{"id":3287,"date":"2022-03-14T13:58:16","date_gmt":"2022-03-14T13:58:16","guid":{"rendered":"https:\/\/itegriti.com\/kw022024\/?p=3287"},"modified":"2022-09-12T14:34:59","modified_gmt":"2022-09-12T14:34:59","slug":"nist-published-the-final-iot-specific-guidance","status":"publish","type":"post","link":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/","title":{"rendered":"NIST Published the Final IoT-specific Guidance"},"content":{"rendered":"<div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last\" style=\"--awb-bg-size:cover;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-1\" style=\"--awb-text-transform:none;\"><p>NIST has released <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2021\/11\/nist-updates-iot-cybersecurity-guidance-and-accompanying-catalog\" target=\"_blank\" rel=\"noopener\">final IoT-specific guidance to federal organizations<\/a> to support extending their risk management process to the inclusion of IoT devices in federal systems. This guidance enables understanding and definition of IoT device cybersecurity requirements (NIST SP 800-213) using an accompanying catalog (NIST SP 800-213A). The guidance is pursuant to the <a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/house-bill\/1668\/text\" target=\"_blank\" rel=\"noopener\">IoT Cybersecurity Act of 2020<\/a> that requires NIST to provide a framework for the appropriate use and management of IoT devices connected to federal information systems.<\/p>\n<h2>The need for IoT security guidance<\/h2>\n<p>As the Internet of Things (IoT) technology evolves, most organizations will inevitably integrate this equipment into systems. IoT technology creates many opportunities for organizations in support of mission objectives. However, IoT technology may also present security challenges throughout the lifecycle if proper considerations are not made during the acquisition and integration of an IoT device.<\/p>\n<p>Existing NIST risk management guidance, such as <a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-53\/rev-5\/final\" target=\"_blank\" rel=\"noopener\">Special Publication (SP) 800-53 Rev. 5<\/a>, helps organizations identify, communicate, and satisfy the security requirements to support business objectives and manage risk across the organization &#8211; from the system level to the organizational level. However, the increasing scale, heterogeneity, and pace of IoT deployment requires organizations to focus on security below the information system level, at the system element level. A system element is a discrete part of a system such as a device, equipment, or application that is connected to other system elements and works with them to achieve the system\u2019s goals.<\/p>\n<p>IoT devices used by organizations are frequently integrated as system elements, while this integration often happens well after the information system has been initially deployed. It is therefore important that organizations identify support for system and organizational security capabilities needed from IoT devices to help manage risk to the system to which they connect.<\/p>\n<p>Organizations must also address the challenge that many IoT devices lack features and functions that are common in conventional IT equipment. This lack of functionality in IoT devices can cause further security concerns. For example, an IoT device may lack the capability to update software.<\/p>\n<h2>Purpose of NIST SP 800-213<\/h2>\n<p><a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-213\/final\" target=\"_blank\" rel=\"noopener\">NIST SP 800-213<\/a> is intended to help organizations incorporate IoT devices into an existing information system as system elements. The IoT devices covered by this publication have at least one transducer (sensor or actuator) for interacting directly with the physical world and at least one network interface for interfacing with the digital world. The IoT devices can function on their own, although they may be dependent on other specific devices (e.g., an IoT hub) or systems (e.g., a cloud) for some functionality.<\/p>\n<h2>How to identify cybersecurity requirements for IoT devices<\/h2>\n<p>NIST\u2019s publication provides comprehensive guidance to organizations in determining the applicable device cybersecurity requirements \u2013 both cybersecurity capabilities and non-technical supporting capabilities &#8211; for an IoT device. The guidance is illustrated in the diagram below, courtesy of NIST.