{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:41:49Z","timestamp":1785512509787,"version":"3.56.0"},"reference-count":76,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2023,3,13]],"date-time":"2023-03-13T00:00:00Z","timestamp":1678665600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2023,5,31]]},"abstract":"<jats:p>\n            Academic research has highlighted the failure of many\n            <jats:bold>Internet of Things (IoT)<\/jats:bold>\n            product manufacturers to follow accepted practices, while IoT security\n            <jats:italic>best practices<\/jats:italic>\n            have recently attracted considerable attention worldwide from industry and governments. Given current examples of security advice, confusion is evident from guidelines that conflate desired outcomes with security practices to achieve those outcomes. We explore a surprising lack of clarity, and void in the literature, on what (generically)\n            <jats:italic>best practice<\/jats:italic>\n            means, independent of identifying specific individual practices or highlighting failure to follow best practices. We consider categories of security advice, and analyze how they apply over the lifecycle of IoT devices. For concreteness in discussion, we use iterative inductive coding to code and systematically analyze a set of 1,013 IoT security best practices, recommendations, and guidelines collated from industrial, government, and academic sources. Among our findings, of all analyzed items, 68% fail to meet our definition of an (actionable) practice, and 73% of all actionable advice relates to the software development lifecycle phase, highlighting the critical position of manufacturers and developers. We hope that our work provides a basis for the community to better understand best practices, identify and reach consensus on specific practices, and find ways to motivate relevant stakeholders to follow them.\n          <\/jats:p>","DOI":"10.1145\/3563392","type":"journal-article","created":{"date-parts":[[2022,9,15]],"date-time":"2022-09-15T09:54:32Z","timestamp":1663235672000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":27,"title":["Security Best Practices: A Critical Analysis Using IoT as a Case Study"],"prefix":"10.1145","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2319-9916","authenticated-orcid":false,"given":"David","family":"Barrera","sequence":"first","affiliation":[{"name":"Carleton University, Ottawa, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1996-7943","authenticated-orcid":false,"given":"Christopher","family":"Bellman","sequence":"additional","affiliation":[{"name":"Carleton University, Ottawa, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5038-5370","authenticated-orcid":false,"given":"Paul","family":"Van Oorschot","sequence":"additional","affiliation":[{"name":"Carleton University, Ottawa, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,3,13]]},"reference":[{"key":"e_1_3_3_2_2","first-page":"22","volume-title":"Cybersecurity Development (SecDev)","author":"Acar Yasemin","year":"2017","unstructured":"Yasemin Acar, Christian Stransky, Dominik Wermke, Charles Weir, Michelle L. Mazurek, and Sascha Fahl. 2017. Developers need support, too: A survey of security advice for software developers. In Cybersecurity Development (SecDev). IEEE, 22\u201326."},{"key":"e_1_3_3_3_2","doi-asserted-by":"publisher","DOI":"10.2307\/1879431"},{"key":"e_1_3_3_4_2","unstructured":"Alliance for Internet of Things Innovation (AIOTI). 2015. Report: Working Group 4\u2014Policy. https:\/\/aioti.eu\/wp-content\/uploads\/2017\/03\/AIOTIWG04Report2015-Policy-Issues.pdf."},{"key":"e_1_3_3_5_2","unstructured":"Alliance for Internet of Things Innovation (AIOTI). 2016. AIOTI Digitisation of Industry Policy Recommendations. https:\/\/aioti.eu\/wp-content\/uploads\/2017\/03\/AIOTI-Digitisation-of-Ind-policy-doc-Nov-2016.pdf."