A long list of documents have been offered as security advice, codes of practice, and security guidelines for building and using security products, including Internet of Things (IoT) devices. To date, little or no systematic analysis has been carried out on the advice datasets themselves. Contributing in this direction, we begin with an informal analysis of two documents offering advice related to IoT security -- the ETSI Provisions and the UK DCMS Guidelines -- and then carry out what we believe is the first systematic analysis of these advice datasets. Our analysis explains in what ways the ETSI Provisions are a positive evolution of the UK DCMS Guidelines. We also suggest aspects of security advice that might be given special attention by those offering security advice.
翻译:已经提供了一长串文件清单,作为安全建议、业务守则以及建造和使用安全产品的安全准则,包括物联网装置,迄今为止,对咨询数据集本身几乎没有或根本没有进行系统分析,为此,我们首先非正式地分析了提供与信息技术安全有关的咨询意见的两份文件 -- -- ETSI规定和英国DCMS准则 -- -- 然后对这些咨询数据集进行了我们认为是第一次系统的分析,我们的分析解释了ETII规定如何是联合王国DCMS准则的积极演变,我们还提出了安全咨询意见的提供者可能特别注意的安保建议的各个方面。