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-3289 lazyload\" data-src=\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-guidance.jpg\" alt=\"\" width=\"800\" height=\"369\" data-srcset=\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-guidance-200x92.jpg 200w, https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-guidance-400x185.jpg 400w, https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-guidance-600x277.jpg 600w, https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-guidance-768x354.jpg 768w, https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-guidance.jpg 800w\" data-sizes=\"(max-width: 800px) 100vw, 800px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 800px; --smush-placeholder-aspect-ratio: 800\/369;\" \/><\/p>\n<p>The first step is to contemplate the IoT device\u2019s use case and gain a foundational understanding of how the IoT device might impact risk to the system. The second step is about understanding how the IoT device and its use case can impact the system\u2019s risk assessment and the subsequent allocation of security controls to the information system. Finally, the third step is to determine the applicable device cybersecurity requirements based on the risk assessment and controls allocation from the second step.<\/p>\n<h2>Purpose of NIST SP 800-213A<\/h2>\n<p>The purpose of <a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-213a\/final\" target=\"_blank\" rel=\"noopener\">NIST SP 800-213A<\/a> is to help federal organizations determine device cybersecurity requirements for IoT devices they seek to use with federal information systems and other systems operated by the federal government. The publication is to be used with the guidance in Special Publication (SP) 800-213.<\/p>\n<p>Federal organizations can use this catalog of device cybersecurity requirements to determine those appropriate support the security controls implemented on their system and in their organization. <em>Device cybersecurity requirements<\/em> are<\/p>\n<ul>\n<li>device cybersecurity capabilities, and<\/li>\n<li>non-technical supporting capabilities<\/li>\n<\/ul>\n<p>required to integrate an IoT device into a system.<\/p>\n<p><em>Device cybersecurity capabilities<\/em> are cybersecurity features or functions that computing devices provide on their own. For example, data protection using encryption would be a device&#8217;s cybersecurity capability.<\/p>\n<p><em>Non-technical supporting capabilities<\/em> are the actions an organization performs in support of the cybersecurity of an IoT device. For example, notifications when an update is available and training on how to apply the software update may be a non-technical supporting capability needed by a federal organization in support of the cybersecurity of an IoT device.<\/p>\n<p>The catalog includes mappings to <a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-53\/rev-5\/final\" target=\"_blank\" rel=\"noopener\">SP 800-53<\/a> and the Cybersecurity Framework as well as an IoT cybersecurity profile. The material included in this new publication was based on collaborative input from the public that NIST received via GitHub throughout all of 2021.<\/p>\n<h2>Conclusion<\/h2>\n<p>Organizations should be strategic and deliberate in their planning for device cybersecurity requirements, including how to mitigate gaps between desired cybersecurity requirements and the capabilities provided by the IoT device. As organizations examine IoT devices available on the market, they shall determine which device cybersecurity requirements are provided by the IoT device.<\/p>\n<p>Keeping up to date with all the regulations is not easy, but you don&#8217;t have to do everything yourself! <a href=\"https:\/\/itegriti.com\/kw022024\/cybersecurity\/\">ITEGRITI can help you<\/a> navigate these treacherous, ever-changing waters. To learn how, <a href=\"https:\/\/itegriti.com\/kw022024\/contact\/\">contact our experts<\/a>.<\/p>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>NIST has released final IoT-specific guidance to federal organizations to support extending their risk management process to the inclusion of IoT devices in federal systems. <\/p>\n","protected":false},"author":10,"featured_media":3292,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[2188,2193],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v22.0 (Yoast SEO v23.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>NIST Published the Final IoT-specific Guidance<\/title>\n<meta name=\"description\" content=\"NIST SP 800-213 is intended to help organizations incorporate IoT devices into an existing information system as system elements.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIST Published the Final IoT-specific Guidance\" \/>\n<meta property=\"og:description\" content=\"NIST SP 800-213 is intended to help organizations incorporate IoT devices into an existing information system as system elements.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/\" \/>\n<meta property=\"og:site_name\" content=\"kw022024\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/itegriti\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-14T13:58:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-09-12T14:34:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-IoTguidance.