{"id":12607,"date":"2017-09-14T16:54:24","date_gmt":"2017-09-14T16:54:24","guid":{"rendered":"https:\/\/one.sightlinemg.com\/c4isrnet\/uncategorized\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/"},"modified":"2026-08-08T17:43:46","modified_gmt":"2026-08-08T17:43:46","slug":"compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/","title":{"rendered":"Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary]"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The internet of things (IoT) has ushered in a new and complex world of cybersecurity threats placing federal agencies at risk. Nearly nine out of 10 agencies consider the security of IoT devices \u201cessential\u201d for executing their missions. Connectivity, cost-efficiency and productivity advantages make the IoT indispensable. Yet, in the same study, 58 percent describe themselves as \u2013 at best \u2013 only \u201csomewhat\u201d confident in their ability to protect these devices, if not answering \u201cnot very\u201d or \u201cnot at all\u201d confident, according to <a href=\"http:\/\/www.govexec.com\/insights\/reports\/securing-edge-surveying-vulnerabilities-federal-governments-internet-things\/136184\/\">research<\/a> from the Government Business Council (GBC).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What\u2019s more, the IoT\u2019s presence within government networks will continue to grow, as 40 percent of agencies view IoT expansion as a priority, with 17 percent saying this is a \u201chigh\u201d or \u201ccritical\u201d priority, according to GBC\u2019s report. But, at the same time, agencies indicate that they struggle to secure IoT due to a lack of funding (as cited by 39 percent of survey respondents), slow procurement processes (39 percent) and unavailable technical expertise (30 percent).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These numbers are eye-catching and a symptom of a broader, strategic challenge: The government is attempting to counter a new and unfamiliar risk \u2013 hackers seeking to exploit multiplying, non-traditional IoT devices \u2013 with what amount to \u201ccompeting\u201d security versus compliance instincts, sometimes at each other\u2019s expense.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When it comes to securing federal networks, the perceived effectiveness of IT leaders is primarily based on how compliant they are based on periodical audits, some of which only happens on an annual basis. Successful completion of current compliance reviews and approval do not adequately prepare a federal organization to defend itself from today\u2019s cyber adversaries. Traditional compliance efforts such as the CIO Cybersecurity Scorecard are fairly limited in responding to current threats. These benchmarks reflect thinking from well before the IoT\u2019s rise, when the bar for information assurance was much lower. Any compliance effort primarily focused on known Microsoft Windows based endpoints, has very limited effectiveness today, if the goal it address the most foundational cyber hygiene challenges.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers recognize this. They realize that a compliance-driven methodology doesn\u2019t effectively address IoT exposures and attack vectors. In U.S. government settings, agencies\u2019 stakes in cyber security should motivate a shift to playbooks that places a premium on complete and continuous visibility and control of all IP-based endpoints \u2013 that is, preventative measures and protection \u2013 instead of primarily being focused on \u201conce in a while\u201d auditing scores that do not even account for many existing IoT assets \u2013 or worse, audits failing to take IoT risks into consideration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The good news is that voices within government are already driving change. At AFCEA\u2019s Energy and Earth Sciences IT symposium in July, Robert Powell, senior advisor for cybersecurity in NASA\u2019s office of the chief information officer, <a href=\"https:\/\/federalnewsradio.com\/technology-main\/2017\/07\/agencies-approach-to-iot-security-highlights-differences-in-cybersecurity-approach\/\">noted<\/a>, agencies \u201ccan get so overly focused on compliance and trying to get a good grade or a good score, or be green or what have you, when really what we need to be focused on is risk. If you forget that basic principle of \u2018How do I manage risk, why do we even have a risk process in place?\u2019 If we\u2019re going through compliance exercises at the expense of not focusing on risk, then that\u2019s a broken model.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So how can agencies fix or rebalance \u2018broken\u2019 risk models? First, government leaders must overcome uncertainty about what\u2019s \u201cout there\u201d on their networks by gathering hard data and insight. Assumptions will cloud risk perceptions and agencies do not have time for guesswork, they need to look out there and establish complete <b>visibility<\/b> of what is on their networks, and what software is running on those devices. Incorporating best practices and standards from the National Institute of Standards and Technology (NIST) <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2017\/01\/nist-releases-update-cybersecurity-framework\">Cybersecurity Framework<\/a> and the <a href=\"https:\/\/www.sans.org\/\">SANS Institute<\/a>, experts have constantly preached the mantra, \u201cYou cannot protect what you cannot see.\u201d Until you continuously shine a light to identify all IoT assets touching your network, you cannot prevent today \u2013 or tomorrow\u2019s IoT fabric from introducing unchecked risk. It is also important to consider the kind of \u201clight\u201d you are shining, because most traditional network scanning solutions are unable to recognize newly-connected, non-traditional IoT devices running non\u2013standard operating systems, which prevents the installation of third-party security software. In an effort to gain complete visibility across the enterprise, it is therefore paramount that the solutions leveraged do not require its software to be installed in the IoT asset.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you\u2019ve acquired total visibility, you <b>classify<\/b> what you\u2019re seeing. You determine what each device is \u2013 from \u201csmart\u201d thermostats and HVAC gear to security cameras or facility systems \u2013 and what it is supposed to do. With this vantage point, you develop baselines of routine, acceptable activity to better recognize unusual and possibly threatening patterns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, you implement a network admission-based dynamic <b>network segmentation<\/b> architecture. To illustrate how, let\u2019s use a common IoT example of a mission-critical, discrete connected device like a heart monitor in a hospital. This equipment might run on a version of Microsoft Windows \u2013 much like an agency\u2019s fleets of laptops. However, there are significantly different warranty considerations for heart monitors, and its operating system is embedded and more complicated to patch for known vulnerabilities. Therefore, the strict enforcement of designated network segments, assures the organization that these heart monitors remain in their own \u201clane\u201d, in order to prevent needless disruption or breach exposures. This way organizations can keep security issues affecting heart monitors, security cameras, HVAC systems or similar devices from affecting other assets \u2013 and vice versa.