https://www.americancityandcounty.com/wp-content/themes/acc_child/assets/images/logo/footer-logo.png
  • Home
  • Co-op Solutions
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcast
  • Resources
    • Back
    • Resources
    • Webinars
    • White Papers
    • Events
    • How to Contribute
    • Municipal Cost Index – Archive
    • Equipment Watch Page
    • American City & County Awards
  • Magazine
    • Back
    • Digital Editions
    • Reprints & Reuse
    • Advertise
  • About Us
    • Back
    • About Us
    • Contact Us
    • Privacy Statement
    • Terms of Service
American City and County
  • NEWSLETTER
  • Home
  • Co-op Solutions
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcasts
  • Resources
    • Back
    • Webinars
    • White Papers
    • Events
    • How to Contribute
    • American City & County Awards
    • Municipal Cost Index
    • Equipment Watch Page
  • Magazine
    • Back
    • Digital Editions
    • Reprints & Reuse
    • Subscribe to GovPro
    • Manage GovPro Subscription
    • Advertise
  • About Us
    • Back
    • About Us
    • Contact Us
    • Cookie Policy
    • Privacy Stament
    • Terms of Service
  • newsletter
  • Administration
  • Economy & Finance
  • Procurement
  • Public Safety
  • Public Works & Utilities
  • Smart Cities & Technology
acc.com

Commentaries


Commentary

Securing the Internet of Things tide

Securing the Internet of Things tide

  • Written by Mav Turner
  • 1st November 2019

The long-promised Internet of Things (IoT) storm has arrived in force, bringing with it a combination of good and bad news for state and local government agencies.

First, the good: the IoT has the potential to offer state and local municipalities real and tangible benefits for their citizens. The IoT is already powering smart city efforts throughout the country, through things like smart grids, automatic flood detection, and more. The city of Chicago alone has an initiative called the “Array of Things”—a massive open data effort that relies on sensors to turn Chicago into “the most data-driven government in the world,” according to former Mayor Rahm Emanuel. These big picture, large-scale innovations offer the promise of a safer and more efficient way of life for citizens.

But state and local IT teams are faced with an IoT flood of their own. This tsunami has taken the form of millions of small devices that are using agency networks to communicate and share information. We’ve moved beyond the quaint “bring your own device” trend into a world where government workers are using an endless sea of technologies, from smartwatches to smart speakers, all of which are difficult to track and secure.

Let’s explore some strategies that state and local government IT professionals can employ to batten down the network hatches and weather this storm.


Containment is key

Any approach to dealing with the IoT must first start with the recognition that it is not something that can be “managed” traditionally. There are now 7 billion IoT devices in circulation according to research from IoT Analytics. Those devices come in different forms and run on various (mostly proprietary) operating systems. To adopt a sports phrase, you can’t stop them, you can only hope to contain them.

In a sense, that’s what the National Institute of Standards and Technology (NIST) is advocating for the federal government. NIST recently published NISTIR 8228, which provides guidelines on how best to manage cybersecurity and privacy risks related to the IoT. The publication advocates focusing on protecting device security, data security, and individuals’ privacy without objecting to the use of IoT devices in public agencies. It accepts them as fact and encourages organizations to better understand their use of IoT and how it impacts security.

While the publication is geared toward federal agencies, the same principles and challenges that NISTIR 8228 addresses clearly apply to the state and local government sector. IT professionals at these levels need to secure their devices and data while protecting their workers’ rights to privacy. That’s hard to do when faced with thousands of non-secure access points.

 

Visibility is critical

Of course, you can’t secure what you can’t see. Many IT managers simply do not have visibility into all—or even probably most—of the IoT devices that are being used daily on their networks. They may not know that there’s a problem, or where the problem is coming from, until it’s too late. As such, IoT can be a particularly insidious form of shadow IT that can significantly broaden an agency’s attack surface without IT managers even realizing that it’s happening.

Taking stock of every device that is in use is essential, but even that in and of itself isn’t necessarily enough. IT professionals should be able to gain a precise understanding of device behavior to ensure that connected devices are not acting in a suspicious or potentially malicious manner. For example, is that connected printer doing what it’s supposed to be doing? Or is it exhibiting signs of being an information-sharing node? If it’s the latter, it’s time to take action.


Action is necessary

Once a device is flagged, IT administrators will want to automatically kill any applications running on the device. Securing the IoT is about application awareness more than anything else. Administrators must gain a solid understanding of how apps are transmitting information in order to better protect their networks and data.

