{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T23:01:54Z","timestamp":1780527714007,"version":"3.54.1"},"reference-count":187,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2020,12,6]],"date-time":"2020-12-06T00:00:00Z","timestamp":1607212800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Spanish Ministry of Economy and Competitiveness"},{"name":"Ministry of Education and Professional Training of Spain","award":["FPU-16\/03305"],"award-info":[{"award-number":["FPU-16\/03305"]}]},{"name":"European Commission through the SerIoT project","award":["H2020-780139"],"award-info":[{"award-number":["H2020-780139"]}]},{"name":"ERDF funds cofinantiation through the PERSEIDES project","award":["TIN2017-86885-R"],"award-info":[{"award-number":["TIN2017-86885-R"]}]},{"name":"CyberSec4Europe","award":["H2020-830929"],"award-info":[{"award-number":["H2020-830929"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2021,11,30]]},"abstract":"<jats:p>In recent years, cybersecurity certification is gaining momentum as the baseline to build a structured approach to mitigate cybersecurity risks in the Internet of Things (IoT). This initiative is driven by industry, governmental institutions, and research communities, which have the goal to make IoT more secure for the end-users. In this survey, we analyze the current cybersecurity certification schemes, as well as the potential challenges to make them applicable for the IoT ecosystem. We also examine current efforts related to risk assessment and testing processes, which are widely recognized as the processes to build a cybersecurity certification framework. Our work provides a multidisciplinary perspective of a possible IoT cybersecurity certification framework by integrating research and technical tools and processes with policies and governance structures, which are analyzed against a set of identified challenges. This survey is intended to give a comprehensive overview of cybersecurity certification to facilitate the definition of a framework that fits in emerging scenarios, such as the IoT paradigm.<\/jats:p>","DOI":"10.1145\/3410160","type":"journal-article","created":{"date-parts":[[2020,12,6]],"date-time":"2020-12-06T22:23:20Z","timestamp":1607293400000},"page":"1-36","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":54,"title":["A Survey of Cybersecurity Certification for the Internet of Things"],"prefix":"10.1145","volume":"53","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-7997-5737","authenticated-orcid":false,"given":"Sara N.","family":"Matheu","sequence":"first","affiliation":[{"name":"University of Murcia, Department of Information and Communications Engineering, Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jos\u00e9 L.","family":"Hern\u00e1ndez-Ramos","sequence":"additional","affiliation":[{"name":"European Commission, Joint Research Centre, Ispra 21027, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Antonio F.","family":"Skarmeta","sequence":"additional","affiliation":[{"name":"University of Murcia, Department of Information and Communications Engineering, Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gianmarco","family":"Baldini","sequence":"additional","affiliation":[{"name":"European Commission, Joint Research Centre, Ispra 21027, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,12,6]]},"reference":[{"key":"e_1_2_2_1_1","unstructured":"European Parliament. 2016. Directive 2010\/41\/EU of the European Parliament and of the Council of 7 July 2010. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016L11488from=EN.  European Parliament. 2016. Directive 2010\/41\/EU of the European Parliament and of the Council of 7 July 2010. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016L11488from=EN."},{"key":"e_1_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.5555\/2442691.2442752"},{"key":"e_1_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.13052\/jcsm2245-1439.414"},{"key":"e_1_2_2_4_1","volume-title":"Cognitive Hyperconnected Digital Transformation: Internet of Things Intelligence Evolution","author":"Ahmad Abbas"},{"key":"e_1_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-47169-3_55"},{"key":"e_1_2_2_6_1","volume-title":"Report on Workshop on Security and Privacy in the Hyper-Connected World.","author":"AIOTI.","year":"2016"},{"key":"e_1_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/IT-DREPS.2017.8277814"},{"key":"e_1_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2444095"},{"key":"e_1_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.3390\/s18030817"},{"key":"e_1_2_2_11_1","unstructured":"Lautenbach Aljoscha and Mafijul Islam. 2016. HEAling Vulnerabilities to ENhance Software Security and Safety\u2014Project Proposal (HAVENS). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/autosec.se\/wp-content\/uploads\/2018\/03\/HEAVENS_D2_v2.0.pdf.  Lautenbach Aljoscha and Mafijul Islam. 2016. HEAling Vulnerabilities to ENhance Software Security and Safety\u2014Project Proposal (HAVENS). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/autosec.se\/wp-content\/uploads\/2018\/03\/HEAVENS_D2_v2.0.pdf."},{"key":"e_1_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00013"},{"key":"e_1_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.Workshops.2017.72"},{"key":"e_1_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS.2018.8406318"},{"key":"e_1_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2017.36"},{"key":"e_1_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ETFA.2009.5347129"},{"key":"e_1_2_2_17_1","unstructured":"ANSSI. 2008. Certification de S\u00e9curit\u00e9 de Premier Niveau (CSPN). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ssi.gouv.fr\/administration\/produits-certifies\/cspn\/.  ANSSI. 2008. Certification de S\u00e9curit\u00e9 de Premier Niveau (CSPN). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ssi.gouv.fr\/administration\/produits-certifies\/cspn\/."},{"key":"e_1_2_2_18_1","unstructured":"ANSSI. 2018. Certification de S\u00e9curit\u00e9 de Premier Niveau des Produits des Technologies de l\u2019Information. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ssi.gouv.fr\/uploads\/2015\/01\/anssi-cspn-cer-p-01-certification_de_securite_de_premier_niveau_v2.0.pdf.  ANSSI. 2018. Certification de S\u00e9curit\u00e9 de Premier Niveau des Produits des Technologies de l\u2019Information. