Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 8228

Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks

Date Published: June 2019

Planning Note (03/30/2021): NISTIR 8228 is now available in Portuguese and Spanish translations.


Kaitlin Boeckl (NIST), Michael Fagan (NIST), William Fisher (NIST), Naomi Lefkovitz (NIST), Katerina Megas (NIST), Ellen Nadeau (NIST), Ben Piccarreta (NIST), Danna Gabel O'Rourke (Deloitte & Touche), Karen Scarfone (Scarfone Cybersecurity)



cybersecurity risk; Internet of Things (IoT); privacy risk; risk management; risk mitigation
Control Families

None selected


Download URL

Supplemental Material:
NIST news article
Portuguese translation (pdf)
Spanish translation (pdf)

Related NIST Publications:
IR 8259

Document History:
09/24/18: IR 8228 (Draft)
06/25/19: IR 8228 (Final)


Security and Privacy

general security & privacy, risk management


Internet of Things