What it means
NIST IR 8259 describes what a manufacturer should do before a device reaches the market, and 8259A lists the corresponding device capabilities. It is often used together with the IoT device cybersecurity guidance for federal acquisition.
Applies to
- Manufacturers planning device security features
- Procurement requirements that reference NIST guidance
- Products seeking a documented baseline for enterprise buyers
What it does not cover
- A certification or a mark
- Privacy law compliance
- Sector-specific regulation such as medical devices
Verification checklist
- Identify the device and its security assumptions
- Define the customer-facing security capabilities
- Document the update and vulnerability handling model
- Map the device against the six activities and 8259A capabilities