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ssi.gouv.fr\/uploads\/2015\/01\/anssi-cspn-cer-p-01-certification_de_securite_de_premier_niveau_v2.0.pdf."},{"key":"e_1_2_2_19_1","volume-title":"Autonomic schemes for threat mitigation in Internet of Things. J. Netw. Comput. Applic. 49 (Mar","author":"Ashraf Qazi Mamoon","year":"2015"},{"key":"e_1_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2008.130"},{"key":"e_1_2_2_21_1","unstructured":"Hans Baars Robert Lassche Robin Massink and Hans Pille. 2014. Smart grid security certification in Europe. Challenges and recommendations. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.enisa.europa.eu\/publications\/smart-grid-security-certification-in-europe\/at_download\/fullReport.  Hans Baars Robert Lassche Robin Massink and Hans Pille. 2014. Smart grid security certification in Europe. Challenges and recommendations. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.enisa.europa.eu\/publications\/smart-grid-security-certification-in-europe\/at_download\/fullReport."},{"key":"e_1_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11623-014-0102-0"},{"key":"e_1_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/WF-IoT.2016.7845514"},{"key":"e_1_2_2_25_1","unstructured":"Aaron Ballman. 2016. SEI CERT C++ Coding Standard Edition: 98 Rules for Developing Safe Reliable and Secure Systems in C++. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/cysecure.org\/455\/dmccarroll\/455\/online\/WeekTwo\/Reading\/sei-cert-cpp-coding-standard-2016-v01.pdf.  Aaron Ballman. 2016. SEI CERT C++ Coding Standard Edition: 98 Rules for Developing Safe Reliable and Secure Systems in C++. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/cysecure.org\/455\/dmccarroll\/455\/online\/WeekTwo\/Reading\/sei-cert-cpp-coding-standard-2016-v01.pdf."},{"key":"e_1_2_2_26_1","volume-title":"Mark Skall, Katia Sycara, and Hideki Yoshida.","author":"Barstow Arthur","year":"2004"},{"key":"e_1_2_2_27_1","volume-title":"Formal Methods for Open Object-based Distributed Systems","author":"Bartoletti Massimo"},{"key":"e_1_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.27"},{"key":"e_1_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2011.48"},{"key":"e_1_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.159"},{"key":"e_1_2_2_31_1","unstructured":"BITAG. 2016. Internet of Things (IoT) Security and Privacy Recommendations. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.bitag.org\/documents\/BITAG_Report_-_Internet_of_Things_(IoT)_Security_and_Privacy_Recommendations.pdf.  BITAG. 2016. Internet of Things (IoT) Security and Privacy Recommendations. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.bitag.org\/documents\/BITAG_Report_-_Internet_of_Things_(IoT)_Security_and_Privacy_Recommendations.pdf."},{"key":"e_1_2_2_33_1","first-page":"2","article-title":"Evaluation of the ability of the Shodan search engine to identify Internet-facing industrial control devices","volume":"7","author":"Bodenheim Roland","year":"2014","journal-title":"Int. J. Crit. Infrast. Protect."},{"key":"e_1_2_2_34_1","volume-title":"Ben Piccarreta, and Karen Scarfone.","author":"Boeckl Katie","year":"2018"},{"key":"e_1_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2013.42"},{"key":"e_1_2_2_36_1","volume-title":"Proceedings of the 3rd International Workshop on Advances in Model-based Testing (A-MOST\u201907)","author":"Bouquet F."},{"key":"e_1_2_2_37_1","unstructured":"Josip Bozic and Franz Wotawa. 2012. Model-based testing\u2014From safety to security. In STV Bozic Wotawa. 9--16. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/graz.pure.elsevier.com\/en\/publications\/model-based-testing-from-safety-to-security.  Josip Bozic and Franz Wotawa. 2012. Model-based testing\u2014From safety to security. In STV Bozic Wotawa. 9--16. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/graz.pure.elsevier.com\/en\/publications\/model-based-testing-from-safety-to-security."},{"key":"e_1_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSTW.2014.58"},{"key":"e_1_2_2_39_1","volume-title":"Proceedings of the International Conference on Information Science and Applications, Kuinam J. Kim and Nakhoon Baek (Eds.).","volume":"514","author":"Bures Miroslav"},{"key":"e_1_2_2_40_1","volume-title":"Proceedings of the 12th International Conference on Formal Methods for the Design of Computer, Communication, and Software Systems: Formal Methods for Model-driven Engineering. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10","author":"Cabot Jordi","year":"2017"},{"key":"e_1_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/WCNCW.2018.8369033"},{"key":"e_1_2_2_42_1","volume-title":"Wilson","author":"Caralli Richard A.","year":"2007"},{"key":"e_1_2_2_43_1","unstructured":"CCRA. 2012. Common Criteria Assurance Continuity CCRA requirements. Version 2.1. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.commoncriteriaportal.org\/files\/operatingprocedures\/2012-06-01.pdf.  CCRA. 2012. Common Criteria Assurance Continuity CCRA requirements. Version 2.1. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.commoncriteriaportal.org\/files\/operatingprocedures\/2012-06-01.pdf."},{"key":"e_1_2_2_44_1","unstructured":"CCRA. 2017. Common Criteria for Information Technology Security Evaluation. Part 1: Introduction and general model.Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.commoncriteriaportal.org\/files\/ccfiles\/CCPART1V3.1R5.pdf.  CCRA. 2017. Common Criteria for Information Technology Security Evaluation. Part 1: Introduction and general model.Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.commoncriteriaportal.org\/files\/ccfiles\/CCPART1V3.1R5.pdf."},{"key":"e_1_2_2_45_1","unstructured":"CERT SEI. 2018. Android Secure Coding Standard. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/wiki.sei.cmu.edu\/confluence\/display\/android\/Android+Secure+Coding+Standard.  CERT SEI. 2018. Android Secure Coding Standard. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/wiki.sei.cmu.edu\/confluence\/display\/android\/Android+Secure+Coding+Standard."},{"key":"e_1_2_2_46_1","unstructured":"CESG. 2014. The Commercial Product Assurance (CPA) build standard. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ncsc.gov.uk\/content\/files\/protected_files\/document_files\/The%20CPA%20Build%20Standard%201.3.pdf.  