Technical Device Cybersecurity Capabilities Catalog

This catalog section presents IoT device technical cybersecurity capabilities that expand on the capabilities defined in NISTIR 8259A, IoT Device Cybersecurity Capability Core Baseline. The core baseline describes device capabilities needed to support common cybersecurity controls that protect an organization’s devices as well as device data, systems, and ecosystems. The core baseline provides a starting point to use in identifying IoT device cybersecurity capabilities. Device cybersecurity capabilities are cybersecurity features or functions that computing devices provide through their own technical means (i.e., device hardware and software). The seven device cybersecurity capabilities are:

This on-line catalog enumerates specific IoT device abilities associated with each of the capabilities listed above. The abilities were developed by applying an IoT focus to the security and privacy controls contained in NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations to arrive at specific ability statements. As not every ability listed here is applicable to every situation, this catalog should be viewed as a collection of abilities that can be filtered down to a profile suitable for a particular use case, industry sector, or customer organization, as described in NISTIR 8259C, Creating a Profile Using the IoT Core Baseline and Non-Technical Baseline.