How Should Security Teams Manage IoT Risks?

146 views
•
May 1, 2014
by
RSAC Cybersecurity
YouTube video player
How Should Security Teams Manage IoT Risks?

TL;DR

Internet of Things security should begin with understanding connected endpoints, assessing the business and safety impact of each service, and concentrating limited resources on the most serious threats. As connectivity spreads across vehicles, homes, passports, healthcare, and enterprises, organizations also need faster education, training, mentoring, and recruitment paths to address the shortage of skilled security professionals.

Transcript

Hi, I'm Tom Field, vice president of editorial with Information Security Media Group, and it's my pleasure to be speaking today with the incoming president of ISACA, Robert Stroud. Rob, pleasure to meet you and to sit down with you. Yeah, it's finally to meet in person, Tom. Been a long time. We've talked over the phone for years now. I mean, you'v... Read More

Key Insights

  • The Internet of Things is an environment in which devices, systems, services, and identities become increasingly interconnected. Examples in the discussion include electronically controlled cars, smartphone-operated doors, ePassports, business systems, healthcare equipment, and robots used during medical procedures.
  • Connected endpoints increase the potential points of entry available to attackers. As devices become more intelligent and business services depend on multiple endpoints, security professionals must understand how each connection extends the enterprise environment and changes its exposure to threats.
  • IoT risk depends on the importance and potential consequences of the connected service. A noncritical service may present limited harm, while failures involving healthcare or other life-threatening situations can justify much greater concern, scrutiny, and allocation of security resources.
  • Risk assessment is essential because security teams have limited people, time, and effort. Professionals must comprehend connected environments, analyze where meaningful threats exist, and prioritize protections at the points where failures or attacks would produce the most serious consequences.
  • Connected technology makes the service value chain more complex. A car, for example, is no longer simply mechanical because electronic controls, computerized diagnostics, maintenance providers, and related services form an interconnected system that creates both opportunities and risks.
  • ISACA is adapting its mission as technology professions evolve. The association began by serving audit and assurance professionals, expanded its relevance to governance professionals, and identified security education and support as a major objective amid cybersecurity and advanced persistent threats.
  • The security skills shortage requires accelerated career pathways for people entering from colleges and universities. Education, training, mentoring, and access to good practices can help newcomers develop useful capabilities quickly and begin adding value to employers and the profession.
  • Security careers must be actively marketed to prospective professionals. Industry organizations and employers need to recruit at the grassroots level, advertise in colleges, describe security as a real and rewarding career, and clearly communicate the profession's value and opportunities.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should organizations assess Internet of Things risks?

Organizations should first comprehend how connected devices, endpoints, and services interact across the full environment. They should then analyze possible threats and evaluate the consequences of failure or attack. A noncritical service does not require the same attention as a healthcare system or another potentially life-threatening service. This assessment helps teams apply limited people, time, and effort where protection matters most.

Q: Why does the Internet of Things increase security threats?

The Internet of Things increases security threats because services can depend on multiple connected endpoints, creating additional points through which an attacker might enter an enterprise. Devices that were once non-intelligent are also becoming intelligent and interconnected. As this environment expands, security professionals must understand not only individual devices but also the longer, more complex service value chains surrounding them.

Q: What are practical examples of Internet of Things technology?

Practical examples include cars whose engines and diagnostics rely on electronic control systems, doors that can be unlocked with a smartphone, and ePassports that support identification before a traveler reaches a customs agent. The discussion also includes connected business services and robots used in healthcare procedures. Together, these examples show how connectivity is spreading throughout consumer life and enterprise operations.

Q: Why are healthcare IoT systems especially concerning?

Healthcare IoT systems are especially concerning because a malfunction, interruption, or reboot can occur during a life-threatening procedure. The interview uses a connected robot performing an operation as an example, noting that a computer reboot during open-heart surgery would be particularly dangerous. The potential consequences make healthcare services a higher priority for careful risk analysis and appropriate security resources.

Q: How can security teams prioritize limited resources for IoT?

Security teams can prioritize limited resources by assessing the importance of each connected service and the severity of possible consequences. They should avoid reacting with equal alarm to every device. Instead, they should identify where threats are meaningful, distinguish low-impact services from critical or life-threatening systems, and direct available personnel, time, and effort toward the areas of greatest risk.

Q: How does IoT change the service value chain?

IoT makes the service value chain longer and more complex because connected products depend on electronic controls, software, diagnostics, maintenance processes, endpoints, and service providers. The electronically controlled car is presented as a clear example. Understanding this entire chain is necessary because security risks and business opportunities can arise from the relationships among its components, not only from the product itself.

Q: How can the security profession address its skills shortage?

The profession can address its skills shortage by identifying and attracting people from colleges and universities, then giving them structured career paths. Accelerated education, practical training, mentoring, and access to established good practices can help newcomers develop relevant skills quickly. These measures are intended to help new professionals contribute value to employers while strengthening the broader security community.

Q: How can organizations attract more people to security careers?

Organizations can attract more people by actively recruiting rather than waiting for candidates to discover the profession. The interview recommends grassroots outreach, advertising in colleges, explaining that security is a genuine career, and communicating that the work can be enjoyable and rewarding. Clear education and mentoring paths can make the profession more accessible and help interested candidates see how they can progress.

Summary & Key Takeaways

  • Connected technology is spreading through consumer life and business, from electronically controlled cars and smartphone-operated doors to ePassports and healthcare systems. This expansion makes endpoints more intelligent, increases possible entry points for attackers, and creates longer, more complicated service value chains that organizations must understand before they can manage risk effectively.

  • Security teams should not treat every connected service as equally dangerous. They must determine whether a service is noncritical or potentially life-threatening, analyze its threats, and direct limited time and staff toward the highest-risk areas. Established risk assessment and sound management principles remain applicable as connected environments continue to expand.

  • ISACA plans to strengthen the security profession through education, training, mentoring, career development, and shared good practices. Colleges and universities can supply new professionals, but the industry must actively recruit candidates, present security as a rewarding career, and help newcomers acquire useful skills quickly enough to contribute to employers and the wider community.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