Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

NIST Lays Out Cybersecurity Guidance for Non-Technical Supporting Capabilities Related to IoT Devices

By Sheila Millar, Tracy Marshall & Anushka R. Stein on September 21, 2021
Email this postTweet this postLike this postShare this post on LinkedIn

With millions of Internet of Things (IoT) devices from phones to smart home censors flooding the market every year, effective cybersecurity to help mitigate risks to devices is vital. New guidance from The National Institute of Standards and Technology (NIST), IoT Non-Technical Supporting Capability Core Baseline (NISTIR 8259B), is intended to help manufacturers identify the non-technical capabilities they need to support device and system cybersecurity controls and to communicate with customers and third parties effectively. NISTIR 8259B is one of four documents recently released by NIST to help manufacturers and federal agencies manage cybersecurity, which include IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements (SP 800-213), Creating a Profile Using the IoT Core Baseline and Non-Technical Baseline (NISTIR 8259C), and Profile Using the IoT Core Baseline and Non-Technical Baseline for the Federal Government (NISTIR 8259D).

The guidance notes that “both device cybersecurity capabilities and non-technical supporting capabilities are vital to customers’ abilities to achieve their needs and goals.” While IoT devices are typically secured through technological capabilities, NISTIR 8259B focuses on the non-technical supporting capabilities that “that manufacturers or third parties take in support of the initial and ongoing security of IoT devices.” The guidance identifies four primary non-technical areas of cybersecurity:

  • Documentation, which ensures that customers and third parties have the information they need to ensure their device and its data are secure;
  • Information and query reception, which helps businesses respond to questions customers and others may have about a device’s security and operation;
  • Information dissemination, which ensures that customers are kept in the loop about any newly discovered security issues or device or related systems updates; and
  • Education and awareness, to assist customers and others in understanding how to secure and protect IoT software, hardware, and systems.

The guidance contains several tables that lay out detailed steps of common actions for organizations to consider taking and encourages organizations to add other non-technical capabilities where needed. NIST also updated its IoT catalog for device technical cybersecurity capabilities and supporting non-technical capabilities.

As IoT devices continue to rise in popularity, it is vital for manufacturers to ensure that their products come designed not only with effective cybersecurity technology but a plan for communicating with customers and third parties, keeping detailed records, and efficient methods for responding to questions. NISTIR 8259B gives organizations a helpful place to start, and this and other NIST guidance on IoT security may be relevant to the ongoing NIST cybersecurity labeling initiative.

 

Photo of Sheila Millar Sheila Millar

Sheila A. Millar is a partner at Keller and Heckman LLP, where she represents businesses and trade associations on a variety of public policy and regulatory issues, including privacy, data security, cybersecurity and advertising matters, as well as product safety issues. She has…

Sheila A. Millar is a partner at Keller and Heckman LLP, where she represents businesses and trade associations on a variety of public policy and regulatory issues, including privacy, data security, cybersecurity and advertising matters, as well as product safety issues. She has been involved in a variety of audit and compliance projects, including, among other issues, privacy and data security audits, and is experienced in providing crisis management legal support to a variety of national and international companies and associations.

Ms. Millar is a frequent speaker on regulatory and public policy matters, and has authored many articles. Ms. Millar is one of the vice chairs of the International Chamber of Commerce (ICC) Marketing and Advertising Commission, and chair of its Working Group on Sustainability, where she spearheaded the development of the ICC Framework Guides on Environmental Marketing Claims.

Ms. Millar is AV® PreeminentTM Rated by Martindale-Hubbell and for the eigth consecutive year was selected by her peers for inclusion in The Best Lawyers in America® 2018 for her work in practicing Advertising Law. She has also received the distinguished honor of Advertising Law “Lawyer of the Year” 2014 in Washington, DC by Best Lawyers®, and was awarded Advertising and Marketing Lawyer of the Year USA by Finance Monthly for their Finance Monthly Global Awards 2017.

Read more about Sheila MillarEmailSheila's Linkedin Profile
Show more Show less
Photo of Tracy Marshall Tracy Marshall

Tracy Marshall counsels international and domestic for-profit and non-profit clients on a range of privacy, data security, advertising, promotions, and intellectual property matters. She also advises on general corporate and transactional matters.

Tracy assists clients with compliance and advocates on their behalf. She …

Tracy Marshall counsels international and domestic for-profit and non-profit clients on a range of privacy, data security, advertising, promotions, and intellectual property matters. She also advises on general corporate and transactional matters.

Tracy assists clients with compliance and advocates on their behalf. She is a Certified Information Privacy Professional (CIPP/US) through the International Association of Privacy Professionals (IAPP) and helps clients implement privacy, data security, and security breach response programs, develop internal and public-facing privacy policies to comply with applicable laws, respond to cyber and data security incidents, and manage relationships with service providers and third parties. Tracy advises on structuring and conducting email and text messaging campaigns, sweepstakes, contests, and other promotions, and she helps clients protect and enforce their intellectual property rights.

In addition, Tracy counsels clients on corporate matters and assists with structuring and negotiating a variety of transactions, including licensing, marketing, and outsourcing arrangements.

Tracy is frequently invited to speak at privacy, data security, telecommunications, and advertising conferences and is a contributor to Keller and Heckman’s Consumer Protection Connection blog and Beyond Telecom Law Blog.


To learn more about Tracy’s practice areas, click here.
Read more about Tracy MarshallEmailTracy's Linkedin Profile
Show more Show less
Photo of Anushka R. Stein Anushka R. Stein
Read more about Anushka R. SteinEmailAnushka R.'s Linkedin Profile
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Consumer Protection Connection
  • Organization:
    Keller Heckman
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo