<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "http://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="review-article" dtd-version="1.2" xml:lang="en">
    <front>
        <journal-meta>
            <journal-id journal-id-type="pmc">F1000Research</journal-id>
            <journal-title-group>
                <journal-title>F1000Research</journal-title>
            </journal-title-group>
            <issn pub-type="epub">2046-1402</issn>
            <publisher>
                <publisher-name>F1000 Research Limited</publisher-name>
                <publisher-loc>London, UK</publisher-loc>
            </publisher>
        </journal-meta>
        <article-meta>
            <article-id pub-id-type="doi">10.12688/f1000research.172017.1</article-id>
            <article-categories>
                <subj-group subj-group-type="heading">
                    <subject>Review</subject>
                </subj-group>
                <subj-group>
                    <subject>Articles</subject>
                </subj-group>
            </article-categories>
            <title-group>
                <article-title>Possible security threats coming from IOT medicine sensor calibration process</article-title>
                <fn-group content-type="pub-status">
                    <fn>
                        <p>[version 1; peer review: 1 approved with reservations]</p>
                    </fn>
                </fn-group>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author" corresp="yes">
                    <name>
                        <surname>Kairiukstis</surname>
                        <given-names>Laimonas</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Supervision</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <uri content-type="orcid">https://orcid.org/0009-0000-2102-9070</uri>
                    <xref ref-type="corresp" rid="c1">a</xref>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Kairi&#x016b;k&#x0161;tyt&#x0117;</surname>
                        <given-names>Kamil&#x0117;</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Norvilas</surname>
                        <given-names>Edvinas</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Resources</role>
                    <role content-type="http://credit.niso.org/">Visualization</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <aff id="a1">
                    <label>1</label>Lietuvos In&#x017e;inerijos Kolegija Higher Education Institution, Tvirtoves al. 35, 50155 Kaunas, Lithuania</aff>
            </contrib-group>
            <author-notes>
                <corresp id="c1">
                    <label>a</label>
                    <email xlink:href="mailto:kairiukstis.laimonas@gmail.com">kairiukstis.laimonas@gmail.com</email>
                </corresp>
                <fn fn-type="conflict">
                    <p>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>27</day>
                <month>11</month>
                <year>2025</year>
            </pub-date>
            <pub-date pub-type="collection">
                <year>2025</year>
            </pub-date>
            <volume>14</volume>
            <elocation-id>1327</elocation-id>
            <history>
                <date date-type="accepted">
                    <day>21</day>
                    <month>11</month>
                    <year>2025</year>
                </date>
            </history>
            <permissions>
                <copyright-statement>Copyright: &#x00a9; 2025 Kairiukstis L et al.</copyright-statement>
                <copyright-year>2025</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access article distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <self-uri content-type="pdf" xlink:href="https://f1000research.com/articles/14-1327/pdf"/>
            <abstract>
                <p>The global deployment of over seven billion IoT measuring devices in critical fields like healthcare and industrial safety systems exposes a pressing vulnerability to cyber-attacks, where compromised data integrity can lead to severe financial or life-threatening incidents. Calibration is the fundamental process ensuring measurement uniformity, yet the immense scale of the IoT makes traditional laboratory calibration physically impossible. Consequently, the calibration process must migrate on-site, relying on remote communication with calibration standards&#x2014;a paradigm known as Calibration as a Service (CaaS). This digital shift, however, introduces significant cybersecurity risks into the very foundation of measurement trust. This paper addresses this critical challenge by presenting a comprehensive Standard Operating Procedure (SOP) for Secure IoT Measuring System Calibration. The proposed framework establishes the necessary protocols to protect the calibration process within a CaaS infrastructure. We further emphasize that the development and deployment of such secure IoT systems necessitate dedicated collaboration between IT security specialists and domain experts, ensuring that device integrity is prioritized from inception to safeguard end-users in an increasingly connected and vulnerable digital ecosystem.</p>
