Paper Type

Complete

Abstract

Consumer IoT security and privacy harms persist despite extensive Security-by-Design and Privacy-by-Design guidance, in part because lifecycle governance is often weak, fragmented, and difficult to verify. This paper introduces the IoT Lifecycle Governance Model (ILGM), an information-systems governance artifact that operationalizes lifecycle stewardship through seven evidence-gated decision points (G1–G7) and five learning loops (L1–L5) that enable cyber resilience (by anticipating hazards, withstanding exploits, recovering control, and adapting governance). ILGM specifies accountable ownership, minimum assurance evidence, and contextual-integrity-aligned artifacts for key gates, translating principle-level guidance into auditable obligations. Using an abductive conceptual-development approach and a five-case secondary-data pilot assessment, we provide preliminary analytic validation that gate evidence and loop signals can yield stable, discriminating patterns aligned with five falsifiable propositions. The model advances IS research by moving IoT risk analysis from narrative diagnosis toward operational measurement and comparative evaluation.

Paper Number

1701

Comments

SIG SEC

Share

COinS
 
Aug 15th, 12:00 AM

Evidence-Gated IoT Lifecycle Governance: A Stage-Gate Model with Learning Loops for Cyber Resilience

Consumer IoT security and privacy harms persist despite extensive Security-by-Design and Privacy-by-Design guidance, in part because lifecycle governance is often weak, fragmented, and difficult to verify. This paper introduces the IoT Lifecycle Governance Model (ILGM), an information-systems governance artifact that operationalizes lifecycle stewardship through seven evidence-gated decision points (G1–G7) and five learning loops (L1–L5) that enable cyber resilience (by anticipating hazards, withstanding exploits, recovering control, and adapting governance). ILGM specifies accountable ownership, minimum assurance evidence, and contextual-integrity-aligned artifacts for key gates, translating principle-level guidance into auditable obligations. Using an abductive conceptual-development approach and a five-case secondary-data pilot assessment, we provide preliminary analytic validation that gate evidence and loop signals can yield stable, discriminating patterns aligned with five falsifiable propositions. The model advances IS research by moving IoT risk analysis from narrative diagnosis toward operational measurement and comparative evaluation.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.