CESG. 2014. The Commercial Product Assurance (CPA) build standard. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ncsc.gov.uk\/content\/files\/protected_files\/document_files\/The%20CPA%20Build%20Standard%201.3.pdf."},{"key":"e_1_2_2_47_1","volume-title":"A systematic review of fuzzing techniques. Comput. Secur. 75 (June","author":"Chen Chen","year":"2018"},{"key":"e_1_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23159"},{"key":"e_1_2_2_49_1","first-page":"448","article-title":"Ensuring interoperability for the Internet of Things: Experience with CoAP protocol testing","volume":"6","author":"Chen Nanxing","year":"2012","journal-title":"J. Contr. Meas. Electron. Comput. Commun."},{"key":"e_1_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2018.00052"},{"key":"e_1_2_2_51_1","unstructured":"Brian Chess and Jabob West. 2007. Secure Programming with Static Analysis. Gary McGraw. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.e-reading.club\/bookreader.php\/142130\/Secure_programming_with_Static_Analysis.pdf.  Brian Chess and Jabob West. 2007. Secure Programming with Static Analysis. Gary McGraw. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.e-reading.club\/bookreader.php\/142130\/Secure_programming_with_Static_Analysis.pdf."},{"key":"e_1_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2866423"},{"key":"e_1_2_2_53_1","volume-title":"Sam Kee, Moritz Jan Kleinaltenkamp, Thanel Voigt, and Antonio Rosato.","author":"Cihon Peter","year":"2018"},{"key":"e_1_2_2_55_1","unstructured":"CNSSI. 2015. CNSSI No. 4009: Committee on National Security Systems (CNSS) Glossary. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/cryptosmith.files.wordpress.com\/2015\/08\/glossary-2015-cnss.pdf.  CNSSI. 2015. CNSSI No. 4009: Committee on National Security Systems (CNSS) Glossary. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/cryptosmith.files.wordpress.com\/2015\/08\/glossary-2015-cnss.pdf."},{"key":"e_1_2_2_56_1","unstructured":"Common Criteria. 2014. Arrangement on the Recognition of Common Criteria Certificates in the field of Information Technology Security. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.commoncriteriaportal.org\/files\/operatingprocedures\/cc-recarrange.pdf.  Common Criteria. 2014. Arrangement on the Recognition of Common Criteria Certificates in the field of Information Technology Security. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.commoncriteriaportal.org\/files\/operatingprocedures\/cc-recarrange.pdf."},{"key":"e_1_2_2_57_1","unstructured":"Andrei Costin Jonas Zaddach Aur\u00e9lien Francillon and Davide Balzarotti. 2014. A large-scale analysis of the security of embedded firmwares. 95--110. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/node\/184450.  Andrei Costin Jonas Zaddach Aur\u00e9lien Francillon and Davide Balzarotti. 2014. A large-scale analysis of the security of embedded firmwares. 95--110. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/node\/184450."},{"key":"e_1_2_2_58_1","unstructured":"Antoine Coutant. 2016. French Scheme CSPN to CC evaluation. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.yourcreativesolutions.nl\/ICCC13\/p\/CC%20and%20New%20Techniques\/Antoine%20COUTANT%20-%20CSPN%20to%20CC%20Evaluation.pdf.  Antoine Coutant. 2016. French Scheme CSPN to CC evaluation. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.yourcreativesolutions.nl\/ICCC13\/p\/CC%20and%20New%20Techniques\/Antoine%20COUTANT%20-%20CSPN%20to%20CC%20Evaluation.pdf."},{"key":"e_1_2_2_59_1","volume-title":"Proceedings of the Doctoral Symposium (ICRAT\u201918)","author":"Cretin Aymeric","year":"2018"},{"key":"e_1_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1002\/stvr.1627"},{"key":"e_1_2_2_61_1","unstructured":"CTIA. 2018. Cybersecurity Certification Test Plan for IoT Devices. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/api.ctia.org\/wp-content\/uploads\/2018\/08\/CTIA-IoT-Cybersecurity-Certification-Test-Plan-V1_0.pdf.  CTIA. 2018. Cybersecurity Certification Test Plan for IoT Devices. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/api.ctia.org\/wp-content\/uploads\/2018\/08\/CTIA-IoT-Cybersecurity-Certification-Test-Plan-V1_0.pdf."},{"key":"e_1_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1155\/2014\/762891"},{"key":"e_1_2_2_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSTW.2018.00035"},{"key":"e_1_2_2_65_1","unstructured":"ECSO. 2017. A Meta-Scheme Approach v1.0. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.ecs-org.eu\/documents\/uploads\/european-cyber-security-certification-a-meta-scheme-approach.pdf.  ECSO. 2017. A Meta-Scheme Approach v1.0. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.ecs-org.eu\/documents\/uploads\/european-cyber-security-certification-a-meta-scheme-approach.pdf."},{"key":"e_1_2_2_66_1","unstructured":"ECSO. 2017. State of the Art Syllabus v2. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.ecs-org.eu\/documents\/uploads\/updated-sota.pdf.  ECSO. 2017. State of the Art Syllabus v2. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.ecs-org.eu\/documents\/uploads\/updated-sota.pdf."},{"key":"e_1_2_2_67_1","unstructured":"ENISA. 2018. Overview of ICT certification laboratories. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.european-accreditation.org\/brochure\/document-ict-certification-laboratories.  ENISA. 2018. Overview of ICT certification laboratories. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.european-accreditation.org\/brochure\/document-ict-certification-laboratories."},{"key":"e_1_2_2_68_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10009-014-0330-5"},{"key":"e_1_2_2_69_1","volume-title":"ETSI EG 203 251: Methods for Testing 8 Specification","author":"ETSI.","year":"2032"},{"key":"e_1_2_2_70_1","unstructured":"European Commission. 2010. Directive 2010\/30\/EU on the indication by labelling and standard product information of the consumption of energy and other resources by energy-related products. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32010L0030.  European Commission. 2010. Directive 2010\/30\/EU on the indication by labelling and standard product information of the consumption of energy and other resources by energy-related products. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32010L0030."},{"key":"e_1_2_2_71_1","unstructured":"European Parliament. 