Evidence-Gated IoT Lifecycle Governance: A Stage-Gate Model with Learning Loops for Cyber Resilience
Paper Type
Complete
Abstract
Consumer IoT security and privacy harms persist despite extensive Security-by-Design and Privacy-by-Design guidance, in part because lifecycle governance is often weak, fragmented, and difficult to verify. This paper introduces the IoT Lifecycle Governance Model (ILGM), an information-systems governance artifact that operationalizes lifecycle stewardship through seven evidence-gated decision points (G1–G7) and five learning loops (L1–L5) that enable cyber resilience (by anticipating hazards, withstanding exploits, recovering control, and adapting governance). ILGM specifies accountable ownership, minimum assurance evidence, and contextual-integrity-aligned artifacts for key gates, translating principle-level guidance into auditable obligations. Using an abductive conceptual-development approach and a five-case secondary-data pilot assessment, we provide preliminary analytic validation that gate evidence and loop signals can yield stable, discriminating patterns aligned with five falsifiable propositions. The model advances IS research by moving IoT risk analysis from narrative diagnosis toward operational measurement and comparative evaluation.
Paper Number
1701
Recommended Citation
Yates, David, "Evidence-Gated IoT Lifecycle Governance: A Stage-Gate Model with Learning Loops for Cyber Resilience" (2026). AMCIS 2026 Proceedings. 33.
https://aisel.aisnet.org/amcis2026/sig_sec/sig_sec/33
Evidence-Gated IoT Lifecycle Governance: A Stage-Gate Model with Learning Loops for Cyber Resilience
Consumer IoT security and privacy harms persist despite extensive Security-by-Design and Privacy-by-Design guidance, in part because lifecycle governance is often weak, fragmented, and difficult to verify. This paper introduces the IoT Lifecycle Governance Model (ILGM), an information-systems governance artifact that operationalizes lifecycle stewardship through seven evidence-gated decision points (G1–G7) and five learning loops (L1–L5) that enable cyber resilience (by anticipating hazards, withstanding exploits, recovering control, and adapting governance). ILGM specifies accountable ownership, minimum assurance evidence, and contextual-integrity-aligned artifacts for key gates, translating principle-level guidance into auditable obligations. Using an abductive conceptual-development approach and a five-case secondary-data pilot assessment, we provide preliminary analytic validation that gate evidence and loop signals can yield stable, discriminating patterns aligned with five falsifiable propositions. The model advances IS research by moving IoT risk analysis from narrative diagnosis toward operational measurement and comparative evaluation.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.
Comments
SIG SEC