IoT Devices and “Things”

Jason Garbis, Jerry W. Chapman · Apress eBooks · 2021

Throughout this book, much of our focus has been on controlling access by authenticated entities—namely, users and servers. What they both have in common are that they’re authenticated against an identity system, have attributes or roles for context, and are using modern devices with full-featured operating systems that support the installation of third-party software. This makes these systems well suited for integration into the type of Zero Trust architectures that we’ve been discussing. Of course, these are not the only types of devices—there are billions of connected devices of entirely different types, running on lower-capability and less extensible hardware and software platforms, often referred to as Internet of Things (IoT) devices. These devices often coexist on the same enterprise networks as organizations’ most valuable resources. They are also well-known for exhibiting security vulnerabilities and representing an inviting attack surface, and should be included in any Zero Trust security architecture.

Read the paper · More papers on PaperTik