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Anastasios Arampatzis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@TassosAramp\" \/>\n<meta name=\"twitter:site\" content=\"@itegriti\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Anastasios Arampatzis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/\"},\"author\":{\"name\":\"Anastasios Arampatzis\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673\"},\"headline\":\"NIST Published the Final IoT-specific Guidance\",\"datePublished\":\"2022-03-14T13:58:16+00:00\",\"dateModified\":\"2022-09-12T14:34:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/\"},\"wordCount\":1136,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\"},\"image\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-IoTguidance.jpg\",\"keywords\":[\"Cybersecurity\",\"Energy Sector\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/\",\"url\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/\",\"name\":\"NIST Published the Final IoT-specific Guidance\",\"isPartOf\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-IoTguidance.jpg\",\"datePublished\":\"2022-03-14T13:58:16+00:00\",\"dateModified\":\"2022-09-12T14:34:59+00:00\",\"description\":\"NIST SP 800-213 is intended to help organizations incorporate IoT devices into an existing information system as system elements.\",\"breadcrumb\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#primaryimage\",\"url\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-IoTguidance.jpg\",\"contentUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-IoTguidance.jpg\",\"width\":800,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/itegriti.com\/kw022024\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NIST Published the Final IoT-specific Guidance\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#website\",\"url\":\"https:\/\/itegriti.com\/kw022024\/\",\"name\":\"ITEGRITI\",\"description\":\"cybersecurity | compliance | managed services\",\"publisher\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/itegriti.com\/kw022024\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\",\"name\":\"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services\",\"url\":\"https:\/\/itegriti.com\/kw022024\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png\",\"contentUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png\",\"width\":600,\"height\":100,\"caption\":\"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services\"},\"image\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/itegriti\",\"https:\/\/x.com\/itegriti\",\"https:\/\/www.linkedin.com\/company\/itegriti\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673\",\"name\":\"Anastasios Arampatzis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g\",\"caption\":\"Anastasios Arampatzis\"},\"description\":\"Anastasios Arampatzis is a retired Hellenic Air Force officer with over 20 years\u2019 worth of experience in managing IT projects and evaluating cybersecurity. During his service in the Armed Forces, he was assigned to various key positions in national, NATO and EU headquarters and has been honoured by numerous high-ranking officers for his expertise and professionalism. He was nominated as a certified NATO evaluator for information security. Anastasios\u2019 interests include among others cybersecurity policy and governance, ICS and IoT security, encryption, and certificates management. He is also exploring the human side of cybersecurity - the psychology of security, public education, organizational training programs, and the effect of biases (cultural, heuristic and cognitive) in applying cybersecurity policies and integrating technology into learning. He is intrigued by new challenges, open-minded and flexible. Currently, he works as a cybersecurity content writer for Bora - IT Security Marketing. Tassos is a member of the non-profit organization Homo Digitalis.\",\"sameAs\":[\"http:\/\/www.welcometobora.com\",\"https:\/\/www.linkedin.com\/in\/anastasiosarampatzis\/\",\"https:\/\/x.com\/TassosAramp\"],\"url\":\"https:\/\/itegriti.com\/kw022024\/author\/anastasios-arampatiz\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"NIST Published the Final IoT-specific Guidance","description":"NIST SP 800-213 is intended to help organizations incorporate IoT devices into an existing information system as system elements.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/","og_locale":"en_US","og_type":"article","og_title":"NIST Published the Final IoT-specific Guidance","og_description":"NIST SP 800-213 is intended to help organizations incorporate IoT devices into an existing information system as system elements.","og_url":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/","og_site_name":"kw022024","article_publisher":"https:\/\/www.facebook.com\/itegriti","article_published_time":"2022-03-14T13:58:16+00:00","article_modified_time":"2022-09-12T14:34:59+00:00","og_image":[{"width":800,"height":450,"url":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-IoTguidance.jpg","type":"image\/jpeg"}],"author":"Anastasios Arampatzis","twitter_card":"summary_large_image","twitter_creator":"@TassosAramp","twitter_site":"@itegriti","twitter_misc":{"Written by":"Anastasios Arampatzis","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#article","isPartOf":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/"},"author":{"name":"Anastasios Arampatzis","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673"},"headline":"NIST