},{"key":"e_1_3_3_6_2","unstructured":"Alliance for Internet of Things Innovation (AIOTI). 2016. Report on Workshop on Security and Privacy in the Hyper-connected World. https:\/\/aioti-space.org\/wp-content\/uploads\/2017\/03\/AIOTI-Workshop-on-Security-and-Privacy-in-the-Hyper-connected-World-Report-20160616_vFinal.pdf."},{"key":"e_1_3_3_7_2","first-page":"1362","volume-title":"IEEE Symp. Security and Privacy","author":"Alrawi Omar","year":"2019","unstructured":"Omar Alrawi, Chaz Lever, Manos Antonakakis, and Fabian Monrose. 2019. SoK: Security evaluation of home-based IoT deployments. In IEEE Symp. Security and Privacy. IEEE, 1362\u20131380."},{"key":"e_1_3_3_8_2","first-page":"3505","volume-title":"USENIX Security Symp.","author":"Alrawi Omar","year":"2021","unstructured":"Omar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court, Kevin Snow, Fabian Monrose, and Manos Antonakakis. 2021. The circle of life: A large-scale study of the IoT malware lifecycle. In USENIX Security Symp.USENIX, 3505\u20133522."},{"key":"e_1_3_3_9_2","first-page":"281","volume-title":"Symp. on Usable Privacy and Security (SOUPS)","author":"Assal Hala","year":"2018","unstructured":"Hala Assal and Sonia Chiasson. 2018. Security in the software development lifecycle. In Symp. on Usable Privacy and Security (SOUPS). USENIX, 281\u2013296."},{"key":"e_1_3_3_10_2","unstructured":"AT&T. 2016. The CEO\u2019s Guide to Securing the Internet of Things. https:\/\/www.business.att.com\/cybersecurity\/docs\/exploringiotsecurity.pdf."},{"key":"e_1_3_3_11_2","unstructured":"Australian Department of Home Affairs and Australian Cyber Security Centre. 2020. Code of Practice\u2014Securing the Internet of Things for Consumers. https:\/\/www.homeaffairs.gov.au\/reports-and-pubs\/files\/code-of-practice.pdf."},{"key":"e_1_3_3_12_2","unstructured":"Christopher Bellman. 2022. cb1 013-dataset. https:\/\/github.com\/ChristopherBellman\/SecurityAdvice\/blob\/main\/cb1013-dataset-TOPS.json."},{"key":"e_1_3_3_13_2","volume-title":"Computer Security: Art and Science","author":"Bishop Matt","year":"2003","unstructured":"Matt Bishop. 2003. Computer Security: Art and Science. Addison-Wesley."},{"key":"e_1_3_3_14_2","doi-asserted-by":"crossref","first-page":"383","DOI":"10.1007\/BFb0013545","volume-title":"International Workshop on Processing Declarative Knowledge","author":"Boley Harold","year":"1991","unstructured":"Harold Boley, Micha Meier, Chris Moss, Michael M. Richter, and A. A. Voronkov. 1991. Declarative and procedural paradigms - do they really compete?. In International Workshop on Processing Declarative Knowledge. Springer, 383\u2013398."},{"key":"e_1_3_3_15_2","unstructured":"Broadband Internet Technical Advisory Group (BITAG). 2016. Internet of Things (IoT) Security and Privacy Recommendations. http:\/\/www.bitag.org\/documents\/BITAG_Report_-_Internet_of_Things_(IoT)_Security_and_Privacy_Recommendations.pdf."},{"key":"e_1_3_3_16_2","unstructured":"CableLabs. 2017. A Vision for Secure IoT. https:\/\/www.cablelabs.com\/insights\/vision-secure-iot\/."},{"key":"e_1_3_3_17_2","unstructured":"City of New York (NYC) Guidelines for the Internet of Things. 2019. Privacy + Transparency. https:\/\/iot.cityofnewyork.us\/privacy-and-transparency\/."},{"key":"e_1_3_3_18_2","unstructured":"City of New York (NYC) Guidelines for the Internet of Things. 2019. Security. https:\/\/iot.cityofnewyork.us\/security\/."},{"key":"e_1_3_3_19_2","unstructured":"Cloud Security Alliance (CSA). 2015. Security Guidance for Early Adopters of the Internet of Things (IoT). https:\/\/downloads.cloudsecurityalliance.org\/whitepapers\/Security_Guidance_for_Early_Adopters_of_the_Internet_of_Things.pdf."},{"key":"e_1_3_3_20_2","unstructured":"Cloud Security Alliance (CSA). 2016. Future-proofing the Connected World: 13 Steps to Developing Secure IoT. https:\/\/downloads.cloudsecurityalliance.org\/assets\/research\/internet-of-things\/future-proofing-the-connected-world.pdf."