2016. REGULATION (EU) 2016\/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95\/46\/EC (General Data Protection Regulation). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/eugdpr.org\/.  European Parliament. 2016. REGULATION (EU) 2016\/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95\/46\/EC (General Data Protection Regulation). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/eugdpr.org\/."},{"key":"e_1_2_2_72_1","unstructured":"EVITA. 2008. E-Safety Vehicle Intrusion Protected Applications. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.evita-project.org\/.  EVITA. 2008. E-Safety Vehicle Intrusion Protected Applications. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.evita-project.org\/."},{"key":"e_1_2_2_73_1","unstructured":"Michael Felderer Berthold Agreiter Philipp Zech and Ruth Breu. 2011. A classification for model-based security testing. 109--114. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.thinkmind.org\/index.php?view=article8articleid=valid_2011_5_10_40020.  Michael Felderer Berthold Agreiter Philipp Zech and Ruth Breu. 2011. A classification for model-based security testing. 109--114. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.thinkmind.org\/index.php?view=article8articleid=valid_2011_5_10_40020."},{"key":"e_1_2_2_74_1","doi-asserted-by":"crossref","unstructured":"Michael Felderer Matthias B\u00fcchler Martin Johns Achim D. Brucker Ruth Breu and Alexander Pretschner. 2015. Chapter one - Security testing: A survey. In Advances in Computers. Vol. 101. Elsevier 1--51. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/bs.adcom.2015.11.003  Michael Felderer Matthias B\u00fcchler Martin Johns Achim D. Brucker Ruth Breu and Alexander Pretschner. 2015. Chapter one - Security testing: A survey. In Advances in Computers. Vol. 101. Elsevier 1--51. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/bs.adcom.2015.11.003","DOI":"10.1016\/bs.adcom.2015.11.003"},{"key":"e_1_2_2_75_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10009-015-0365-2"},{"key":"e_1_2_2_76_1","first-page":"5","article-title":"A taxonomy of risk-based testing","volume":"16","author":"Felderer Michael","year":"2014","journal-title":"Int. J. Softw. Tools Technol. Transf."},{"key":"e_1_2_2_77_1","unstructured":"FIRST. 2015. Common Vulnerability Score System (CVSS) v3. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.first.org\/cvss\/cvss-v30-specification-v1.8.pdf.  FIRST. 2015. Common Vulnerability Score System (CVSS) v3. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.first.org\/cvss\/cvss-v30-specification-v1.8.pdf."},{"key":"e_1_2_2_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSTW.2011.95"},{"key":"e_1_2_2_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICNSURV.2018.8384911"},{"key":"e_1_2_2_80_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2017.01.033"},{"key":"e_1_2_2_81_1","volume-title":"Proceedings of the IEEE 21st International Conference on Parallel and Distributed Systems (ICPADS\u201915)","author":"Ge Mengmeng","year":"2015"},{"key":"e_1_2_2_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2863244"},{"key":"e_1_2_2_83_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2388550"},{"key":"e_1_2_2_84_1","volume-title":"A taxonomy to assess and tailor risk-based testing in recent testing standards","author":"Grossmann Jurgen","year":"2019"},{"key":"e_1_2_2_85_1","unstructured":"GSMA. 2016. IoT Security Guidelines Overview Document. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.gsma.com\/iot\/wp-content\/uploads\/2016\/02\/CLP.11-v1.1.pdf.  GSMA. 2016. IoT Security Guidelines Overview Document. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.gsma.com\/iot\/wp-content\/uploads\/2016\/02\/CLP.11-v1.1.pdf."},{"key":"e_1_2_2_86_1","volume-title":"Theophilus A. Benson, Matthew Roughan, and Vijay Sivaraman.","author":"Hamza Ayyoob","year":"2019"},{"key":"e_1_2_2_87_1","doi-asserted-by":"publisher","DOI":"10.1145\/3220162.3220170"},{"key":"e_1_2_2_88_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2004.1264857"},{"key":"e_1_2_2_89_1","volume-title":"Proceedings of the 4th International Conference on Wireless Mobile Communication and Healthcare\u2014Transforming Healthcare through Innovations in Mobile and Wireless Technologies (MOBIHEALTH\u201914)","author":"Hiremath S.","year":"2014"},{"key":"e_1_2_2_90_1","unstructured":"Juliane Hubner and Maria Lastovka. 2017. BOSCH Political Viewpoint. Security in IoT. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.boschsecurity.com\/xc\/en\/news\/rethink-the-magazine\/winds-of-change\/.  Juliane Hubner and Maria Lastovka. 2017. BOSCH Political Viewpoint. Security in IoT. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.boschsecurity.com\/xc\/en\/news\/rethink-the-magazine\/winds-of-change\/."},{"key":"e_1_2_2_91_1","unstructured":"ICSA. 2016. ICSA Labs IoT Security and Privacy. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.icsalabs.com\/technology-program\/iot-devices-sensors\/iot-device-requirements-framework.  ICSA. 2016. ICSA Labs IoT Security and Privacy. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.icsalabs.com\/technology-program\/iot-devices-sensors\/iot-device-requirements-framework."},{"key":"e_1_2_2_92_1","unstructured":"ICSA. 2016. Internet of Things (IoT) Security Testing Framework. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.icsalabs.com\/sites\/default\/files\/body_images\/ICSALABS_IoT_reqts_framework_v2.0_161026.pdf.  ICSA. 2016. Internet of Things (IoT) Security Testing Framework. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.icsalabs.com\/sites\/default\/files\/body_images\/ICSALABS_IoT_reqts_framework_v2.0_161026.pdf."},{"key":"e_1_2_2_93_1","unstructured":"Information Technology Promotion Agency (IPA). 2019. Japan Information Technology Security Evaluation and Certification Scheme. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ipa.go.jp\/security\/jisec\/jisec_e\/.  Information Technology Promotion Agency (IPA). 2019. Japan Information Technology Security Evaluation and Certification Scheme. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ipa.go.jp\/security\/jisec\/jisec_e\/."},{"key":"e_1_2_2_94_1","unstructured":"IoT Security Fundation. 2017. IoT Security Compliance Framework. Release 1.1. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.iotsecurityfoundation.org\/wp-content\/uploads\/2017\/12\/IoT-Security-Compliance-Framework_WG1_2017.pdf.  