            </abstract>
            <kwd-group kwd-group-type="author">
                <kwd>Calibration</kwd>
                <kwd>Security</kwd>
                <kwd>Data</kwd>
                <kwd>IoT Medical device</kwd>
                <kwd>Standard Operating Procedure</kwd>
            </kwd-group>
            <funding-group>
                <award-group id="fund-1">
                    <funding-source>Lietuvos In&#x017e;inerijos Kolegija  Higher Education Institution</funding-source>
                </award-group>
                <funding-statement>This work was supported by the Lietuvos In&#x017e;inerijos Kolegija  Higher Education Institution.</funding-statement>
                <funding-statement>
                    <italic>The funders had no role in study design, data collection and analysis, decision to publish, or preparation of the manuscript.</italic>
                </funding-statement>
            </funding-group>
        </article-meta>
    </front>
    <body>
        <sec id="sec1" sec-type="intro">
            <title>1. Introduction</title>
            <sec id="sec2">
                <title>1.1 Challenges of digital transformation in metrology</title>
                <p>The use of IoT measurement devices is rapidly increasing across all areas of life &#x2014; including industry, households, agriculture, and medicine. However, this growing deployment also raises various metrological challenges caused by factors such as device aging, unstable power supply, and environmental influences like vibration, temperature fluctuations, and other external conditions.
                    <sup>
                        <xref ref-type="bibr" rid="ref1">1</xref>
                    </sup> Additionally, although to a lesser extent, cybersecurity issues can also impact measurement reliability. Metrology forms the foundation of the entire quality infrastructure. Without reliable measurements, it is impossible to conduct any research &#x2014; from electronics and mechanics to medicine or management. To ensure product quality, prevent production losses, and avoid physical harm or even death, the calibration of IoT measuring devices (IoTM) must be performed at appropriate intervals, and their suitability for measurement must be continuously verified and validated. Due to calibration a uninterrupted link between the measuring device and the SI system units is formed. However, it is practically impossible to calibrate large number of IoTM devices in laboratories, in this situation, the solution becomes calibration performed onsite.
                    <sup>
                        <xref ref-type="bibr" rid="ref1">1</xref>
                    </sup>
                </p>
                <p>In this article we will use the terms described in the International Vocabulary of Metrology (VIM). This guidance harmonizes worldwide fundamental terminology and thus allows the science of metrology to improve. In Chapter 5 of the VIM, &#x201c;Measurement standards (etalons) and metrological traceability&#x201d;, calibration is defined as an operation performed on a measuring instrument or a measuring system that, under specified conditions establishes a relation between the values with measurement uncertainties provided by measurement standards and corresponding indications with associated measurement uncertainties and uses this information to establish a relation for obtaining a measurement result from an indication.
                    <sup>
                        <xref ref-type="bibr" rid="ref2">2</xref>
                    </sup> Some authors use the concept of calibration incorrectly, for example, calibration is not just adjustment of a measuring system or verification of calibration, which frequently inaccurately called &#x201c;selfcalibration&#x201d;. Calibration of devices used in the healthcare sector is a key step in protecting lives, therefore the accuracy, precision, and performance of the devices become extremely important.
                    <sup>
                        <xref ref-type="bibr" rid="ref3">3</xref>
                    </sup> The global medical equipment calibration services market size was estimated at US$1.7 billion in 2024 and is expected to grow over the next decade to US$4.8 billion by 2034 owing to the rising demand for accuracy and regulatory compliance in medical devices.
                    <sup>
                        <xref ref-type="bibr" rid="ref4">4</xref>
                    </sup>
                </p>
                <p>It is important to understand that calibration may be expressed by a statement, calibration function, diagram, curve or table.
                    <sup>
                        <xref ref-type="bibr" rid="ref2">2</xref>
                    </sup> The calibration can be performed directly between the primary measurement standard and the secondary measurement standard or using an intermediate measurement system calibrated by the primary measurement standard, with the measurement result assigned to the secondary measurement standard.
