The use of Internet of Things (IoT) devices is growing at a rapid rate. While much of this growth is consumer devices, IoT devices are also commonly found in corporate and industrial environments, as well. These devices can be organization-owned and managed by an information technology unit, deployed organizationally without the knowledge and involvement of technology staff or brought in to the corporate environment by user-owners. In each case, these devices may have access to corporate networks and data and are, thus, important to consider as part of organizational cybersecurity risk assessment. Despite the prevalence of these devices, there is little literature about how to audit their security. This paper presents a risk-based auditing framework which can be used by both internal and external auditors, of any experience level and in any industry, to assess IoT devices.
翻译:物联网(IoT)设备的使用正在快速增长。虽然这一增长主要涉及消费类设备,但物联网设备在企业和工业环境中也普遍存在。这些设备可能由组织拥有并由信息技术部门管理,可能在技术部门不知情或未参与的情况下被组织部署,也可能由用户所有者带入企业环境。无论在哪种情况下,这些设备都可能访问企业网络和数据,因此作为组织网络安全风险评估的一部分加以考虑至关重要。尽管此类设备普遍存在,但关于如何审计其安全性的文献却很少。本文提出了一种基于风险的审计框架,可供任何经验水平、任何行业的内部和外部审计人员用于评估物联网设备。