The load-bearing documents for a DIB program — CMMC / DFARS regulatory text (eCFR), federal rulemaking, NIST publications and OIRA review — organized as a library. Pick a document; the reader shows the dex dossier: what it says, why it matters, and the concrete obligations it imposes. Originals open at the source.
SP 800-213A Rev. 1, PRE-DRAFT Call for Comments: IoT Device Cybersecurity Requirement CatalogInitial Preliminary Draft
NIST is soliciting public comments on an updated draft of IoT product cybersecurity guidelines for the federal government.
This document is an initial public draft of NIST Special Publication 800-213 Rev. 1, which updates guidelines for establishing cybersecurity requirements for Internet of Things (IoT) products used by the federal government. It emphasizes that IoT products are system elements that must be considered in the risk management process, noting that integrating an IoT product may alter a system's risk assessment and require additional or new controls. The publication focuses on establishing product cybersecurity requirements to support security controls and provides general considerations of how IoT products may impact an information system's risk.
DIBs must understand evolving IoT cybersecurity requirements to ensure their products and systems comply with federal standards when integrating IoT devices into their information systems.