                    <sup>
                        <xref ref-type="bibr" rid="ref2">2</xref>
                    </sup>
                </p>
                <p>All measurement systems, including IoTM devices, must have an unbroken chain of metrological traceability to an international or national measurement standard. Continuous calibration monitoring is extremely important for metrological traceability, as it allows the identification of factors contributing to measurement uncertainty and a more accurate assessment of the conformity of the measurement result to the standard.
                    <sup>
                        <xref ref-type="bibr" rid="ref2">2</xref>
                    </sup> The measurement system, measurement result and calibration interfaces can be depicted in 
                    <xref ref-type="fig" rid="f1">Figure 1</xref> below. This diagram illustrates that data transmission occurs throughout all processes, thereby revealing two key security risks for IoTM devices: the potential for data leakage or intentional modification, and the specific locations where these threats may arise.</p>
                <fig fig-type="figure" id="f1" orientation="portrait" position="float">
                    <label>Figure 1. </label>
                    <caption>
                        <title>Conceptual diagram about &#x201c;calibration&#x201d;.
                            <sup>
                                <xref ref-type="bibr" rid="ref2">2</xref>
                            </sup>
                        </title>
                    </caption>
                    <graphic id="gr1" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/189694/adfcd33c-ff6f-4344-92f1-f5138bdc78f0_figure1.gif"/>
                </fig>
                <p>To ensure measurement traceability and compliance with quality standards, measuring devices require accredited calibration certificates. Traditionally, these are issued on paper, which complicates the work of technical supervisors, increases logistical costs, extends device downtime, and hinders automation in facilities with numerous instruments.</p>
                <p>To address these inefficiencies, the industry is moving toward digital calibration certificates for IoT devices. However, this shift presents not only metrological challenges but also demands robust IT security and a stable data transmission network. This is particularly difficult given the constraint of limited power sources, especially when a device should operate without changing batteries for the minimum 5 years.</p>
                <p>The implementation of digital technologies in metrology, as we can see, is a slow process, historically most likely related to the tradition of providing standards and measurement services. The responsibility arising during this process makes even minimal changes slow and consistent, in order to avoid any financial, emotional or health damage.
                    <sup>
                        <xref ref-type="bibr" rid="ref5">5</xref>
                    </sup> National Metrology Institutes (NMIs) have plans to provide secure and traceable Digital Calibration Certificates (DCCs), but this project is still on the hold due lack of reliable, secure and traceable infrastructure, therefore the digitalization process in metrology lags behind progress in other areas and new projects just starting in this area.
                    <sup>
                        <xref ref-type="bibr" rid="ref6">6</xref>
                    </sup> The concept
                    <sup>
                        <xref ref-type="bibr" rid="ref6">6</xref>
                    </sup> of digital calibration certificates was introduced by scientist from National Metrology Institute of Germany within the project Smartcon framework
                    <sup>
                        <xref ref-type="bibr" rid="ref7">7</xref>
                    </sup> in 2018 and continues in the Euramet project &#x201c;Development of digital calibration certificates&#x201d; till 2026. The preliminary results of introduction paper free DCC inside IoT measurement systems are described in the article.
                    <sup>
                        <xref ref-type="bibr" rid="ref6">6</xref>
                    </sup> The requirements for DCC calibration infrastructure and certificate structure are described in the sources.
                    <sup>
                        <xref ref-type="bibr" rid="ref7">7</xref>&#x2013;
                        <xref ref-type="bibr" rid="ref9">9</xref>
                    </sup>
                </p>
                <p>In order to transmit digital metrology data over public networks, such as the Internet, security must be ensured, only then will the data not be compromised by various means during transmission, especially by malicious actors on the Internet.