IoT Security Fundation. 2017. IoT Security Compliance Framework. Release 1.1. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.iotsecurityfoundation.org\/wp-content\/uploads\/2017\/12\/IoT-Security-Compliance-Framework_WG1_2017.pdf."},{"key":"e_1_2_2_95_1","unstructured":"ISO. 2018. Information technology\u2014Internet of Things (IoT)\u2014Vocabulary (ISO\/IEC 20924:2018). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.iso.org\/cms\/render\/live\/en\/sites\/isoorg\/contents\/data\/standard\/06\/94\/69470.html.  ISO. 2018. Information technology\u2014Internet of Things (IoT)\u2014Vocabulary (ISO\/IEC 20924:2018). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.iso.org\/cms\/render\/live\/en\/sites\/isoorg\/contents\/data\/standard\/06\/94\/69470.html."},{"key":"e_1_2_2_96_1","volume-title":"A risk analysis of a smart home automation system. Fut. Gen. Comput. Syst. 56 (Mar","author":"Jacobsson Andreas","year":"2016"},{"key":"e_1_2_2_99_1","volume-title":"Trust, Privacy, and Security in Digital Business.","author":"Kaluvuri Samuel Paul"},{"key":"e_1_2_2_100_1","doi-asserted-by":"publisher","DOI":"10.1109\/WiMOB.2013.6673419"},{"key":"e_1_2_2_101_1","volume-title":"Proceedings of the IEEE 9th International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob\u201913)","volume":"16","author":"Kasinathan Prabhakaran"},{"key":"e_1_2_2_102_1","unstructured":"Kaspersky. 2017. Kaspersky Labs Targeted Attacks Detection Solution Is Certified by ICSA Labs. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.kaspersky.com\/about\/press-releases\/2017_targeted-attacks-detection-solution-certified-by-icsa-labs.  Kaspersky. 2017. Kaspersky Labs Targeted Attacks Detection Solution Is Certified by ICSA Labs. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.kaspersky.com\/about\/press-releases\/2017_targeted-attacks-detection-solution-certified-by-icsa-labs."},{"key":"e_1_2_2_103_1","first-page":"2","article-title":"Applying the common criteria in systems engineering","volume":"4","author":"Keblawi F.","year":"2006","journal-title":"IEEE Secur. Priv. Mag."},{"key":"e_1_2_2_104_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.201"},{"key":"e_1_2_2_105_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2015.7102627"},{"key":"e_1_2_2_106_1","volume-title":"Internet of Things, Smart Spaces, and Next Generation Networks and Systems (Lecture Notes in Computer Science)","author":"Kuzminykh Ievgeniia"},{"key":"e_1_2_2_107_1","doi-asserted-by":"publisher","DOI":"10.1109\/DCOSS.2012.48"},{"key":"e_1_2_2_108_1","doi-asserted-by":"crossref","unstructured":"Eliot Lear Dan Romascanu and Ralph Droms. 2019. Manufacturer Usage Description Specification (RFC 8520). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/tools.ietf.org\/html\/rfc8520.  Eliot Lear Dan Romascanu and Ralph Droms. 2019. Manufacturer Usage Description Specification (RFC 8520). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/tools.ietf.org\/html\/rfc8520.","DOI":"10.17487\/RFC8520"},{"key":"e_1_2_2_109_1","volume-title":"Game theory-based security vulnerability quantification for social Internet of Things. Fut. Gen. Comput. Syst. 82 (May","author":"Lee Seokcheol","year":"2018"},{"key":"e_1_2_2_110_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2013.55"},{"key":"e_1_2_2_111_1","volume-title":"Franck Le Gall, and Naum Spaseski","author":"Li Wenbin","year":"2018"},{"key":"e_1_2_2_112_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICNC.2012.6234533"},{"key":"e_1_2_2_113_1","volume-title":"Seacord","author":"Long Fred","year":"2011"},{"key":"e_1_2_2_114_1","article-title":"Toward a methodology for unified verification of hardware\/software co-designs","author":"Lugou Florian","year":"2016","journal-title":"J. Cryptog. Eng."},{"key":"e_1_2_2_115_1","volume-title":"Ren Ping Liu, and Wei Ni","author":"Makhdoom Imran","year":"2018"},{"key":"e_1_2_2_116_1","unstructured":"Mark Miller. 2018. D3.2 European cybersecurity and privacy Research and Innovation Ecosystem. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.cyberwatching.eu\/sites\/default\/files\/D3.2_European_cybersecurity_and_privacy_Research_%26Innovation_Ecosystem.pdf.  Mark Miller. 2018. D3.2 European cybersecurity and privacy Research and Innovation Ecosystem. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.cyberwatching.eu\/sites\/default\/files\/D3.2_European_cybersecurity_and_privacy_Research_%26Innovation_Ecosystem.pdf."},{"key":"e_1_2_2_117_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2019.2904475"},{"key":"e_1_2_2_118_1","volume-title":"Proceedings of the IEEE 4th World Forum on Internet of Things (WF-IoT\u201918)","author":"Matheu-Garcia Sara N.","year":"2018"},{"key":"e_1_2_2_119_1","volume-title":"Risk-based automated assessment and testing for the cybersecurity certification and labelling of IoT devices. Comput. Stand. Interf. 62 (Feb","author":"Matheu-Garcia Sara N.","year":"2019"},{"key":"e_1_2_2_120_1","volume-title":"Exploit Development, and Vulnerability Research","author":"Maynor David"},{"key":"e_1_2_2_121_1","first-page":"2","article-title":"Software security","volume":"2","author":"Mcgraw G.","year":"2004","journal-title":"IEEE Secur. Priv. Mag."},{"key":"e_1_2_2_122_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.icte.2017.12.005"},{"key":"e_1_2_2_123_1","volume-title":"Proceedings of the Brazilian Symposium on Information Security and Computer Systems. 533--540","author":"Melo Bruno"},{"key":"e_1_2_2_124_1","unstructured":"Microsoft. 2018. The STRIDE Threat Model. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/msdn.microsoft.com\/en-us\/library\/ee823878(v=cs.20).aspx.  Microsoft. 2018. The STRIDE Threat Model. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/msdn.microsoft.com\/en-us\/library\/ee823878(v=cs.20).aspx."},{"key":"e_1_2_2_125_1","unstructured":"Microsoft. 2010. DREAD scheme. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/docs.microsoft.com\/en-us\/previous-versions\/msp-n-p\/ff648644(v=pandp.10)#dread.  Microsoft. 2010. DREAD scheme. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/docs.microsoft.com\/en-us\/previous-versions\/msp-n-p\/ff648644(v=pandp.10)#dread."},{"key":"e_1_2_2_126_1","unstructured":"Charlie Miller and Zachary Peterson. 