The Department of Homeland Security (DHS) is expected to announce a set of guidelines for deploying and securing Internet of Things (IoT) devices at The Security of Things Forum in Cambridge, Massachusetts, on Thursday, according to The Security Ledger, one of the event's co-hosts.
Robert Silvers, the DHS Assistant Secretary for Digital Policy, is expected to present and take questions about a still-incomplete set of guidelines on IoT security.
“We’re thinking of everyone. Government, industry, and consumers need to take their security seriously so that it’s built into IoT devices. And we need to do it now, before we develop an entire ecosystem,” Silvers told Paul Roberts, Editor-in-Chief and Founder of The Security Ledger.
DHS has a very important role to play in the infosec community in the US and around the world, being the leader of the US Computer Emergency Readiness Team (US-CERT) and one of the main sponsors of the National Vulnerabilities Database (NVD).
DHS is not the only US government considering developing IoT security guidelines, but it certainly has the strongest voice and the largest sphere of influence.
The Food and Drug Administration (FDA) has issued guidelines to secure smart medical devices against cyberattacks, while the FTC has set out to create guidelines to secure customer privacy in IoT devices.
In the infosec community, IoT security has become a laughing stock, with new reports about insecure IoT devices coming out on a daily basis. If you're curious, today's insecure IoT device is the BT Wi-Fi Extender, after security researchers from Pen Test Partners published a report detailing its multiple vulnerabilities.
Even the Tor Project has recognized the IoT insecurity and has formed an alliance with other projects to create a technology to secure client-server communications for IoT devices using the Tor network.

