A long list of documents have been offered as security advice, codes of practice, and security guidelines for building and using security products, including Internet of Things (IoT) devices. To date, little or no systematic analysis has been carried out on the advice datasets themselves. Towards addressing this, with IoT as a case study, we begin with an informal analysis of two documents offering advice related to IoT security -- the ETSI Provisions and the UK DCMS Guidelines -- and then carry out what we believe is the first systematic analysis of these advice datasets. Our analysis explains in what ways the ETSI Provisions are a positive evolution of the UK DCMS Guidelines. We also suggest aspects of security advice warranting special attention by those offering security advice. Such parties may find the systematic analysis method, which categorizes advice into predefined categories, to be of general interest beyond IoT itself.
翻译:已经提供了一长串文件清单,作为安全咨询、业务守则和安保指南,用于建造和使用安保产品,包括物的互联网(IoT)装置;迄今为止,对咨询数据集本身很少或没有进行系统分析;为了解决这一问题,以IoT作为案例研究,我们首先对两份提供与IoT安全有关咨询的文件 -- -- ETSI规定和英国DCMS准则 -- -- 进行非正式分析,然后进行我们认为是对这些咨询数据集的首次系统分析。我们的分析解释了ETII规定如何是联合王国DCMS准则的积极演变。我们还提出了需要提供安保咨询者特别注意的安全咨询意见的各个方面。这些当事方可能会发现系统分析方法,将咨询意见分为预先界定的类别,除IoT本身之外,还具有普遍意义。