Industrial Internet Consortium Announces Practitioner’s Guide for Assessing the Maturity of IoT System Security

IIC Openfog Report

Apr 14, 2019

The Industrial Internet Consortium, now incorporating OpenFog, announces the Security Maturity Model (SMM) Practitioner’s Guide, which provides detailed actionable guidance enabling IoT stakeholders to assess and manage the security maturity of IoT systems. Along with the publication of the SMM Practitioner’s Guide is an update to the IoT SMM: Description and Intended Use White Paper, which provides an introduction to the concepts and approach of the SMM. This white paper has been updated for consistency with the SMM Practitioner’s Guide, including revised diagrams and updated terminology.

As organizations connect their systems to the internet, they become vulnerable to new threats, and they are rightly concerned with security. Addressing these concerns requires investment, but determining investment focus and amount is a difficult business decision. The SMM helps by enabling a structured top-down approach toward setting goals as well as a means toward assessing the current security state, taking into account various specific practices. The SMM allows an organization to trade off investment against risk in a sensible manner.

Building on concepts identified in the IIC Industrial Internet Security Framework published in 2016, the SMM defines levels of security maturity for a company to achieve based on its security goals and objectives as well as its appetite for risk. Organizations may improve their security state by making continued security assessments and improvements over time, up to their required level.

“This is the first model of its kind to assess the maturity of organizations’ IoT systems in a way that includes governance, technology and system management,” said Stephen Mellor, CTO, IIC. “Other models address part of what is addressed by the SMM: they may address a particular industry, IoT but not security, or security but not IoT. The SMM covers all these aspects and points to parts of existing models, where appropriate, to recognize existing work and avoid duplication.”

The practitioner’s guide includes tables describing what must be done to reach a given security comprehensiveness for each security domain, subdomain and practice and can be extended to address specific industry or system scope needs. Following each table is an example using various industry use cases to demonstrate how an organization might use the table to pick a target state or to evaluate a current state.

One example is that of an automotive manufacturer considering the possible threats interfering with the operations of a vehicle key fob. The manufacturer sets its target maturity comprehensiveness level to “1” as it considers some IT threats, such as a Denial of Service attack that may prevent a driver from opening the car door using the key fob. Over time, as new threats emerge, the manufacturer realizes it needs additional threat modeling and enhanced practices so raises its target maturity comprehensiveness level to a higher level “2.”

The practitioner’s guide contains three case studies that show IoT stakeholders how to apply the process based on realistic assessments, showing how the SMM can be applied in practice. The case studies include a smarter data-driven bottling line, an automotive gateway supporting OTA updates and security cameras used in residential settings.

IOT SMM: PRACTITIONER’S GUIDE

The Practitioner’s Guide provides a pragmatic approach, enabling implementation teams to communicate an IoT system’s current state of security through confident discussions with business stakeholders about the desired state of security maturity, where gaps exist and a roadmap for achieving their goal. The Practitioner’s Guide describes how to reach a given security comprehensiveness for each security domain, subdomain and practice and can be extended to address specific industry or system scope needs. Various industry use case examples demonstrate how an organization might select a target state or evaluate a current state.

PRIMARY AUTHORS

  • Sandy Carielli – Entrust Datacard
  • Matthew Eble – Praetorian
  • Frederick Hirsch – Fujitsu
  • Ekaterina Rudina – Kaspersky Lab
  • Ron Zahavi – Microsoft Azure IoT

OTHER CONTRIBUTORS

  • Tata Consultancy Services / NetFoundry
  • Wibu-Systems

Go HERE to download the report

Related Articles


Latest Articles

  • Industrial Construction Intentions Drive Increase in Non-Residential Sector in January

    Industrial Construction Intentions Drive Increase in Non-Residential Sector in January

    March 13, 2026 In January, the total value of building permits issued in Canada increased $607.0 million (+4.8%) to $13.3 billion. The increase was led by the non-residential sector (+$464.0 million) and supported by the residential sector (+$143.0 million). On a constant dollar basis (2023=100), the total value of building permits issued in January rose 4.3% from the previous month Read More…

  • Multi-Unit Construction Drives Growth in December Residential Construction Investment, 2025 Review

    Multi-Unit Construction Drives Growth in December Residential Construction Investment, 2025 Review

    March 13, 2026 The total value of investment in building construction increased $442.9 million (+1.9%) to $23.7 billion in December. The residential sector grew 2.4%, while the non-residential sector edged up 0.6%. Year over year, investment in building construction grew 12.2% in December. On a constant dollar basis (2023=100), the total value of investment in building construction in December rose 1.7% Read More…

  • 5 Strategic Reasons to Attend the Lumen Exhibition

    5 Strategic Reasons to Attend the Lumen Exhibition

    March 13, 2026 In a market where deadlines are tight and projects are increasingly complex, staying competitive is no longer just about technical skills. It also depends on having the right tools, the right information, and the right partners by your side. The Lumen Exhibition is more than just an event—it’s a strategic lever designed to Read More…

  • BCCA Official Statement on Construction Projects Procurement Act

    BCCA Official Statement on Construction Projects Procurement Act

    March 13, 2026 On March 5, 2026, Kiel Giddens, MLA for Prince George – Mackenzie and Critic for Labour, introduced the Construction Projects Procurement Act, a Private Member’s Bill aimed at restoring fair and open procurement on public construction projects in British Columbia. BCCA has a long history of advocating for fair and open public procurement. Read More…


Changing Scene

  • Nova Scotia Strengthens Housing Legislation to Accelerate Supply

    Nova Scotia Strengthens Housing Legislation to Accelerate Supply

    March 13, 2026 Amendments to existing legislation will mean more housing, improved efficiency in the sector and better alignment of related agencies. The changes extend the Executive Panel on Housing in the Halifax Regional Municipality and give the Minister of Housing new authority to ensure housing projects aren’t delayed. “We are strengthening how we plan, Read More…

  • Sonepar Company Opens a New Automated Distribution Center in Las Vegas

    Sonepar Company Opens a New Automated Distribution Center in Las Vegas

    March 13, 2026 Codale Electric Supply, a Sonepar company, is transforming electrical distribution with the launch of its central distribution center located just off the Las Vegas Strip, in October 2025. The site features a highly automated setup designed to improve speed, accuracy, and customer convenience. At the heart of the facility is an advanced Read More…

  • BC Introduces Public Sector Construction Projects Procurement Act

    BC Introduces Public Sector Construction Projects Procurement Act

    March 13, 2026 Kiel Giddens, MLA for Prince George-Mackenzie and Critic for Labour, has introduced the Public Sector Construction Projects Procurement Act, legislation aimed at ensuring publicly funded construction contracts are awarded through labour-neutral, merit-based procurement. “Here’s the simple question: if labour shortages are driving cost overruns, why would government limit who can work on public projects?” Read More…

  • KPMG Establishes Major Products Delivery Office

    KPMG Establishes Major Products Delivery Office

    March 13, 2026 KMPG: Complex projects require well-structured teams, appropriate delivery models tailored to the project’s needs, robust governance frameworks, and stable execution environments: KPMG Canada Canada is entering a defining era of major project development that has significant implications for the nation’s economic future, as the country works to establish new trade partnerships, develop its resources, reinforce Read More…