Published the Final IoT-specific Guidance","datePublished":"2022-03-14T13:58:16+00:00","dateModified":"2022-09-12T14:34:59+00:00","mainEntityOfPage":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/"},"wordCount":1136,"commentCount":0,"publisher":{"@id":"https:\/\/itegriti.com\/kw022024\/#organization"},"image":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#primaryimage"},"thumbnailUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-IoTguidance.jpg","keywords":["Cybersecurity","Energy Sector"],"articleSection":["Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/","url":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/","name":"NIST Published the Final IoT-specific Guidance","isPartOf":{"@id":"https:\/\/itegriti.com\/kw022024\/#website"},"primaryImageOfPage":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#primaryimage"},"image":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#primaryimage"},"thumbnailUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-IoTguidance.jpg","datePublished":"2022-03-14T13:58:16+00:00","dateModified":"2022-09-12T14:34:59+00:00","description":"NIST SP 800-213 is intended to help organizations incorporate IoT devices into an existing information system as system elements.","breadcrumb":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#primaryimage","url":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-IoTguidance.jpg","contentUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/03\/itegriti_84_NIST-IoTguidance.jpg","width":800,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/itegriti.com\/kw022024\/2022\/cybersecurity\/nist-published-the-final-iot-specific-guidance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/itegriti.com\/kw022024\/"},{"@type":"ListItem","position":2,"name":"NIST Published the Final IoT-specific Guidance"}]},{"@type":"WebSite","@id":"https:\/\/itegriti.com\/kw022024\/#website","url":"https:\/\/itegriti.com\/kw022024\/","name":"ITEGRITI","description":"cybersecurity | compliance | managed services","publisher":{"@id":"https:\/\/itegriti.com\/kw022024\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/itegriti.com\/kw022024\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/itegriti.com\/kw022024\/#organization","name":"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services","url":"https:\/\/itegriti.com\/kw022024\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/","url":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png","contentUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png","width":600,"height":100,"caption":"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services"},"image":{"@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/itegriti","https:\/\/x.com\/itegriti","https:\/\/www.linkedin.com\/company\/itegriti\/"]},{"@type":"Person","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673","name":"Anastasios Arampatzis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g","caption":"Anastasios Arampatzis"},"description":"Anastasios Arampatzis is a retired Hellenic Air Force officer with over 20 years\u2019 worth of experience in managing IT projects and evaluating cybersecurity. During his service in the Armed Forces, he was assigned to various key positions in national, NATO and EU headquarters and has been honoured by numerous high-ranking officers for his expertise and professionalism. He was nominated as a certified NATO evaluator for information security. Anastasios\u2019 interests include among others cybersecurity policy and governance, ICS and IoT security, encryption, and certificates management. He is also exploring the human side of cybersecurity - the psychology of security, public education, organizational training programs, and the effect of biases (cultural, heuristic and cognitive) in applying cybersecurity policies and integrating technology into learning. He is intrigued by new challenges, open-minded and flexible. Currently, he works as a cybersecurity content writer for Bora - IT Security Marketing. Tassos is a member of the non-profit organization Homo Digitalis.","sameAs":["http:\/\/www.welcometobora.com","https:\/\/www.linkedin.com\/in\/anastasiosarampatzis\/","https:\/\/x.com\/TassosAramp"],"url":"https:\/\/itegriti.com\/kw022024\/author\/anastasios-arampatiz\/"}]}},"_links":{"self":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts\/3287"}],"collection":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/comments?post=3287"}],"version-history":[{"count":6,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts\/3287\/revisions"}],"predecessor-version":[{"id":3577,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts\/3287\/revisions\/3577"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/media\/3292"}],"wp:attachment":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/media?parent=3287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/categories?post=3287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/tags?post=3287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}