},{"key":"e_1_3_3_21_2","unstructured":"Copper Horse Ltd.2019. Mapping Security & Privacy in the Internet of Things. https:\/\/iotsecuritymapping.uk\/wp-content\/uploads\/Mapping-of-Code-of-Practice-to-recommendations-and-standards_v3.json. Version 3 dataset."},{"key":"e_1_3_3_22_2","unstructured":"George Corser Glenn A. Fink Mohammed Aledhari Jared Bielby Rajesh Nighot Sukanya Mandal Nagender Aneja Chris Hrivnak and Lucian Cristache. 2017. IoT Security Principles and Best Practices. IEEE. https:\/\/internetinitiative.ieee.org\/images\/files\/resources\/white_papers\/internet_of_things_feb2017.pdf."},{"key":"e_1_3_3_23_2","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1109\/IoTDI.2018.00044","volume-title":"2018 IEEE\/ACM Third International Conference on Internet-of-Things Design and Implementation (IoTDI)","author":"Dingman Andrew","year":"2018","unstructured":"Andrew Dingman, Gianpaolo Russo, George Osterholt, Tyler Uffelman, and L. Jean Camp. 2018. Poster abstract: Good advice that just doesn\u2019t help. In 2018 IEEE\/ACM Third International Conference on Internet-of-Things Design and Implementation (IoTDI). IEEE, 289\u2013291."},{"key":"e_1_3_3_24_2","unstructured":"European Telecommunications Standards Institute (ETSI). 2019. CYBER; Cyber Security for Consumer Internet of Things. https:\/\/www.etsi.org\/deliver\/etsi_ts\/103600_103699\/103645\/01.01.01_60\/ts_103645v010101p.pdf."},{"key":"e_1_3_3_25_2","unstructured":"European Telecommunications Standards Institute (ETSI). 2020. CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements (ETSI EN 303 645). https:\/\/www.etsi.org\/deliver\/etsi_en\/303600_303699\/303645\/02.01.01_60\/en_303645v020101p.pdf."},{"key":"e_1_3_3_26_2","unstructured":"European Telecommunications Standards Institute (ETSI). 2021. CYBER; Cyber Security for Consumer Internet of Things: Conformance Assessment of Baseline Requirements (ETSI TS 103 701 V1.1.1). https:\/\/www.etsi.org\/deliver\/etsi_ts\/103700_103799\/103701\/01.01.01_60\/ts_103701v010101p.pdf."},{"key":"e_1_3_3_27_2","unstructured":"European Union Agency for Network and Information Security (ENISA). 2015. Security and Resilience of Smart Home Environments. https:\/\/www.ENISA.europa.eu\/publications\/security-resilience-good-practices."},{"key":"e_1_3_3_28_2","unstructured":"European Union Agency for Network and Information Security (ENISA). 2017. Baseline Security Recommendations for IoT. https:\/\/www.ENISA.europa.eu\/publications\/baseline-security-recommendations-for-iot."},{"key":"e_1_3_3_29_2","unstructured":"Michael Fagan Jeffrey Marron Kevin G. Brady Jr. Barbara B. Cuthill Katerina N. Megas and Rebecca Herold. 2020. Draft NISTIR 8259C\u2014Creating a Profile Using the IoT Core Baseline and Non-Technical Baseline. NIST."},{"key":"e_1_3_3_30_2","doi-asserted-by":"crossref","unstructured":"Michael Fagan Jeffrey Marron Kevin G. Brady Jr. Barbara B. Cuthill Katerina N. Megas and Rebecca Herold. 2021. NISTIR 8259B\u2014IoT Non-Technical Supporting Capability Core Baseline. NIST.","DOI":"10.6028\/NIST.IR.8259B"},{"key":"e_1_3_3_31_2","doi-asserted-by":"crossref","unstructured":"Michael Fagan Jeffrey Marron Kevin G. Brady Jr. Barbara B. Cuthill Katerina N. Megas Rebecca Herold David Lemire and Brad Hoehn. 2020. SP 800-213\u2014IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements. NIST.","DOI":"10.6028\/NIST.SP.800-213-draft"},{"key":"e_1_3_3_32_2","doi-asserted-by":"crossref","first-page":"353","DOI":"10.1007\/978-3-642-01862-6_29","volume-title":"Enterprise, Business-Process and Information Systems Modeling","author":"Fahland Dirk","year":"2009","unstructured":"Dirk Fahland, Daniel L\u00fcbke, Jan Mendling, Hajo Reijers, Barbara Weber, Matthias Weidlich, and Stefan Zugal. 2009. Declarative versus imperative process modeling languages: The issue of understandability. In Enterprise, Business-Process and Information Systems Modeling. Springer, 353\u2013366."