NIST IR 8259 testing
As security breaches are making the headlines of newspapers almost every week, consumers and regulators are paying more and more attention to the security of IoT devices. National governments in various regions across the world are formulating and promulgating new IoT security regulations. Improving the security of your products to meet the new and upcoming regulations such as NIST IR 8259 will help your company decrease the risk of financial cost and bad publicity associated with cyber security and data breach.
What is NIST IR 8259?
In December 2020, the IoT Cybersecurity Improvement Act became a law in USA : It mandates that all government agencies shall not obtain IoT device that doesn’t comply with NIST 8259 guideline.
This technical guide can be used for IoT products comply to with the requirements of the California and Oregon Connected Device Information Privacy Protection Act which covers:
- Device identification, as the identity of the device, to achieve management of the device (to prevent device forgery)
- Security configuration of the device. The authorized entity configures the security parameters of the device to ensure the security of the device.
- Data protection, protection of user data, security configuration data from transmission to storage, preventing data leakage/tampering
- Logical access to interface authorization, requiring authorization mechanisms to be deployed on logical interfaces to prevent unauthorized malicious access
- Software/firmware upgrades that require a secure upgrade process to prevent an attacker from performing malicious firmware/software updates on the device resulting in further network security events
- Security event log, which requires the implementation of security event log capability to implement network security events/hazards and vulnerability patch management capabilities.
Our services at a glance
Below is a quick overview of the services that TÜV SÜD provides:
- NIST 8259 Test report and AoC
- ETSI EN 303 645 testing service
- IoT basic security check
- Penetration Test & Vulnerability Scanning
- Code Review
- Data protection assessment to support your GDPR compliance
Contact us
Fill out the form on this page and we will be in touch with more details.Why is NIST IR 8259 important?
Why choose TÜV SÜD for NIST IR 8259 testing?
Your benefits at a glance
- Gain competitive edge - by certifying your products as it is critical in competing with other well-established security products have already been evaluated.
- Minimise risks - by certifying your products with a well-established cybersecurity standard such as NIST IR 8259.
- Proof of quality - by signaling to customers the cybersecurity of your products.