This page is being moved to a new, faster, and mobile-friendly application! Access the enhanced and centralized experience now on MyWorkspace!
ITU's 160 anniversary

Connecting the world and beyond

  •  
GSR 2025

ITU-T Recommendations

Search by number:
Others:
Skip Navigation Links
Content search
Advanced search
Provisional name
Equivalent number
Formal description
Study Groups tree viewExpand Study Groups tree view

ITU-T X.1355 (04/2025)

عربي | 中文 | English | Español | Français | Русский
Security risk analysis framework for Internet of things devices
The Internet of things (IoT) encompasses diverse applications in sectors, e.g., healthcare, transportation, industrial control systems, smart cities, and smart homes. It is pivotal in enabling advanced services by connecting physical and virtual entities. However, IoT devices are susceptible to cyberattacks due to their function in collecting, processing, and transmitting sensitive data within the IoT environment. Security breaches in IoT devices can yield severe repercussions, including unauthorized information access, disruption of vital services, financial ramifications, and even physical harm. Hence, the imperative lies in protecting data and safeguarding IoT systems by ensuring their security.
Adopting a risk management approach is imperative in securing IoT devices, similar to practices in IT security. A robust risk management strategy entails identifying potential threats, assessing their likelihood and impact, and systematically mitigating them. This method not only facilitates prioritizing risks and compliance with regulations but also fosters stakeholder confidence and enhances resilience to emergent threats. Risk analysis is the cornerstone of this vital process, serving as the initial step toward fortifying the IoT environment.
Recommendation ITU-T X.1355 establishes a comprehensive security risk analysis framework tailored to IoT devices. The framework encompasses defining the analysis target, identifying potential threats, and evaluating these threats to develop effective mitigation strategies. It provides a systematic approach for stakeholders to assess and address security risks associated with IoT devices, whether they possess communication, actuation, sensing, data processing, or data storage capabilities. It is adaptable across diverse industries and various types of IoT devices, thereby endorsing the implementation of secure IoT solutions through rigorous risk analysis and the mitigation of potential threats.
Citation: https://handle.itu.int/11.1002/1000/16162
Series title: X series: Data networks, open system communications and security
  X.1300-X.1499: Secure applications and services (II)
  X.1350-X.1369: Internet of things (IoT) security
Approval date: 2025-04-17
Provisional name:X.ra-iot
Approval process:TAP
Status: In force
Maintenance responsibility: ITU-T Study Group 17
Further details: Patent statement(s)
Development history
[15 related work items in progress]