Strategic Principles for Securing the Internet of Things

The growth of network-connected devices, systems, and services comprising the Internet of Things (IoT) creates immense opportunities and benefits for our society. IoT security, however, has not kept up with the rapid pace of innovation and deployment, creating substantial safety and economic risks. This document explains these risks and provides a set of non-binding principles and suggested best practices to build toward a responsible level of security for the devices and systems businesses design, manufacture, own, and operate.

The following principles offer stakeholders a way to organize their thinking about how to address IoT security challenges:

  1. Incorporate Security at the Design Phase
  2. Advance Security Updates and Vulnerability Management
  3. Build on Proven Security Practices
  4. Prioritize Security Measures According to Potential Impact
  5. Promote Transparency across IoT
  6. Connect Carefully and Deliberately

Strategic Principles for Securing the Internet of Things