
handle: 11588/1049804 , 11367/155783
Cyber-attacks get more sophisticated every day, potentially affecting a large number of Internet of Things (IoT) -based infrastructures and raising security and privacy concerns in consumer and business products. The EU Cybersecurity Act (CSA) first and the Cyber Resilience Act (CRA) more recently have established the pivotal role covered by a cybersecurity management encompassing the full lifecycle of products and services, and a continuous certification process. CERTIFY defines a methodological, technological, and organizational approach towards IoT security lifecycle management. To ensure security compliance throughout the device lifetime, CERTIFY designs and implements a cybersecurity lifecycle management framework for IoT devices. The framework is intended to support the device security management by collecting and sharing relevant security information both internally (via monitoring and attestation services) and externally, e.g., by interacting with device manufacturers, threat databases, certification authorities, Information Sharing and Analysis Centers (ISACs), and more. The received information is meant to support a local decision making with respect to the security monitoring, updating, and configuration of the device. Moreover, this information sharing will enable a continuous risk assessment, gathering evidence that could agile future recertifications. CERTIFY provides IoT stakeholders with mechanisms achieving high-level of security to detect and respond to a wide spectrum of attack, in a collaborative and decentralized fashion. CERTIFY will validate the architecture through cutting-edge use cases and pave the way towards innovative security in a broad spectrum of IoT environments.
Embedded systems security, Embedded systems security; Hardware security implementation; Security services; Systems security, Security services, 10009 Department of Informatics, 1705 Computer Networks and Communications, 2207 Control and Systems Engineering, 1711 Signal Processing, 000 Computer science, knowledge & systems, Hardware security implementation, Systems security, 000 Computer science, knowledge & systems
Embedded systems security, Embedded systems security; Hardware security implementation; Security services; Systems security, Security services, 10009 Department of Informatics, 1705 Computer Networks and Communications, 2207 Control and Systems Engineering, 1711 Signal Processing, 000 Computer science, knowledge & systems, Hardware security implementation, Systems security, 000 Computer science, knowledge & systems
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 1 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
