides new and enhanced capabilities across diverse industries and enterprise functions, as well as unique security challenges associated with each market segment, use case and vendor community. However, sufficient research into the vulnerabilities associated with the IoT, and best practices for securely developing, deploying, trusting and maintaining IoT components has not yet been conducted.
“Traditional security mechanisms such as secure software development and security controls engineering, common vulnerability and exploit (CVE) discovery and reporting, vulnerability management, and field upgrade and patching do not exist or are immature in most of the industries taking advantage of IoT platforms,” said Luciano Santos, VP of Research and Member Services for the CSA. “Research is needed to allow organizations to design a trusted IoT ecosystem in their enterprise that securely utilizes the cloud for control and data connectivity. In the absence of this research, organizations will be forced to make substantial architectural decisions without sufficient data to understand the risks and identify appropriate mitigations.”
CSA is supporting the industry by decomposing the common devices types, markets and architectures of the IoT, and subsequently analyzing and recommending appropriate security mitigations across these commonalities. In future research in this area, CSA will associate each category with the appropriate cloud security standards, CCM controls, best practices and relevant governance. Research will help identify and document critical vulnerabilities associated with introduction of IoT in various enterprise environments and provide best practices for vulnerability mitigation. As part of its ongoing research, CSA will also provide developers with secure development guidance to ensure IoT components are designed securely from the start.
Recommended security controls detailed in the report include: * Analyze privacy impacts to stakeholders and adopt a privacy-by-design approach to IoT development and deployment. * Apply a Secure Systems Engineering approach to architecting and deploying a new IoT SoS. * Implement layered security protections to defend IoT assets. * Define life-cycle controls for IoT devices. * Define and implement an authentication/authorization framework for the organization’s IoT deployments. * Define and implement a logging/audit framework for the organization’s IoT ecosystem. * Develop safeguards to assure the availability of IoT-based systems and data. * Information sharing and support of a global approach to combating security threats by sharing threat information with security vendors, industry peers and Cloud Security Alliance.
The full report is freely available at https://downloads.cloudsecurityalliance.org/whitepapers/Security_Guidance_for_Early_Adopters_of_the_Internet_of_Things.pdf
About Cloud Security Alliance
The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.
ContactKari Walker for the CSA ZAG Communications 703.928.9996 [email protected]
About Cloud Security Alliance
The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.
For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.