Periodic risk assessments

Perform periodic risk assessments, ideally using third parties, to validate that the IoT system is not only compliant but also meets its minimum security baseline. Perform black box penetration testing at least every six months, and more focused testing (white box) at least every year. The testing should focus on the IoT systems as a whole, and not just the devices themselves.

A comprehensive penetration testing program should be established by organizations deploying IoT solutions. This should include a mix of black box and white box testing, as well as fuzz testing against well-known IoT application protocols in use.

Get Practical Internet of Things Security - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.