Creating protocols around unsanctioned devices is also a good idea. State and local IT professionals should consider developing whitelists for devices that are allowed on their networks. Then, assert further control by tracking and blocking rogue devices. Those devices that are allowed should be consistently patched and updated to help ensure that they are better protected.


Secure—not stem—the tide

There are some agencies out there that have adopted strict “no consumer devices” policies, but those are few and far between. For most, the IoT horse left the barn years ago when employees began using their personal smartphones for work.

Now, it’s too late to turn back—and really, do we want to? As much of a challenge the IoT poses, use of connected devices propagates greater efficiency and employee satisfaction. Perhaps the best state and local IT professionals can do is to secure the tide—rather than stem it—by expanding their perspectives and processes when it comes to fortifying IoT devices.

 

Mav Turner is group vice president of products at SolarWinds.

 

 

Tags: Smart Cities & Technology Commentaries Commentary

Related


  • COVID-19 and pivoting into a new year: It may be 2021, but did we really leave 2020?
    As we continue to navigate 2021, many issues will require continued tech leadership and support to carry everyone through
  • Artificial cities could pave the way to driverless adoption
    Connected and autonomous vehicles (CAVs) have a future. That is without doubt but there is still a need to ensure that they will be safe on our highways and to ease the public’s safety concerns to increase their adoption over the next few years. CAVs need to be able to react to unforeseen events – […]
  • Buffalo, N.Y.'s 48 hours to navigate a mission-critical transition to remote work
    In Buffalo, N.Y., 311 is a vital lifeline for the city, providing an always-on call resource for the city’s 250,000 residents to reach city government. When the COVID-19 pandemic prompted a stay-at-home order, city officials knew a surge of calls was coming, and they needed to act fast to keep their front-line communications channel open. […]
  • Hi-tech sewers can help safeguard public health, environment and economies
    In the wake of the coronavirus, economic recovery is top of mind for all city leaders, the majority of whom believe that investing in infrastructure and technology can spur a rebound. Yet current analyses indicate that we only have funding available to cover approximately 57 percent of infrastructure system improvements through 2029, leaving an investment gap […]

Leave a comment Cancel reply

-or-

Log in with your American City and County account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Bridging the digital divide by fostering digital inclusion and economic recovery
  • Amazon Web Services unveils program to help government technology startups
  • AT&T unveils FirstNet innovations, including HPUE, vertical location, deployable offerings
  • As cities praise America’s return to Paris agreement, many have remained on course with climate actions and goals

Twitter


AmerCityCounty

2020 Crown Communities winner: El Paso County, Texas’ pretrial justice modernization dlvr.it/Rv4GKL

6th March 2021
AmerCityCounty

A city’s innovative downtown master plan sees future in local, inclusive placemaking dlvr.it/Rv3SfM

5th March 2021
AmerCityCounty

2020 Crown Communities winner: Gainesville, Fla. closes Dignity Village and houses its homeless population dlvr.it/Rv1GS2

5th March 2021
AmerCityCounty

2020 Crown Communities Winner: South Bay Cities Council of Governments’ South Bay Fiber Network dlvr.it/Rv10b7

5th March 2021
AmerCityCounty

Senate American Rescue Plan includes more than $60 million in direct aid for counties dlvr.it/RtzvBK

4th March 2021
AmerCityCounty

ASCE releases 2021 Report Card for America’s Infrastructure dlvr.it/Rtvck5

3rd March 2021
AmerCityCounty

Updating the assessor report: A new approach dlvr.it/RttvDv

3rd March 2021
AmerCityCounty

2020 Crown Communities winner: Phases 2 and 3 of Minot, N.D.’s Mouse River Enhanced Flood Protection Plan dlvr.it/RtrWMC

3rd March 2021

Newsletters

Sign up for American City & County’s newsletters to receive regular news and information updates about local governments.

Resale Insights Dashboard

The Resale Insights Dashboard provides model-level data for the entire used equipment market to help you save time and money.

Municipal Cost Index

Updated monthly since 1978, our exclusive Municipal Cost Index shows the effects of inflation on the cost of providing municipal services

Media Kit and Advertising

Want to reach our digital audience? Learn more here.

DISCOVER MORE FROM INFORMA TECH

  • IWCE’s Urgent Communications
  • IWCE Expo

WORKING WITH US

  • About Us
  • Contact Us

FOLLOW American City and County ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookies Policy
  • Terms
Copyright © 2021 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X