                    <sup>
                        <xref ref-type="bibr" rid="ref5">5</xref>
                    </sup> However, the implementation of DCC in any chosen measurement area to enable calibration as a service for IoTM devices without human intervention (machine-to-machine communication) makes preparation an appropriate secure infrastructure necessary.</p>
                <p>The article examines wearable and implanted devices (IMDs) in medicine, aims to determine the impact of Calibration Errors on Medical Device Security and at the end of the analysis, a Standard Operating Procedure for calibration of IoTM will be proposed as a result.</p>
            </sec>
            <sec id="sec3">
                <title>1.2 Security challenges in measurement systems used in healthcare</title>
                <p>With the growing trend that medicine should be personalized and advancements in microelectronics, materials science, and wireless communication the number of personalized IoT sensors used in the healthcare system is increasing every year. This shows US $33.85 billion global market for health care wearables in 2023 and expected rising trend with US $250 billion market by 2030.
                    <sup>
                        <xref ref-type="bibr" rid="ref10">10</xref>
                    </sup> The World Health Organization (WHO) believes with the Global Health Strategy for 2025-2028 6 billion people will enjoy better health and well-being and 7 billion people to be better protected from health emergencies,
                    <sup>
                        <xref ref-type="bibr" rid="ref11">11</xref>
                    </sup> we believe that medical devices calibration process improvement could also contribute to this plan. Since 2010 WHO organizes Global Forum on Medical Devices, in 2025 June 2-4 were the fifth forum, in which were defined methods for increasing access to essential and priority medical devices were defined, examples of best practices from countries in medical device regulation, evaluation, and governance were shared, and the development and use of innovative, appropriate, and affordable technologies to address global health priorities were demonstrated.</p>
                <p>Wearable medical devices are considered to have one or more than one of the four main functions: monitoring, screening, detection and prediction.
                    <sup>
                        <xref ref-type="bibr" rid="ref11">11</xref>
                    </sup> From general vital signs monitoring to specialized sensors designed to diagnose, monitor symptoms, and treat specific diseases from different body systems - cardiovascular, neurological, psychological, musculoskeletal.
                    <sup>
                        <xref ref-type="bibr" rid="ref12">12</xref>,
                        <xref ref-type="bibr" rid="ref13">13</xref>
                    </sup> These sensors are already incorporated in our everyday life. Continuous monitoring data collected through IoT technologies can enhance the knowledge base for decision-making and is inherently different from routine clinical consultations.
                    <sup>
                        <xref ref-type="bibr" rid="ref14">14</xref>
                    </sup> However, it also possesses the risk of information overload in the healthcare system.
                    <sup>
                        <xref ref-type="bibr" rid="ref15">15</xref>
                    </sup> The cross-sectional study in 2025 showed that female users and with higher income levels have greater likelihood of usage, on other hand data sharing declines drastically with age.
                    <sup>
                        <xref ref-type="bibr" rid="ref16">16</xref>
                    </sup>
                </p>
                <p>Implantable cardioverter defibrillators, pacemakers, insulin pumps, deep brain stimulators and drug delivery systems are examples of IMDs used for long-term use, i.e. for the treatment of chronic diseases. However, former US Vice President Dick Cheney&#x2019;s wireless connectivity of heart pacemaker was disabled due to national security concerns, such as the pacemaker&#x2019;s set by cybercriminals at frequency being incompatible with life.
                    <sup>
                        <xref ref-type="bibr" rid="ref17">17</xref>
                    </sup> This applies not only to pacemakers, but also to other devices, such as insulin pumps, which may use similar principles to regulate insulin delivery, increasing medicaments dosage or brainjacking can lead to physical or psychological harm and even to death and experiments conducted by scientists show that this is indeed possible.
                    <sup>
                        <xref ref-type="bibr" rid="ref18">18</xref>&#x2013;
                        <xref ref-type="bibr" rid="ref20">20</xref>
                    </sup>
                </p>
                <p>Therefore, medical devices are subject to strict controls and regulations worldwide. In Europe, any medical device must be certified to ensure its safety, effectiveness and consistent quality level. If all regulatory requirements are met, the device can receive the CE mark in Europe.
