Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Workshop Summary Report for "Workshop on Foundational Cybersecurity Activities for IoT Device Manufacturers"

Published

Author(s)

Michael Fagan, Katerina Megas, Barbara Cuthill, Brad Hoehn, Evelyn Petrella

Abstract

This report summarizes discussions held at the March 5, 2025 "Workshop on Foundational Cybersecurity Activities for IoT Device Manufacturers" organized by the NIST Cybersecurity for the Internet of Things (IoT) program. This workshop follows an earlier event held in December 2024 titled "Workshop on Updating Manufacturer Guidance for Securable Connected Product Development" to identify major update areas to NIST IR 8259. Similarly, the purpose of this more recent workshop was to discuss planned updates to NIST IR 8259 and gather additional feedback on taking a product viewpoint with greater emphasis on the IoT product lifecycle, expanded discussion of risk analysis, application to industrial contexts, and cybersecurity considerations around data management to support privacy goals. Over time, NIST work has built upon the concepts introduced in the NIST IR 8259, as reflected in subsequent publications that elaborate on IoT cybersecurity for specific sectors and use cases (e.g., federal agency use of IoT, consumer use of IoT in the home or in small businesses).
Citation
NIST Interagency/Internal Report (NISTIR) - 8572
Report Number
8572

Keywords

Internet of Things, IoT products, manufacturing, risk assessment, product lifecycle, securable products, security requirements, software development, threat modelling

Citation

Fagan, M. , Megas, K. , Cuthill, B. , Hoehn, B. and Petrella, E. (2025), Workshop Summary Report for "Workshop on Foundational Cybersecurity Activities for IoT Device Manufacturers", NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.IR.8572, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=959961 (Accessed May 14, 2025)

Issues

If you have any questions about this publication or are having problems accessing it, please contact [email protected].

Created May 13, 2025