Best Practices for IoT Security: What Does That Even Mean?
Christopher Bellman, Paul C. van Oorschot

TL;DR
This paper investigates the ambiguous concept of 'best practices' in IoT security, analyzing over a thousand guidelines to clarify their meaning, application, and lifecycle relevance, aiming to foster consensus and improved security adherence.
Contribution
It provides a comprehensive analysis of what constitutes IoT security best practices, categorizes them, and highlights their predominant focus on early device lifecycle stages.
Findings
70% of practices relate to early device lifecycle stages
Many guidelines conflate outcomes with specific practices
Significant confusion exists around the actionable nature of best practices
Abstract
Best practices for Internet of Things (IoT) security have recently attracted considerable attention worldwide from industry and governments, while academic research has highlighted the failure of many IoT product manufacturers to follow accepted practices. We explore not the failure to follow best practices, but rather a surprising lack of understanding, and void in the literature, on what (generically) "best practice" means, independent of meaningfully identifying specific individual practices. Confusion is evident from guidelines that conflate desired outcomes with security practices to achieve those outcomes. How do best practices, good practices, and standard practices differ? Or guidelines, recommendations, and requirements? Can something be a best practice if it is not actionable? We consider categories of best practices, and how they apply over the lifecycle of IoT devices. For…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Information and Cyber Security · Cloud Data Security Solutions