                    <sup>
                        <xref ref-type="bibr" rid="ref21">21</xref>
                    </sup> It is important to notice that sensor specificity of current wearable devices can be low, which may lead to over detection of benign nonclinical related signals, resulting in misdiagnosis, unnecessary examinations, and patient anxiety.
                    <sup>
                        <xref ref-type="bibr" rid="ref22">22</xref>
                    </sup> Accordingly, the calibration process and protection against tampering with the set parameters become extremely important. This could give patients, their relatives and medical staff greater confidence in these devices. Bonan Zhang et al. in a 2025 survey on security and privacy issues in wearable health monitoring devices also noticed a lack of standard communication protocols, which could help manufacturers design new devices not only orienting towards development and design of risk assessment.
                    <sup>
                        <xref ref-type="bibr" rid="ref22">22</xref>
                    </sup> A good balance between regulation and innovation is necessary, as the constant progress in this field often outpaces regulatory updates, creating a significant gap between the development of wearable and implantable medical devices and the establishment of the necessary regulatory requirements.</p>
            </sec>
            <sec id="sec4">
                <title>1.3 Regulations, standards and guidelines for medical devices</title>
                <p>In the healthcare sector&#x2014;whether in hospitals or among medical device manufacturers&#x2014;patient safety remains the highest priority. To safeguard this principle, strict regulations, standards, and guidelines govern the development, calibration, use, and quality control of medical devices worldwide. Compliance with frameworks such as FDA guidelines requires structured risk management processes, comprehensive documentation, and clearly defined roles and responsibilities.
                    <sup>
                        <xref ref-type="bibr" rid="ref23">23</xref>
                    </sup>
                </p>
                <p>During data acquisition, risks inevitably arise as a combination of the potential consequences of unwanted events and the likelihood of their occurrence. Currently, no single standardized methodology exists for assessing software security and the risks specific to IoT-based measurement systems. As a result, manufacturers and researchers draw upon various standards and recommendations issued by international organizations such as ISO and WELMEC (European Cooperation in Legal Metrology).</p>
                <p>For IoT-related risk assessment, the ISO/IEC 27005:2022 standard provides guidance on managing information security, cybersecurity, and privacy risks.
                    <sup>
                        <xref ref-type="bibr" rid="ref26">26</xref>
                    </sup> More domain-specific is the WELMEC Guide 7.6 
                    <italic toggle="yes">Software Risk Assessment for Measuring Instruments,
</italic>
                    <sup>
                        <xref ref-type="bibr" rid="ref24">24</xref>
                    </sup> based on the EU Measuring Instruments Directive (2014/32/EU; MID). This directive defines legal requirements for measuring instruments falling under legal metrology, which manufacturers must meet before placing devices on the market. WELMEC Guide 7.6 further specifies risk classes, baseline requirements for embedded software in measurement instruments, and detailed provisions for long-term data storage and secure transmission of measurement results.</p>
                <p>In their survey, Karie et al. identified approximately 80 ISO/IEC security standards, 32 ETSI standards, and 37 conventional security assessment frameworks, including seven NIST special publications on security techniques applicable to IoT-enabled health monitoring environments.
