OWASP IoT and Embedded Application Security
OWASP project resources for securing IoT, embedded, and connected medical devices.
Definition
The OWASP IoT Project (and the related OWASP Embedded Application Security Project and OWASP IoT Top 10) provides community-curated guidance, threat catalogs, and testing methodologies for connected and embedded devices - including connected medical devices. The IoT Top 10 enumerates the most prevalent IoT security weaknesses (weak/guessable passwords, insecure network services, insecure ecosystem interfaces, lack of secure update mechanism, etc.).What this means in practice
OWASP IoT Top 10 is a useful prioritization aid for product security backlogs. The OWASP MASTG (Mobile Application Security Testing Guide) covers companion mobile apps that often ship with connected medical devices; the OWASP Application Security Verification Standard (ASVS) provides a tiered set of testable requirements.- •Treating the OWASP IoT Top 10 as the entirety of the threat model rather than a baseline checklist.
- •Skipping OWASP MASTG when the device ships with a companion mobile app.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsHands-on adversarial testing in which qualified independent testers attempt to exploit a device's security controls.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
Automated security testing - SAST analyzes source code at rest, DAST exercises a running application.
A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
3 sources- 1
OWASP IoT ProjectVerifiedOWASPowasp.org
- 2
OWASP MASTGVerifiedOWASPmas.owasp.org
- 3
CISA - Healthcare and Public Health SectorVerifiedCISAcisa.gov
Inline markers like [1] jump to the matching reference above.