},{"key":"e_1_3_3_33_2","unstructured":"Oscar Garcia-Morchon Sandeep S. Kumar and Mohit Sethi. 2019. State-of-the-Art and Challenges for the Internet of Things Security. https:\/\/datatracker.ietf.org\/doc\/draft-irtf-t2trg-iot-seccons\/."},{"key":"e_1_3_3_34_2","unstructured":"Simson Garfinkel Gene Spafford and Alan Schwartz. 2003. Chapter 3: Policies and Guidelines. In [34]."},{"key":"e_1_3_3_35_2","doi-asserted-by":"publisher","DOI":"10.5555\/1212585"},{"key":"e_1_3_3_36_2","volume-title":"Computer Security, 3rd Edition","author":"Gollmann Dieter","year":"2011","unstructured":"Dieter Gollmann. 2011. Computer Security, 3rd Edition. Wiley."},{"key":"e_1_3_3_37_2","doi-asserted-by":"crossref","unstructured":"Paul A. Grassi et al.2017. SP 800-63B\u2014Digital Identity Guidelines: Authentication and Lifecycle Management. NIST.","DOI":"10.6028\/NIST.SP.800-63b"},{"key":"e_1_3_3_38_2","unstructured":"GSM Association. 2017. IoT Security Guidelines for Endpoint Ecosystems\u2014Version 2.0. https:\/\/www.gsma.com\/iot\/wp-content\/uploads\/2017\/10\/CLP.13-v2.0.pdf."},{"key":"e_1_3_3_39_2","first-page":"1626","volume-title":"IEEE Symp. Security and Privacy","author":"Huaman Nicholas","year":"2021","unstructured":"Nicholas Huaman, Sabrina Amft, Marten Oltrogge, Yasemin Acar, and Sascha Fahl. 2021. They would do better if they worked together: The case of interaction problems between password managers and websites. In IEEE Symp. Security and Privacy. IEEE, 1626\u20131640."},{"key":"e_1_3_3_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/2767181"},{"key":"e_1_3_3_41_2","unstructured":"IoT Security Foundation. 2017. IoT Security Compliance Framework 1.1. https:\/\/www.iotsecurityfoundation.org\/wp-content\/uploads\/2017\/12\/IoT-Security-Compliance-Framework_WG1_2017.pdf."},{"key":"e_1_3_3_42_2","unstructured":"IoT Security Initiative. 2018. Security Design Best Practices. https:\/\/www.iotsi.org\/security-best-practices."},{"key":"e_1_3_3_43_2","unstructured":"Erica Johnson. 2020. Online Banking Agreements Protect Banks Hold Customers Liable for Losses Expert Says. (Feb. 9 2020). Canadian Broadcasting Corporation. https:\/\/www.cbc.ca\/news\/business\/online-banking-agreements-1.5453192."},{"key":"e_1_3_3_44_2","first-page":"39","volume-title":"Symposium on Usable Privacy and Security (SOUPS)","author":"Kang Ruogu","year":"2019","unstructured":"Ruogu Kang, Laura Dabbish, Nathaniel Fruchter, and Sara Kiesler. 2019. \u201cMy data just goes everywhere\u201d: User mental models of the internet and implications for privacy and security. In Symposium on Usable Privacy and Security (SOUPS). USENIX, 39\u201352."},{"key":"e_1_3_3_45_2","volume-title":"National Information Systems Security Conference","author":"King Guy","year":"2000","unstructured":"Guy King. 2000. Best security practices: An overview. In National Information Systems Security Conference. NIST, 12."},{"key":"e_1_3_3_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.201"},{"key":"e_1_3_3_47_2","first-page":"1339","volume-title":"USENIX Security Symp.","author":"Krombholz Katharina","year":"2017","unstructured":"Katharina Krombholz, Wilfried Mayer, Martin Schmiedecker, and Edgar Weippl. 2017. \u201cI have no idea what I\u2019m doing\u201d\u2014on the usability of deploying HTTPS. In USENIX Security Symp.USENIX, 1339\u20131356."},{"key":"e_1_3_3_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2012.167"},{"key":"e_1_3_3_49_2","unstructured":"Greg Lindsay Beau Woods and Joshua Corman. 2016. Smart Homes and the Internet of Things. https:\/\/www.atlanticcouncil.org\/wp-content\/uploads\/2016\/03\/Smart_Homes_0317_web.pdf."},{"key":"e_1_3_3_50_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3359174","article-title":"Reliability and inter-rater reliability in qualitative research: Norms and guidelines for CSCW and HCI practice","volume":"3","author":"McDonald Nora","year":"2019","unstructured":"Nora McDonald, Sarita Schoenebeck, and Andrea Forte. 