Cybersecurity State Awareness

The capability to generate data indicating different types of events related to the use of the device to meet organizational requirements.

Access to Event Information

Ability to access IoT device state information. Elements that may be necessary:

Event Identification & Monitoring

Ability to provide event identification and monitoring capabilities and/or support event identification and monitoring tools interfacing with the device. Elements that may be necessary:

Event Response

Ability for the device to respond to organizationally-defined cybersecurity events in an organizationally-defined way. Elements that may be necessary:

Logging Capture & Trigger Support

Ability for the device, or an interfaced system, to generate, store, retain, delete, and report on specific device audit events, to run specific audit checks, and report findings in a variety of ways. Elements that may be necessary:

Support of Required Data Logging

Ability for the device to capture required information in audit logs.

Audit Log Storage & Retention

Ability to maintain audit logs in accordance with organizational policy.

Support for Reliable Time

Ability to use timestamps to record the time an auditing event occurred.

Audit Support & Protection

Ability for the device to support and protect audit activities and associated data.

State Awareness Support

Ability to differentiate between when a device will likely operate as expected from when it may be in a degraded cybersecurity state.