                    <sup>
                        <xref ref-type="bibr" rid="ref25">25</xref>
                    </sup>
                </p>
                <p>
                    <xref ref-type="table" rid="T1">
Table 1</xref> below summarizes key international and national regulations, standards, and guidelines relevant to medical device calibration, cybersecurity, data integrity, metrology, and traceability. These frameworks form the basis for the Standard Operating Procedure (SOP) for secure calibration processes presented in the final chapter of this work.</p>
                <table-wrap id="T1" orientation="portrait" position="float">
                    <label>
Table 1. </label>
                    <caption>
                        <title>Regulation and standards for medical devices calibrations.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Category</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
Standard</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Key requirements/Purpose</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="4" valign="top">International standards for general calibration</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">ISO/IEC 17025:2017</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Ensures calibration labs are technically competent and traceable to SI units.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">ISO 9001:2015</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Establishes a quality management system with documented calibration procedures.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">ANSI/NCSL Z540.3-2006 (US)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Defines calibration system requirements including uncertainty evaluation.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">ANSI/NCSL Z540.3-2006 (US)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Guides calculation and reporting of calibration uncertainty.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="2" valign="top">International standards for medical devices</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">FDA 21 CFR Part 11</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Ensures secure and auditable electronic calibration records.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">ISO 13485</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Maintains safe and effective calibration processes for medical devices.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="4" valign="top">International Cybersecurity &amp; Data Integrity Standards</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">NIST SP 800-53 (Rev. 5)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Protects calibration systems with secure access controls.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">IEC 62443 (Industrial IoT Security)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Secures calibration in industrial systems against tampering.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">ISO/IEC 27001:2022</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Safeguards calibration data from unauthorized changes.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">NISTIR 8228 (IoT Security)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Recommends secure calibration practices for IoT devices.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="3" valign="top">International Metrology &amp; Traceability Standards</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">JCGM 100:2008 (GUM)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Standardizes how to report calibration uncertainty.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">BIPM SI Brochure (9th Edition)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Ensures calibration traceability to SI units.</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">EURAMET cg-18 (Europe)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Gives regional guidance for temperature device calibration.</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>These standards precisely describe how calibration laboratories, measurement systems and with them related processes must be done to ensure accuracy, reliability, and security. Medical devices are no exceptions; they must be calibrated following in standards described requirements. As already mentioned, they can be international or national, requirements or quality control tests may vary depending on this. Main European Union regulations are Medical Devices Regulation (MDR) describing how medical devices must be approved for safety and their performance.
                    <sup>
                        <xref ref-type="bibr" rid="ref26">26</xref>
                    </sup> The MDR also includes part about IT security in medical devices, to ensure data and device performance regulation from unauthorized access. As medical devices development never stops, new measurement methods, their implementation of IoT devices, hardware or software improvement also are necessary and regulations that must be regularly updated.</p>
            </sec>
        </sec>
        <sec id="sec5">
            <title>2. Key components of a cybersecurity protocol for calibration data security and calibration process security measures</title>
            <p>The main components ensuring the safety of the calibration process can be listed as follows: identification, protection, access control, detection, response, and recovery. During the identification phase we should understand and prioritize assets, risks, and vulnerabilities to ensure that all critical data and systems are recognized and assessed for potential threats. To make it easier to do this, it is recommended to use the following regulations on medical devices.
                <sup>
                    <xref ref-type="bibr" rid="ref27">27</xref>
                </sup> For protection of the measurement system, safeguards, firewalls should be implemented, used encryption protocols, and secure communication protocols to protect data and systems from unauthorized access and cyber threats.
                <sup>
                    <xref ref-type="bibr" rid="ref27">27</xref>,
                    <xref ref-type="bibr" rid="ref28">28</xref>
                </sup> Calibration data is particularly important; therefore, access control and multi-factor authentication should ensure only authorized personnel access of sensitive data.
                <sup>
                    <xref ref-type="bibr" rid="ref29">29</xref>
                </sup> During the system working time we should do non-stop monitoring, which will allow us to detect cybersecurity events promptly. Consequently, establishment of mechanisms detecting cybersecurity events such as intrusion detection systems which monitor for and respond to suspected security breaches.
                <sup>
                    <xref ref-type="bibr" rid="ref30">30</xref>
                </sup> During the response phase development and implementation of an effective response plan to address and mitigate the impact of cybersecurity incidents is essential.