2019. Reliability and inter-rater reliability in qualitative research: Norms and guidelines for CSCW and HCI practice. Proc. ACM Hum.-Comput. Interact 3, CSCW (Nov.2019), 1\u201323.","journal-title":"Proc. ACM Hum.-Comput. Interact"},{"key":"e_1_3_3_51_2","volume-title":"Software Security: Building Security In (First edition)","author":"McGraw Gary","year":"2006","unstructured":"Gary McGraw. 2006. Software Security: Building Security In (First edition). Addison-Wesley Professional."},{"key":"e_1_3_3_52_2","unstructured":"Microsoft. 2018. Security best practices for Internet of Things (IoT). https:\/\/docs.microsoft.com\/en-us\/azure\/iot-fundamentals\/iot-security-best-practices."},{"key":"e_1_3_3_53_2","unstructured":"Keith Moore Richard Barnes and Hannes Tschofenig. July 2017. Best Current Practices (BCP) for IoT Devices. IETF Internet-Draft (Expired). https:\/\/www.ietf.org\/archive\/id\/draft-moore-iot-security-bcp-01.txt."},{"key":"e_1_3_3_54_2","volume-title":"Workshop on Decentralized IoT Security and Standards (DISS)","author":"Morgner Philipp","year":"2018","unstructured":"Philipp Morgner and Zinaida Benenson. 2018. Exploring security economics in IoT standardization efforts. In Workshop on Decentralized IoT Security and Standards (DISS). Internet Society, 6."},{"key":"e_1_3_3_55_2","first-page":"311","volume-title":"ACM CCS","author":"Naiakshina Alena","year":"2017","unstructured":"Alena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog, Sergej Dechand, and Matthew Smith. 2017. Why do developers get password storage wrong? A qualitative usability study. In ACM CCS. ACM, 311\u2013328."},{"key":"e_1_3_3_56_2","unstructured":"NIST. 2001. FIPS PUB 197: Announcing the Advanced Encryption Standard (AES). (2001). US Department of Commerce."},{"key":"e_1_3_3_57_2","unstructured":"NIST. 2020. NIST Releases Draft Guidance on Internet of Things Device Cybersecurity. https:\/\/www.nist.gov\/news-events\/news\/2020\/12\/nist-releases-draft-guidance-internet-things-device-cybersecurity."},{"key":"e_1_3_3_58_2","unstructured":"Online Trust Alliance (OTA). 2017. IoT Security & Privacy Trust Framework v2.5. https:\/\/www.internetsociety.org\/wp-content\/uploads\/2018\/05\/iot_trust_framework2.5a_EN.pdf."},{"key":"e_1_3_3_59_2","unstructured":"Open Web Application Security Project (OWASP). 2010. OWASP Secure Coding Practices Quick Reference Guide. https:\/\/www.owasp.org\/images\/0\/08\/OWASP_SCP_Quick_Reference_Guide_v2.pdf."},{"key":"e_1_3_3_60_2","unstructured":"PlainTextOffenders.com. 2021. https:\/\/plaintextoffenders.com\/."},{"key":"e_1_3_3_61_2","doi-asserted-by":"crossref","unstructured":"Jon Postel Yakov Rekhter and Tony Li. 1995. RFC 1818: Best Current Practices. IETF.","DOI":"10.17487\/rfc1818"},{"key":"e_1_3_3_62_2","unstructured":"PSA Certified. 2019. PSA Certified Level 1 Questionnaire. Critical security questions for chip vendors OS providers and OEMs. https:\/\/www.psacertified.org\/app\/uploads\/2019\/02\/JSADEN001-PSA_Certified_Level_1-1.0Web.pdf."},{"key":"e_1_3_3_63_2","first-page":"89","volume-title":"USENIX Security Symp.","author":"Redmiles Elissa M.","year":"2020","unstructured":"Elissa M. Redmiles, Noel Warford, Amritha Jayanti, Aravind Koneru, Sean Kross, M. Morales, R. Stevens, and Michelle L. Mazurek. 2020. A comprehensive quality evaluation of security and privacy advice on the web. In USENIX Security Symp.USENIX, 89\u2013108."},{"key":"e_1_3_3_64_2","doi-asserted-by":"crossref","unstructured":"Ron Ross Michael McEvilley and Janet Carrier Oren. 2016. SP 800-160 (Vol. 1)\u2014Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems. NIST. https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-160v1.pdf.","DOI":"10.6028\/NIST.SP.800-160"},{"key":"e_1_3_3_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"e_1_3_3_66_2","unstructured":"Behcet Sarikaya Mohit Sethi and Dan Garcia-Carrillo. 