How Connected Data is Transforming Risk Management
The article discusses how the proliferation of Internet of Things (IoT) devices, which enable automation and remote monitoring across industries but often lack robust security controls, is increasing cybersecurity risks and prompting organizations like NIST to develop data security standards to better manage these connected data environments.
Connected devices are increasingly creating cybersecurity stress for businesses of all sizes across all industries. Securing data environments now requires establishing cybersecurity frameworks for Internet of Things (IoT) devices. To address this, the National Institute of Standards and Technology (NIST) issued a call for papers in April 2018 to create data security standards for IoT devices.
Internet of Things Risk Management
What is the Internet of Things?
Any device that can connect to the internet or another device falls under the broad definition of the Internet of Things (IoT). Examples include smart home devices like lights controlled via smartphone, Bluetooth headphones, and real-time monitoring systems for pipelines in the oil and gas industry.
IoT drives efficiency by enabling remote monitoring and automation. People use security systems they can monitor from their phones, businesses incorporate productivity tools, and manufacturers streamline processes with Supervisory Control and Data Acquisition (SCADA) systems.
What are the security risks of using IoT devices?
Unlike traditional computers, which users can turn off and secure, IoT devices are designed for automation and constant connectivity. This increases the risk, as these devices often lack robust security controls.
For example, in healthcare, IoT-enabled pacemakers allow doctors to monitor patients remotely. In homes, doorbells and security cameras connect to smartphones. However, the sensors and connections between these devices often cannot support the same level of protection as larger devices.
What is a Bluetooth connection?
Bluetooth connections use short-distance, low-frequency radio waves and consume little power. They connect devices within a 30-foot range. While some devices, like headphones, require a primary device (like a smartphone) to access the internet, others, like smartwatches, may have their own cellular connections.
Bluetooth connections are considered "lightweight" in security terms. Due to their low power and frequency, they have limited capabilities and often cannot integrate independently.
What are the biggest IoT risks?
Bluetooth-enabled and IoT devices create various security concerns. The five predominant security gaps for risk management are:
Authentication
Traditional network devices use usernames, passwords, and sometimes multi-factor authentication. Bluetooth devices create a unique address but typically do not support password protection, resulting in weak authentication.
Confidentiality
Without secure authentication, information transmitted between devices may not remain confidential. This is similar to the risks of using public Wi-Fi, where unencrypted data can be intercepted.
Authorization
Bluetooth connections lack the complexity to restrict access to authorized users or programs. Unlike traditional networks, you cannot define user-specific data access on Bluetooth devices.
Integrity
Without authentication and authorization, it is difficult to ensure that only authorized individuals access information transmitted over Bluetooth. This makes it easier for attackers to intercept data.
Pairing
Pairing a Bluetooth IoT device with another device requires establishing a connection. If the primary device is left open to Bluetooth connections, malicious actors may attempt to connect to it.
What is the goal of NIST’s “Lightweight Cryptography” project?
IoT devices vary in price and sophistication. For example, an IoT syringe for administering medication requires a higher level of security than headphones connected to an MP3 player. A compromised medical device could endanger lives, while a hacked MP3 player might only expose personal data.
NIST aims to create standards to protect all devices. After consulting with industry groups, NIST's draft Lightweight Cryptography Standardization Process focuses on minimum requirements such as authenticated encryption with associated data (AEAD) to prevent brute-force attacks. The project also emphasizes solutions that maintain low energy consumption, low power, and rapid speed.
How ZenGRC Enables NIST Compliance
ZenGRC offers a solution that helps compliance managers stay current with changes in IT compliance. Its built-in content includes NIST 800-53 and its objectives. When standards change, ZenGRC updates accordingly, providing a single source of truth for standards and regulations to ensure continuous compliance in the evolving cybersecurity landscape.
For more information about how ZenGRC enables continuous compliance, contact them for a demo.