Search

DHS Release Principles For Securing Internet Of Things Amid Expanding Cyber Attack Vectors

DHS Release Principles For Securing Internet Of Things Amid Expanding Cyber Attack Vectors

The Department of Homeland Security (DHS) on Tuesday released its initial version of suggestions for embedding cyber security into the proliferating mass of internet-connected products, devices and systems commonly called the Internet of Things (IoT).

The Strategic Principles for Securing the Internet of Things, Version 1.0, provides approaches, tools and best practices to better secure these myriad products so that stakeholders can make more informed and risk-based decisions as they design, manufacture and use systems connected to the Internet.iStock Cyber Lock

“The growing dependency on network-connected technologies is outpacing the means to secure them,” Homeland Security Secretary Jeh Johnson said in a statement. “We increasingly rely on functional networks to advance life-sustaining activities, from self-driving cars to the control system that deliver water and power to our homes. Securing the Internet of Things has become a matter of homeland security.”

The 17-page document of strategic principles points to the growing importance of IoT devices in everyday life, adding that “The promise offered by IoT is almost without limit.”

The strategic principles are non-binding and essentially follow the path DHS and the Obama Administration have taken toward promoting greater cyber security awareness and practices within the federal government and privately-owned critical infrastructure by making common sense recommendations based on existing practices.

The strategic principles include incorporating security at the design phase of products and systems, provide security updates and vulnerability management throughout the life-cycle of a product, build on proven security practices, use risk models to prioritize security measures based on potential consequences, promote transparency across the IoT by enhancing awareness throughout the supply chain of potential vulnerabilities, and carefully and deliberately connect a device to the Internet.

“Today is a first step,” Robert Silvers, assistant secretary for Cyber Policy at DHS, said in a statement. “We have a rapidly closing window to ensure security is accounted for at the front end of the Internet of Things phenomenon. These principles will initiate longer-term collaboration between government and industry” resulting in a more resilient IoT.

This fall malware called Mirai was used to a large distributed denial of service attack against the cyber security blogger Brian Krebs, who hosts a popular blogging site www.krebsonsecurity.com. The Mirai botnet was found on IoT devices.



Contract Updates

BAE Systems Space & Mission Systems Inc. (Boulder, Colorado) – $48,000,000

BAE Systems Space & Mission Systems Inc., Boulder, Colorado, was awarded a $48,000,000 firm-fixed-price contract for the study, design, development, enhancement, testing, and procurement of advanced communication-electronics technologies. Bids were solicited via the internet with one received. Work locations and…


Portus Stevedoring LLC (Jacksonville, Florida) – $8,292,583

Portus Stevedoring LLC, Jacksonville, Florida, is awarded a not-to-exceed $8,292,583 firm-fixed-price, indefinite-delivery/indefinite-quantity contract with a five-year ordering period for stevedoring and related terminal services. This contract provides for full range of stevedoring and related terminal services to include the receipt,…


Foster Miller doing business as QinetiQ North America (Waltham, Massachusetts) – $11,310,230

Foster Miller, doing business as QinetiQ North America, Waltham, Massachusetts, is awarded an $11,310,230 firm-fixed-price modification to a previously awarded indefinite-delivery/indefinite-quantity contract (N00174-21-D-0019) to exercise Option Year Four for production, engineering support, and post-production support of the MK 2 Man…


EnergySolutions Services Inc. (Oak Ridge, Tennessee) – $13,336,650

EnergySolutions Services Inc., Oak Ridge, Tennessee, is being awarded a $13,336,650 firm-fixed-price, indefinite-delivery/indefinite-quantity contract action (N42158-25-D-E001) for nuclear services for the processing, recycling and disposal of radiologic materials through disassembly, decontamination, metal melting, compaction, incineration, resin sluicing/dewater, bulk waste assay…