2019. Secure IoT Bootstrapping: A Survey. (2019). Internet Draft draft-sarikaya-t2trg-sbootstrapping-05."},{"key":"e_1_3_3_67_2","volume-title":"The New School of Information Security","author":"Shostack Adam","year":"2008","unstructured":"Adam Shostack and Andrew Stewart. 2008. The New School of Information Security. Pearson Education."},{"key":"e_1_3_3_68_2","unstructured":"Abhay Soorya et al.2018. IoT Security Compliance Framework 2.0. https:\/\/www.iotsecurityfoundation.org\/wp-content\/uploads\/2018\/12\/IoTSF-IoT-Security-Compliance-Framework-Release-2.0-December-2018.pdf."},{"key":"e_1_3_3_69_2","doi-asserted-by":"crossref","unstructured":"Gary Stoneburner Clark Hayden and Alexis Feringa. 2004. SP 800-27 RevA\u2014Engineering Principles for Information Technology Security (A Baseline for Achieving Security). NIST.","DOI":"10.6028\/NIST.SP.800-27ra"},{"key":"e_1_3_3_70_2","unstructured":"Sven Schrecker et al. 2016. Industrial Internet of Things Volume G4: Security Framework v1.0. https:\/\/www.iiconsortium.org\/pdf\/IIC_PUB_G4_V1.00_PB-3.pdf."},{"key":"e_1_3_3_71_2","doi-asserted-by":"publisher","DOI":"10.1177\/1098214005283748"},{"issue":"5","key":"e_1_3_3_72_2","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1109\/MSEC.2019.2923973","article-title":"Cyberphysical security for the masses: A survey of the internet protocol suite for internet of things security","volume":"17","author":"Tschofenig Hannes","year":"2019","unstructured":"Hannes Tschofenig and Emmanuel Baccelli. 2019. Cyberphysical security for the masses: A survey of the internet protocol suite for internet of things security. IEEE Security & Privacy 17, 5 (Sep.2019), 47\u201357.","journal-title":"IEEE Security & Privacy"},{"key":"e_1_3_3_73_2","unstructured":"UK Government Department for Digital Culture Media & Sport (DCMS). 2018. Code of Practice for Consumer IoT Security. https:\/\/assets.publishing.service.gov.uk\/government\/uploads\/system\/uploads\/attachment_data\/file\/773867\/Code_of_Practice_for_Consumer_IoT_Security_October_2018.pdf."},{"key":"e_1_3_3_74_2","unstructured":"UK Government Department for Digital Culture Media & Sport (DCMS). 2018. Mapping of IoT Security Recommendations Guidance and Standards to the UK\u2019s Code of Practice for Consumer IoT Security. https:\/\/assets.publishing.service.gov.uk\/government\/uploads\/system\/uploads\/attachment_data\/file\/774438\/Mapping_of_IoT__Security_Recommendations_Guidance_and_Standards_to_CoP_Oct_2018.pdf. https:\/\/assets.publishing.service.gov.uk\/government\/uploads\/system\/uploads\/attachment_data\/file\/774438\/Mapping_of_IoT__Security_Recommendations_Guidance_and_Standards_to_CoP_Oct_2018.pdf."},{"key":"e_1_3_3_75_2","unstructured":"US National Telecommunications and Information Administration (NTIA). 2017. Voluntary Framework for Enhancing Update Process Security. https:\/\/www.ntia.doc.gov\/files\/ntia\/publications\/ntia_iot_capabilities_oct31.pdf."},{"key":"e_1_3_3_76_2","unstructured":"US Senate. 2017. Bill\u2014S.1691 - Internet of Things (IoT) Cybersecurity Improvement Act of 2017 (Bill). https:\/\/www.congress.gov\/bill\/115th-congress\/senate-bill\/1691\/text?format=txt."},{"key":"e_1_3_3_77_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12599-015-0383-3"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3563392","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3563392","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:35Z","timestamp":1750182575000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3563392"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,13]]},"references-count":76,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2023,5,31]]}},"alternative-id":["10.1145\/3563392"],"URL":"https:\/\/doi.org\/10.1145\/3563392","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,13]]},"assertion":[{"value":"2021-09-22","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-03-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}