                <sup>
                    <xref ref-type="bibr" rid="ref27">27</xref>
                </sup> Although manufacturers try to reduce the cost of equipment as much as possible, when it comes to the calibration process, we must ensure its recovery. At this stage we should ensure efficient recovery and resilience after a cybersecurity incident by having data backup and recovery plans in place.
                <sup>
                    <xref ref-type="bibr" rid="ref27">27</xref>,
                    <xref ref-type="bibr" rid="ref29">29</xref>
                </sup>
            </p>
            <p>It is also worth considering additional security measures such as Data Integrity and Cryptography Services, CIA Triad, Defense in Depth. Data Integrity and Cryptography Services ensure the integrity of data through cryptographic services and evaluate access requests based on roles. CIA Triad can emphasize confidentiality, integrity, and availability to prevent unauthorized access, ensure data accuracy, and optimize user access.
                <sup>
                    <xref ref-type="bibr" rid="ref31">31</xref>
                </sup> Defense in Depth (DID) implements a multilayered approach to security, making it difficult for attackers to bypass all security layers.
                <sup>
                    <xref ref-type="bibr" rid="ref32">32</xref>
                </sup>
            </p>
            <p>These previously mentioned components collectively form a robust cybersecurity protocol aimed at protecting calibration data from various cyber threats and ensuring the integrity and availability of the data. For IoT measuring systems, calibration security is critical to ensure data integrity, measurement accuracy, and system reliability. The calibration process must be protected against both intentional tampering and accidental errors.</p>
            <p>Key Security Measures for IoT Calibration Process Security are listed below in 
                <xref ref-type="table" rid="T2">
Table 2</xref>.</p>
            <table-wrap id="T2" orientation="portrait" position="float">
                <label>
Table 2. </label>
                <caption>
                    <title>Security measures and implementation recommendations.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">Security measure</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Method</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Implementation recommendations</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Authentication and Access Control</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Implemented multi-factor authentication for calibration personnel
                                <break/>Role-based access control for calibration functions
                                <break/>Secure credential management for calibration devices</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Secure Calibration Workflow: Establish a documented, auditable calibration procedure; Implement digital workflow with approval requirements; Include verification steps after calibration</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Data Integrity Protection</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Digital signatures for calibration certificates
                                <break/>Cryptographic hash verification of calibration parameters
                                <break/>Secure logging of all calibration activities with timestamps</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Device Security: Secure boot mechanisms for calibration equipment; Regular security updates for calibration software; Hardware security modules for sensitive operations</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Secure Communication</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Encrypted channels for calibration data transmission
                                <break/>Certificate-based device authentication
                                <break/>Protection against man-in-the-middle attacks during calibration</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Blockchain for immutable calibration records; AI-assisted anomaly detection in calibration data; Secure enclaves for calibration computations</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Physical Security</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Tamper-evident seals on calibration interfaces
                                <break/>Secure storage of calibration reference standards
                                <break/>Environmental monitoring for calibration areas</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Audit and Compliance: Maintain detailed calibration records with chain-of-custody; Regular security audits of calibration processes; Compliance with relevant standards (ISO/IEC 17025, NIST guidelines)</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Process Security</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Automated verification of calibration results against expected ranges
                                <break/>Cross-validation with redundant measurement systems when possible
                                <break/>Secure update mechanisms for calibration algorithms</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Anomaly Detection: Monitor for unusual calibration patterns; Implement alerts for suspicious calibration activities; Statistical process control for calibration results</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <p>Proper implementation of these security measures helps ensure that IoT measurement systems maintain their accuracy and reliability throughout their operational lifecycle.</p>
        </sec>
        <sec id="sec6">
            <title>3. Standard Operating Procedure (SOP) for secure IoT measuring system calibration</title>
            <p>Standard Operating Procedures (SOPs) are structured, written instructions designed to achieve uniformity and repeatability in critical processes. They are essential in high-risk industries such as healthcare, where quality, safety, and compliance with regulatory frameworks must be consistently maintained.
