U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

This is an archive
(replace .gov by .rip)

NISTIR 8267 (Draft)

Security Review of Consumer Home Internet of Things (IoT) Products

Date Published: October 2019
Comments Due: November 1, 2019 (public comment period is CLOSED)
Email Questions to: home-iot-nccoe@nist.gov

Author(s)

Michael Fagan (NIST), Mary Yang (MITRE), Allen Tan (MITRE), Lora Randolph (MITRE), Karen Scarfone (Scarfone Cybersecurity)

Announcement

In 2017, more than eight billion IoT devices were in use worldwide and the current estimate is that more than 20 billion IoT devices will be in use by 2020, according to various market research organizations. Since many IoT devices  are accessible via the internet, malicious actors can exploit vulnerabilities to gain access to IoT devices.

Draft NIST Interagency or Internal Report (NISTIR) 8267, Security Assessment of Consumer Home IoT Products, presents the results of technical assessments on security features of smart light bulbs, security lights, security cameras, doorbells, plugs, thermostats, and televisions. This report provides recommendations, along with information on the observations of the devices' security features, to indicate current practices and how these current practices could be improved. These technical assessments will help the NCCoE better address consumer home IoT security in a holistic manner in future projects. In addition, the technical assessments inform the security tenets for IoT devices outlined in Draft NISTIR 8259, Core Cybersecurity Feature Baseline for Securable IoT Devices.
 

NOTE: A call for patent claims is included on page iv of this draft.  For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications

Abstract

Keywords

consumer home Internet of Things; cybersecurity; Internet of Things; IoT devices; smart home
Control Families

None selected

Documentation

Publication:
NISTIR 8267 (Draft) (DOI)
Local Download

Supplemental Material:
None available

Related NIST Publications:
NISTIR 8259 (Draft)

Document History:
10/01/19: NISTIR 8267 (Draft)

Topics

Security and Privacy
general security & privacy

Technologies
mobile; sensors

Applications
Internet of Things

Sectors
retail