2007. Analysis of mutation and generation-based fuzzing. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/mirror.picosecond.org\/defcon\/defcon15-cd\/Speakers\/Miller\/Whitepaper\/dc-15-miller-WP.pdf.  Charlie Miller and Zachary Peterson. 2007. Analysis of mutation and generation-based fuzzing. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/mirror.picosecond.org\/defcon\/defcon15-cd\/Speakers\/Miller\/Whitepaper\/dc-15-miller-WP.pdf."},{"key":"e_1_2_2_127_1","unstructured":"MITRE. 2011. Common Weakness Risk Analysis Framework (CWRAF). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/cwe.mitre.org\/cwraf\/.  MITRE. 2011. Common Weakness Risk Analysis Framework (CWRAF). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/cwe.mitre.org\/cwraf\/."},{"key":"e_1_2_2_128_1","unstructured":"MITRE. 2014. CWE\u2014Common Weakness Scoring System (CWSS). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/cwe.mitre.org\/cwss\/cwss_v1.0.1.html.  MITRE. 2014. CWE\u2014Common Weakness Scoring System (CWSS). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/cwe.mitre.org\/cwss\/cwss_v1.0.1.html."},{"key":"e_1_2_2_129_1","doi-asserted-by":"publisher","DOI":"10.1145\/3159450.3162228"},{"key":"e_1_2_2_130_1","unstructured":"K. Moore R. Barnes and H. Tschofenig. 2016. Best Current Practices for Securing Internet of Things (IoT) Devices. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/tools.ietf.org\/html\/draft-moore-iot-security-bcp-00.  K. Moore R. Barnes and H. Tschofenig. 2016. Best Current Practices for Securing Internet of Things (IoT) Devices. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/tools.ietf.org\/html\/draft-moore-iot-security-bcp-00."},{"key":"e_1_2_2_131_1","doi-asserted-by":"publisher","DOI":"10.1145\/1278972.1278992"},{"key":"e_1_2_2_132_1","first-page":"2","article-title":"Design and implementation of fuzzing framework based on IoT applications","volume":"93","author":"Munea Tewodros Legesse","year":"2017","journal-title":"Wirel. Person. Commun."},{"key":"e_1_2_2_133_1","first-page":"1","article-title":"How certification systems fail: Lessons from the ware report","volume":"10","author":"Murdoch Steven","year":"2012","journal-title":"IEEE Secur. Priv. Mag."},{"key":"e_1_2_2_134_1","unstructured":"National Cybersecurity Center of United Kingdom. 2017. Foundation Grade explained. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ncsc.gov.uk\/articles\/foundation-grade-explained.  National Cybersecurity Center of United Kingdom. 2017. Foundation Grade explained. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ncsc.gov.uk\/articles\/foundation-grade-explained."},{"key":"e_1_2_2_135_1","unstructured":"National Cybersecurity Center (UK). 2016. CPA SC Overwriting Tools for Magnetic Media v2-1. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ncsc.gov.uk\/content\/files\/protected_files\/document_files\/CPA%20SC%20Overwriting%20Tools%20for%20Magnetic%20Media%20v2-1.pdf.  National Cybersecurity Center (UK). 2016. CPA SC Overwriting Tools for Magnetic Media v2-1. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ncsc.gov.uk\/content\/files\/protected_files\/document_files\/CPA%20SC%20Overwriting%20Tools%20for%20Magnetic%20Media%20v2-1.pdf."},{"key":"e_1_2_2_136_1","unstructured":"National Cybersecurity Centre (UK). 2016. Process for performing commercial product assurance foundation grade evaluations. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ncsc.gov.uk\/content\/files\/protected_files\/document_files\/Process%20for%20Performing%20CPA%20Foundation%20Grade%20Evaluations%202-4.pdf.  National Cybersecurity Centre (UK). 2016. Process for performing commercial product assurance foundation grade evaluations. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.ncsc.gov.uk\/content\/files\/protected_files\/document_files\/Process%20for%20Performing%20CPA%20Foundation%20Grade%20Evaluations%202-4.pdf."},{"key":"e_1_2_2_137_1","unstructured":"NCC Group. 2016. Commercial Product Assurance and Common Criteria. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.nccgroup.trust\/uk\/our-services\/cyber-security\/compliance-and-accreditations\/cpa-and-cc\/.  NCC Group. 2016. Commercial Product Assurance and Common Criteria. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.nccgroup.trust\/uk\/our-services\/cyber-security\/compliance-and-accreditations\/cpa-and-cc\/."},{"key":"e_1_2_2_138_1","unstructured":"NCC Group. 2007. CERT C Programming Language Secure Coding Standard. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.open-std.org\/jtc1\/sc22\/wg14\/www\/docs\/n1255.pdf.  NCC Group. 2007. CERT C Programming Language Secure Coding Standard. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.open-std.org\/jtc1\/sc22\/wg14\/www\/docs\/n1255.pdf."},{"key":"e_1_2_2_139_1","unstructured":"NCC Group. 2016. Threat prioritisation: DREAD is dead baby?Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.nccgroup.trust\/uk\/about-us\/newsroom-and-events\/blogs\/2016\/march\/threat-prioritisation-dread-is-dead-baby\/.  NCC Group. 2016. Threat prioritisation: DREAD is dead baby?Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.nccgroup.trust\/uk\/about-us\/newsroom-and-events\/blogs\/2016\/march\/threat-prioritisation-dread-is-dead-baby\/."},{"key":"e_1_2_2_140_1","doi-asserted-by":"publisher","DOI":"10.1109\/GIOTS.2017.8016273"},{"key":"e_1_2_2_141_1","volume-title":"Igor Nai Fovino, and Gianmarco Baldini","author":"Neisse Ricardo","year":"2015"},{"key":"e_1_2_2_142_1","unstructured":"NIST. 2019. Glossary of Key Information Security Terms. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.nist.gov\/publications\/glossary-key-information-security-terms-2.  NIST. 2019. Glossary of Key Information Security Terms. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.nist.gov\/publications\/glossary-key-information-security-terms-2."},{"key":"e_1_2_2_143_1","unstructured":"NIST. 2006. FIPS 200 Minimum Security Requirements for Federal Information and Information Systems. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/csrc.nist.gov\/publications\/detail\/fips\/200\/final.  NIST. 2006. FIPS 200 Minimum Security Requirements for Federal Information and Information Systems. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/csrc.nist.gov\/publications\/detail\/fips\/200\/final."},{"key":"e_1_2_2_144_1","unstructured":"NIST. 2014. Framework for Improving Critical Infrastructure Cybersecurity Version 1.0. