{"title":"Security risk assessment in IoT environments: A taxonomy and survey","authors":"Mofareh Waqdan , Habib Louafi , Malek Mouhoub","doi":"10.1016/j.cose.2025.104456","DOIUrl":null,"url":null,"abstract":"<div><div>Internet of Things (IoT) applications have become an integral part of our daily lives. However, due to the rising number of cybercrimes, ensuring cyberspace security has become essential. The security and privacy of IoT applications are fundamental as they are used in critical sectors, like healthcare, transportation systems, and energy production. As a result, many studies are focusing on the security and privacy of the IoT revolution. The need for assessing IoT security risks is increasing.</div><div>This paper presents a survey and taxonomy of risk management, analysis, and evaluation methods applied to systems involving IoT devices. In particular, the paper reviews and categorizes existing IoT risk management and assessment frameworks, and the different assessments techniques, risk perspectives, and methodologies. The paper concludes with a deep analysis of these frameworks, solutions, and guidelines, and discusses future research directions.</div></div>","PeriodicalId":51004,"journal":{"name":"Computers & Security","volume":"154 ","pages":"Article 104456"},"PeriodicalIF":4.8000,"publicationDate":"2025-03-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computers & Security","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0167404825001452","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
Internet of Things (IoT) applications have become an integral part of our daily lives. However, due to the rising number of cybercrimes, ensuring cyberspace security has become essential. The security and privacy of IoT applications are fundamental as they are used in critical sectors, like healthcare, transportation systems, and energy production. As a result, many studies are focusing on the security and privacy of the IoT revolution. The need for assessing IoT security risks is increasing.
This paper presents a survey and taxonomy of risk management, analysis, and evaluation methods applied to systems involving IoT devices. In particular, the paper reviews and categorizes existing IoT risk management and assessment frameworks, and the different assessments techniques, risk perspectives, and methodologies. The paper concludes with a deep analysis of these frameworks, solutions, and guidelines, and discusses future research directions.
期刊介绍:
Computers & Security is the most respected technical journal in the IT security field. With its high-profile editorial board and informative regular features and columns, the journal is essential reading for IT security professionals around the world.
Computers & Security provides you with a unique blend of leading edge research and sound practical management advice. It is aimed at the professional involved with computer security, audit, control and data integrity in all sectors - industry, commerce and academia. Recognized worldwide as THE primary source of reference for applied research and technical expertise it is your first step to fully secure systems.