Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks



Katie Boeckl, Michael Fagan, Bill Fisher, Naomi Lefkovitz, Katerina N. Megas, Ellen M. Nadeau, Benjamin M. Piccarreta, Danna G. O'Rourke, Karen A. Scarfone


The Internet of Things (IoT) is a rapidly evolving and expanding collection of diverse technologies that interact with the physical world. Many organizations are not necessarily aware of the large number of IoT devices they are already using and how IoT devices may affect cybersecurity and privacy risks differently than conventional information technology (IT) devices do. The purpose of this publication is to help federal agencies and other organizations better understand and manage the cybersecurity and privacy risks associated with their individual IoT devices throughout the devices' lifecycles. This publication is the introductory document providing the foundation for a planned series of publications on more specific aspects of this topic.
NIST Interagency/Internal Report (NISTIR) - 8228
Report Number


cybersecurity risk, Internet of Things (IoT), privacy risk, risk management, risk mitigation


Boeckl, K. , Fagan, M. , Fisher, B. , Lefkovitz, N. , Megas, K. , Nadeau, E. , Piccarreta, B. , O'Rourke, D. and Scarfone, K. (2019), Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online],, (Accessed May 27, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created June 24, 2019, Updated October 12, 2021