LinkedIn post
NIST published an important non-technical baseline today (8259B) that RECC wants all manufacturers and service providers to support. Vendors should provide:
- 1) Adequate Documentation for customers on securing IoT products;
- 2) Information and Query Reception – Create a customer interaction ability to submit questions related to securing IoT products and associated systems;
- 3) Information Dissemination to customers on 1) the disclosure of newly discovered cybersecurity vulnerabilities for the device, associated systems and software, and 2) notifications about IoT device updates used by the manufacturer to update cybersecurity;
- 4) Education and Awareness – Provide educational content required to support customers and others in the secure use and safeguarding of IoT devices and associated systems, software, and hardware.