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/nvlpubs.nist.gov\/nistpubs\/CSWP\/NIST.CSWP.04162018.pdf.  NIST. 2014. Framework for Improving Critical Infrastructure Cybersecurity Version 1.0. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/nvlpubs.nist.gov\/nistpubs\/CSWP\/NIST.CSWP.04162018.pdf."},{"key":"e_1_2_2_146_1","unstructured":"NIST. 2018. Risk Management Framework for Information Systems and Organizations. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/csrc.nist.gov\/CSRC\/media\/Publications\/sp\/800-37\/rev-2\/draft\/documents\/sp800-37r2-draft-fpd.pdf.  NIST. 2018. Risk Management Framework for Information Systems and Organizations. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/csrc.nist.gov\/CSRC\/media\/Publications\/sp\/800-37\/rev-2\/draft\/documents\/sp800-37r2-draft-fpd.pdf."},{"key":"e_1_2_2_147_1","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2017.3680959"},{"key":"e_1_2_2_148_1","volume-title":"Vulnerability Detection and Resolution in Internet of Things (IoT) Devices. Master Thesis","author":"Ogunnaike Ruth Motunrayo"},{"key":"e_1_2_2_149_1","first-page":"1","article-title":"Threat modeling of Internet of Things health devices","volume":"14","author":"Omotosho Adebayo","year":"2019","journal-title":"J. Appl. Secur. Res."},{"key":"e_1_2_2_150_1","unstructured":"Online Trust Alliance. 2017. IoT Security 8 Privacy Trust Framework v2.5. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/otalliance.org\/system\/files\/files\/initiative\/documents\/iot_trust_framework6-22.pdf.  Online Trust Alliance. 2017. IoT Security 8 Privacy Trust Framework v2.5. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/otalliance.org\/system\/files\/files\/initiative\/documents\/iot_trust_framework6-22.pdf."},{"key":"e_1_2_2_151_1","unstructured":"Openstack. 2014. Security\/OSSA-Metrics. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/wiki.openstack.org\/wiki\/Security\/OSSA-Metrics#Calibration.  Openstack. 2014. Security\/OSSA-Metrics. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/wiki.openstack.org\/wiki\/Security\/OSSA-Metrics#Calibration."},{"key":"e_1_2_2_152_1","unstructured":"OWASP. [n.d.]. OWASP Application Security Verification Standard (ASVS) Project. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.owasp.org\/index.php\/OWASP_Risk_Rating_Methodology.  OWASP. [n.d.]. OWASP Application Security Verification Standard (ASVS) Project. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.owasp.org\/index.php\/OWASP_Risk_Rating_Methodology."},{"key":"e_1_2_2_153_1","unstructured":"Euopean Parliament. 2019. Regulation (EU) 2019\/881 of the European Parliament and of the council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification (Cybersecurity Act). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32019R08818from=EN.  Euopean Parliament. 2019. Regulation (EU) 2019\/881 of the European Parliament and of the council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification (Cybersecurity Act). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32019R08818from=EN."},{"key":"e_1_2_2_154_1","unstructured":"J. M. Porup. 2016. Underwriters Labs refuses to share new IoT cybersecurity standard. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arstechnica.com\/information-technology\/2016\/04\/underwriters-labs-refuses-to-share-new-iot-cybersecurity-standard\/.  J. M. Porup. 2016. Underwriters Labs refuses to share new IoT cybersecurity standard. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arstechnica.com\/information-technology\/2016\/04\/underwriters-labs-refuses-to-share-new-iot-cybersecurity-standard\/."},{"key":"e_1_2_2_155_1","volume-title":"Proceedings of the IEEE 2nd International Conference on Big Data Security on Cloud (BigDataSecurity)","author":"Qu Yanzhen"},{"key":"e_1_2_2_156_1","volume-title":"Rafael Mantilla Montalvo, and Peter Burnap","author":"Radanliev Petar","year":"2019"},{"key":"e_1_2_2_157_1","unstructured":"RASEN project. 2015. D3.2.3. Techniques for Compositional Test-Based Security Risk Assessment v.3. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.rasenproject.eu\/downloads\/985\/.  RASEN project. 2015. D3.2.3. Techniques for Compositional Test-Based Security Risk Assessment v.3. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.rasenproject.eu\/downloads\/985\/."},{"key":"e_1_2_2_158_1","doi-asserted-by":"publisher","DOI":"10.1145\/3055245.3055251"},{"key":"e_1_2_2_159_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISDFS.2017.7916496"},{"key":"e_1_2_2_160_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSTW.2013.61"},{"key":"e_1_2_2_161_1","volume-title":"CERT C Coding Standard","author":"Seacord Robert C."},{"key":"e_1_2_2_162_1","unstructured":"SEI CERT. 2016. Coding Standards. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/wiki.sei.cmu.edu\/confluence\/display\/seccode\/SEI+CERT+Coding+Standards.  SEI CERT. 2016. Coding Standards. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/wiki.sei.cmu.edu\/confluence\/display\/seccode\/SEI+CERT+Coding+Standards."},{"key":"e_1_2_2_163_1","unstructured":"SEI CERT. [n.d.]. SEI CERT Perl Coding Standard. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/wiki.sei.cmu.edu\/confluence\/display\/perl.  SEI CERT. [n.d.]. SEI CERT Perl Coding Standard. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/wiki.sei.cmu.edu\/confluence\/display\/perl."},{"key":"e_1_2_2_164_1","volume-title":"Taxonomy of information security risk assessment (ISRA). Comput. Secur. 57 (Mar","author":"Shameli-Sendi Alireza","year":"2016"},{"key":"e_1_2_2_165_1","doi-asserted-by":"crossref","unstructured":"Z. Shelby K. Hartke and C. Bormann. 2014. The Constrained Application Protocol (CoAP) (RFC7252). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/tools.ietf.org\/html\/rfc7252.  Z. Shelby K. Hartke and C. Bormann. 2014. The Constrained Application Protocol (CoAP) (RFC7252). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/tools.ietf.org\/html\/rfc7252.","DOI":"10.17487\/rfc7252"},{"key":"e_1_2_2_166_1","volume-title":"Proceedings of the IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS\u201917)","author":"Shivraj V. L.","year":"2017"},{"key":"e_1_2_2_167_1","volume-title":"A risk assessment methodology for the Internet of Things. Comput. Commun. 