News

9/9/2016
11:00 AM
Steve Zurier
Steve Zurier
Slideshows
Connect Directly
Twitter
RSS
E-Mail
50%
50%

8 Ways IoT Manufacturers Can Improve Security

New guidelines issued by the Online Trust Alliance offer ways to lock down IoT devices.
Previous
1 of 9
Next

(Image source: Pixabay)
(Image source: Pixabay)

There are ways to improve security in IoT devices – and it all starts with IoT manufacturers.

This was one of the findings of research on home and wearable technology done by the Online Trust Alliance (OTA).

The OTA found that when manufacturers follow the security and privacy principles outlined in the organization’s new IoT Trust Framework, many, if not all, of the reported vulnerabilities in IoT devices can be avoided.

Craig Spiezle, executive director and president of the OTA, says in the rush to bring product to market, IoT producers often overlook security and privacy. The IoT Trust Framework lays out 31 principles that device manufacturers, developers and policy makers can follow to improve security in IoT devices.

“We also think that CISOs should be aware of the framework, especially as more people bring IoT devices from the home to the workplace,” Spiezle says, adding that along with device manufacturers and application developers, large retailers, the National Association of Realtors, and venture capital funds have expressed interest in adopting the IoT framework principles.

Based on an interview with Spiezle, the following eight slides offer an easy way for readers to digest the IoT Trust Framework.

 

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Previous
1 of 9
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
eaglei15
100%
0%
eaglei15,
User Rank: Strategist
2/24/2017 | 7:43:30 AM
Cybeats
I would really recommend for manufacturers to look at the https://www.cybeats.com solution that solves all the iot cybersecurity related issues when it comes to securing the firmware and Continuous Cyber Protection
AnnaK746
50%
50%
AnnaK746,
User Rank: Apprentice
1/29/2017 | 3:37:25 AM
healthcare apps
hello thank you for the interesting post. I used the app for medical cards https://itechcraft.com/custom-healthcare-solutions/ like here. It is really very convenient for doctors and patients. Do you think if we use applications and technologies it will make medicine cheaper. And how can I determine the degree of security applications?
lorraine89
50%
50%
lorraine89,
User Rank: Ninja
9/30/2016 | 10:01:59 AM
Cyber security
Manufacturers should also consider investing in and researching the vpn industry so that web users can also benefit from what is the best technology out there to secure your connections. I use purevpn to secure my IP and to revert any kind of unwanted access to my ID. 
New Free Tool Scans for Chrome Extension Safety
Dark Reading Staff 2/21/2019
Making the Case for a Cybersecurity Moon Shot
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  2/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-9047
PUBLISHED: 2019-02-23
GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled.
CVE-2019-9062
PUBLISHED: 2019-02-23
PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.
CVE-2019-9063
PUBLISHED: 2019-02-23
PHP Scripts Mall Auction website script 2.0.4 allows parameter tampering of the payment amount.
CVE-2019-9064
PUBLISHED: 2019-02-23
PHP Scripts Mall Cab Booking Script 1.0.3 allows Directory Traversal into the parent directory of a jpg or png file.
CVE-2019-9065
PUBLISHED: 2019-02-23
PHP Scripts Mall Custom T-Shirt Ecommerce Script 3.1.1 allows parameter tampering of the payment amount.