Responsibility spans manufacturers, integrators, service providers, owners, administrators, and users because a device’s security depends on capabilities and decisions distributed across the product ecosystem.
Requirements should follow purpose, exposure, data, physical effects, environment, support lifetime, and consequences of failure. Consumer baselines are starting points; industrial, medical, transport, or safety-related systems may need sector-specific engineering and assurance.
Key points
Build securable productsProvide device identity, controlled configuration, protected data and credentials, secure communications, minimized interfaces, software integrity, feasible logging, secure defaults, and safe reset or deletion.
Support the lifecycleMaintain component knowledge, publish a support period, deliver authenticated updates, receive and act on vulnerability reports, communicate changes and risks, and enable secure transfer and decommissioning.
Deploy defensiblyInventory devices and dependencies, change unsafe defaults, restrict access, segment by consequence, monitor behavior, preserve recovery options, and test changes against safety needs.
Important limitationA baseline, label, firewall, or segmented network cannot compensate for every weak device or abandoned service. Constrained hardware, unavailable updates, shared credentials, cloud dependency, and physical access may leave residual risk; untested containment or updates can create unsafe effects.