129 (Sept","author":"Sicari Sabrina","year":"2018"},{"key":"e_1_2_2_169_1","unstructured":"International Organization for Standardization. 2018. ISO\/IEC 31000 - Risk Management. IEC. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.iso.org\/iso-31000-risk-management.html.  International Organization for Standardization. 2018. ISO\/IEC 31000 - Risk Management. IEC. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.iso.org\/iso-31000-risk-management.html."},{"key":"e_1_2_2_170_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10009-013-0278-x"},{"key":"e_1_2_2_171_1","volume-title":"Fuzzing\u2014Brute force vulnerability discovery","author":"Sutton Michael"},{"key":"e_1_2_2_172_1","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991085"},{"key":"e_1_2_2_173_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2017.32"},{"key":"e_1_2_2_174_1","doi-asserted-by":"publisher","DOI":"10.1109\/MTS.2016.2527078"},{"key":"e_1_2_2_175_1","volume-title":"Proceedings of the Future Network and Mobile Summit.","author":"Tonjes Ralf","year":"2012"},{"key":"e_1_2_2_176_1","doi-asserted-by":"publisher","DOI":"10.1109\/IWAST.2012.6228985"},{"key":"e_1_2_2_177_1","unstructured":"Underwriters Laboratories. 2017. UL 2900 Standards Process. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/industries.ul.com\/cybersecurity\/ul-2900-standards-process.  Underwriters Laboratories. 2017. UL 2900 Standards Process. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/industries.ul.com\/cybersecurity\/ul-2900-standards-process."},{"key":"e_1_2_2_178_1","volume-title":"Software Cybersecurity for Network-Connectable Products, Part 2-1: Particular Requirements for Network Connectable Components of Healthcare and Wellness Systems.","author":"Underwriters Laboratories"},{"key":"e_1_2_2_179_1","doi-asserted-by":"publisher","DOI":"10.1145\/3055386.3055397"},{"key":"e_1_2_2_180_1","unstructured":"VERACODE. 2006. VerAfied Methodology. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/help.veracode.com\/reader\/kJC1iOtXp8N rCtV8P9jhw\/UQa oUCwYhluVREDo4480g.  VERACODE. 2006. VerAfied Methodology. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/help.veracode.com\/reader\/kJC1iOtXp8N rCtV8P9jhw\/UQa oUCwYhluVREDo4480g."},{"key":"e_1_2_2_181_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2013.82"},{"key":"e_1_2_2_182_1","doi-asserted-by":"publisher","DOI":"10.1109\/TENCON.2017.8228241"},{"key":"e_1_2_2_183_1","volume-title":"Laplante","author":"Voas Jeffrey","year":"2018"},{"key":"e_1_2_2_184_1","doi-asserted-by":"crossref","unstructured":"Dong Wang Xiaosong Zhang Ting Chen and Jingwei Li. 2019. Discovering Vulnerabilities in COTS IoT Devices through Blackbox Fuzzing Web Management Interface. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1155\/2019\/5076324  Dong Wang Xiaosong Zhang Ting Chen and Jingwei Li. 2019. Discovering Vulnerabilities in COTS IoT Devices through Blackbox Fuzzing Web Management Interface. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1155\/2019\/5076324","DOI":"10.1155\/2019\/5076324"},{"key":"e_1_2_2_185_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2805690"},{"key":"e_1_2_2_186_1","first-page":"15","article-title":"Automated vulnerability discovery and exploitation in the Internet of Things","volume":"19","author":"Wang Zhongru","year":"2019","journal-title":"Sensors"},{"key":"e_1_2_2_187_1","unstructured":"Weibull. 2004. Basic concepts of FMEA and FMECA. ([n.d.]). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.weibull.com\/hotwire\/issue46\/relbasics46.htm.  Weibull. 2004. Basic concepts of FMEA and FMECA. ([n.d.]). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/http\/www.weibull.com\/hotwire\/issue46\/relbasics46.htm."},{"key":"e_1_2_2_188_1","doi-asserted-by":"publisher","DOI":"10.1109\/INCIT.2017.8257865"},{"key":"e_1_2_2_189_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11859-014-1031-3"},{"key":"e_1_2_2_190_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2012.24"},{"key":"e_1_2_2_191_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2734681"},{"key":"e_1_2_2_192_1","doi-asserted-by":"publisher","DOI":"10.1109\/SERE-C.2013.11"},{"key":"e_1_2_2_193_1","doi-asserted-by":"publisher","DOI":"10.1002\/stv.430"},{"key":"e_1_2_2_194_1","unstructured":"Yaowen Zheng Ali Davanian Heng Yin Chengyu Song Hongsong Zhu and Limin Sun. 2019. FIRM-AFL\u2014High-throughput greybox fuzzing of IoT firmware via augmented process emulation. 1099--1114. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/zheng.  Yaowen Zheng Ali Davanian Heng Yin Chengyu Song Hongsong Zhu and Limin Sun. 2019. FIRM-AFL\u2014High-throughput greybox fuzzing of IoT firmware via augmented process emulation. 1099--1114. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/zheng."},{"key":"e_1_2_2_195_1","volume-title":"Common criteria: Its limitations and advice on improvement. ISSA Journal","author":"Zhou Changying","year":"2011"},{"key":"e_1_2_2_196_1","unstructured":"Wei Zhou Yan Jia Yao Yao Lipeng Zhu Le Guan Yuhang Mao Peng Liu and Yuqing Zhang. 2019. Discovering and understanding the security hazards in the interactions between IoT devices mobile apps and clouds on smart home platforms. 1133--1150. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/zhou.  Wei Zhou Yan Jia Yao Yao Lipeng Zhu Le Guan Yuhang Mao Peng Liu and Yuqing Zhang. 2019. Discovering and understanding the security hazards in the interactions between IoT devices mobile apps and clouds on smart home platforms. 1133--1150. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/zhou."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3410160","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3410160","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:40:59Z","timestamp":1750200059000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3410160"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12,6]]},"references-count":187,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2021,11,30]]}},"alternative-id":["10.1145\/3410160"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3410160","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,12,6]]},"assertion":[{"value":"2019-07-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-07-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-12-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}