Karen (Scarfone) Kent's Publications

Welcome! This site has links to all of my online publications. Sign up to get a weekly email update when I release something new.

NIST's Secure Software Development Framework (SSDF) 1.2

The content updates from SSDF 1.1 to 1.2 are relatively small, but the changes in format and layout are significant, which makes it arduous to do a side-by-side comparison. To aid you in seeing what’s changed, we’ve created an annotated version. It highlights new content in green and changed content in orange (except for references). Each highlighted instance of changed content also has a callout box with the old text and the new text.

Towards Automating IoT Security: Implementing Trusted Network-Layer Onboarding

This document provides an overview of trusted Internet of Things (IoT) device network-layer onboarding—a capability for securely providing IoT devices with their local network credentials in a manner that helps to ensure that the network is not put at risk as new IoT devices are connected to it. Additionally, the paper demonstrates the security benefits of trusted network-layer onboarding and how it can address problems with current IoT device onboarding practices.
Load More