Thank you for Subscribing to CIO Applications Weekly Brief

Areas Crucial for Ensuring IoT End-to-End Security
In the Internet of Things, connected devices frequently generate massive amounts and types of data that are used,
By
CIO Applications | Saturday, April 30, 2022

The risk profile of the IoT evolves over time, influenced by activities such as device addition and removal, changes in access policies, the discovery of new vulnerabilities, and device firmware and software updates.
Fremont, CA: In the Internet of Things, connected devices frequently generate massive amounts and types of data that are used, sent to, or stored in various areas of an organization's IT infrastructure. As a result, it has a cascading effect across the entire risk landscape, including third-party risk, cyber security, compliance, and business resiliency. IoT security is more than just "device management." Companies will most likely need to transform their security approach to effectively manage IoT risks, whether it is the additional need for identification, discovery, and classification of new endpoints, additional compliance checks, or authentication updates.
Here are the areas that are critical for IoT end-to-end security:
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Visibility Needed
Making sure that each individual endpoint can be discovered, identified, and classified is the first step in securing IoT deployments. Security teams must be able to determine which endpoints are present at an IP address and then detect specific information about the device, such as where it was manufactured, its model and serial number, and the firmware version it runs. This is possible with modern edge platforms such as the EdgeX Foundry, a Linux Foundation-hosted open-source project. By correlating this metadata with known vulnerability information, common misuse and misconfiguration scenarios, and operational strengths and weaknesses, security teams gain additional granularity for tracking and reporting, which should ultimately aid in risk mitigation.
Constant Assessment is Required for Risk Management
It is not enough to simply set up an IoT deployment and then forget about it; risk assessments must be performed on a continuous basis. The risk profile of the IoT evolves over time, influenced by activities such as device addition and removal, changes in access policies, the discovery of new vulnerabilities, and device firmware and software updates. If IoT data must be shared between the enterprise and external service providers, third-party risks may arise. Furthermore, as digital transformation accelerates and IoT technology matures, there will be an increasing number of regulations and guidelines that businesses must monitor and follow. Finally, consider how the results of a risk assessment affect other actions taken – for instance, if the assessment reveals a sensitive or high-risk asset, how should this affect the asset's maintenance, update, as well as authentication policies.
More in News