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our community is discovering new IoT innovations, use cases and risks every day. While we are still in early stages of the IoT transformation, there is a finite window to act and prevent competing directives or outdated cyber playbooks from consuming excess time and security resources. As the IoT rise causes us to rethink how our notions of networks are changing, it is natural to rethink what this means in terms of accounting for every device and managing the associated risk. By \u201cseeing\u201d all there is to see and then classifying and segmenting the IT assets, organizations gain a greater state of awareness about what is happening, why it\u2019s happening, and how to automate the mitigation process of what shouldn\u2019t be happening. Then the IoT doesn\u2019t look so mysterious \u2013 or scary \u2013 anymore.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><i>Niels Jensen is senior vice president for U.S. Public Sector at ForeScout Technologies.<\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nearly nine out of 10 agencies consider the security of IoT devices \u201cessential\u201d for executing their missions.<\/p>\n","protected":false},"author":7,"featured_media":39391,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":10,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":{"8":{"categories":["daily-brief","newsletters","it-cloud-report"],"primary_category":"daily-brief"}}},"categories":[10],"tags":[],"coauthors":[7426],"class_list":["post-12607","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber"],"acf":{"subheadline":"","legacy_arc_id":"3KA2BL5WVRD5FH6AMVHEM2MPXM","arc_canonical_url":"\/opinion\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary] - C4ISRNet<\/title>\n<meta name=\"description\" content=\"Nearly nine out of 10 agencies consider the security of IoT devices \u201cessential\u201d for executing their missions.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary]\" \/>\n<meta property=\"og:description\" content=\"Nearly nine out of 10 agencies consider the security of IoT devices \u201cessential\u201d for executing their missions.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/\" \/>\n<meta property=\"og:site_name\" content=\"C4ISRNet\" \/>\n<meta property=\"article:published_time\" content=\"2017-09-14T16:54:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T17:43:46+00:00\" \/>\n<meta name=\"author\" content=\"Niels Jensen, ForeScout\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Niels Jensen, ForeScout\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary]\",\n\t            \"datePublished\": \"2017-09-14T16:54:24+00:00\",\n\t            \"dateModified\": \"2026-08-08T17:43:46+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/\"\n\t            },\n\t            \"wordCount\": 1075,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ISR-Data-1.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Cyber\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/\",\n\t            \"name\": \"Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary] - C4ISRNet\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ISR-Data-1.jpg.jpg\",\n\t            \"datePublished\": \"2017-09-14T16:54:24+00:00\",\n\t            \"dateModified\": \"2026-08-08T17:43:46+00:00\",\n\t            \"description\": \"Nearly nine out of 10 agencies consider the security of IoT devices \u201cessential\u201d for executing their missions.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ISR-Data-1.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ISR-Data-1.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2017\\\/09\\\/14\\\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Cyber\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/\",\n\t                    \"ad_zone\": \"cyber\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary]\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"description\": \"Media for the Intelligence-Age Military | C4ISRNET\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"caption\": \"C4ISRNet\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary] - C4ISRNet","description":"Nearly nine out of 10 agencies consider the security of IoT devices \u201cessential\u201d for executing their missions.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary]","og_description":"Nearly nine out of 10 agencies consider the security of IoT devices \u201cessential\u201d for executing their missions.","og_url":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/","og_site_name":"C4ISRNet","article_published_time":"2017-09-14T16:54:24+00:00","article_modified_time":"2026-08-08T17:43:46+00:00","author":"Niels Jensen, ForeScout","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Niels Jensen, ForeScout","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary]","datePublished":"2017-09-14T16:54:24+00:00","dateModified":"2026-08-08T17:43:46+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/"},"wordCount":1075,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ISR-Data-1.jpg.jpg","articleSection":["Cyber"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/","name":"Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary] - C4ISRNet","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ISR-Data-1.jpg.jpg","datePublished":"2017-09-14T16:54:24+00:00","dateModified":"2026-08-08T17:43:46+00:00","description":"Nearly nine out of 10 agencies consider the security of IoT devices \u201cessential\u201d for executing their missions.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ISR-Data-1.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ISR-Data-1.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2017\/09\/14\/compliance-vs-security-rethinking-federal-cyber-risk-in-the-iot-era-commentary\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Cyber","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/","ad_zone":"cyber"},{"@type":"ListItem","position":3,"name":"Compliance vs. Security: Rethinking federal cyber risk in the IoT era [Commentary]"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","name":"C4ISRNet","description":"Media for the Intelligence-Age Military | C4ISRNET","publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/c4isrnet\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization","name":"C4ISRNet","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","caption":"C4ISRNet"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/c4isrnet\/author\/migration\/"}]}},"jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"C4ISRNet","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/c4isrnet","push-errors":false,"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ISR-Data-1.jpg.jpg","_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/12607","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/comments?post=12607"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/12607\/revisions"}],"predecessor-version":[{"id":12613,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/12607\/revisions\/12613"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/media?parent=12607"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/categories?post=12607"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/tags?post=12607"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/coauthors?post=12607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}