                <sup>
                    <xref ref-type="bibr" rid="ref33">33</xref>
                </sup> In this section, we propose a step-by-step SOP for the calibration of IoT-enabled medical measuring devices. The procedure clearly defines roles and responsibilities across participants, establishes common terminology to facilitate communication between IT engineers, medical staff, and measurement specialists, and integrates both metrological and cybersecurity requirements. While adaptable to other domains, the SOP is particularly tailored to reducing measurement uncertainties and mitigating risks related to data integrity and system security.</p>
            <p>The SOP consists of seven key components:
                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>Purpose</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>Scope</p>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>Responsibilities</p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>Equipment &amp; Requirements</p>
                    </list-item>
                    <list-item>
                        <label>5.</label>
                        <p>Procedure</p>
                    </list-item>
                    <list-item>
                        <label>6.</label>
                        <p>Records &amp; Compliance</p>
                    </list-item>
                    <list-item>
                        <label>7.</label>
                        <p>Training &amp; Competence</p>
                    </list-item>
                    <list-item>
                        <label>1.</label>
                        <p>Purpose. This SOP defines the secure calibration process for IoT measuring systems to ensure accuracy, data integrity, and protection against tampering or unauthorized modifications.</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>Scope. SOP applies to:
                            <list list-type="bullet">
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>IoT-based measurement devices requiring periodic calibration;</p>
                                </list-item>
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>Calibration technicians, engineers, and quality assurance personnel;</p>
                                </list-item>
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>Third-party calibration service providers, calibration laboratories.</p>
                                </list-item>
                            </list>
                        </p>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>Responsibilities are distributed among the participants in the process as follows:
                            <list list-type="bullet">
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>Quality Manager: Approves calibration procedures and audits compliance;</p>
                                </list-item>
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>Calibration Technician: Performs calibration following this SOP;</p>
                                </list-item>
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>IT Security Team: Ensures secure data transmission and access controls;</p>
                                </list-item>
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>Device Owner: Verifies calibration status and reports anomalies.</p>
                                </list-item>
                            </list>
                        </p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>Equipment &amp; Requirements. This part describes the equipment used inside the measuring process and requirements from a metrological and IT security perspective. It describes the following requirements:
                            <list list-type="bullet">
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>Certified reference standards (traceable to NIST/ISO/IEC 17025);</p>
                                </list-item>
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>Secure calibration software/hardware with authentication;</p>
                                </list-item>
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>Tamper-evident seals and logging tools;</p>
                                </list-item>
                                <list-item>
                                    <label>&#x2022;</label>
                                    <p>Encrypted communication channels.</p>
                                </list-item>
                            </list>
                        </p>
                    </list-item>
                    <list-item>
                        <label>5.</label>
                        <p>Procedure part is divided in following parts:</p>
                        <p>
5.1 Pre-Calibration Security Checks. Authentication should be done, therefore only authorized personnel with multi-factor authentication (MFA) may access calibration tools. Additionally, role-based permissions should be set in order to restrict calibration parameter changes. Device Integrity Check should be performed in order to verify that the IoT device has no physical tampering. For example, the responsible person should check that seals have no intact. The physical inspection of the measuring instrument is followed by the equipment software inspection and a check for firmware/software version consistency is applied in order to verify that there are no unauthorized modifications to source code. During the calibration process the secure connection setup should be done and the use of TLS/SSL encryption for data transfer between IoT device and calibration tool should be established. During connection setup the person, who makes calibration, should ensure calibration equipment has valid digital certificates.</p>
                        <p>
5.2 Calibration Execution is carried out by procedures and additional documents listed in ISO17025 standard. Firstly, reference standard verification is performed, i.e. it is checked if calibration standards are within validity period. Secondly, environmental conditions are recorded. In case of automated calibration process the cryptographically signed calibration scripts to prevent tampering should be used. In order to avoid environmental influences during calibration, it is necessary to ensure that as few environmental factors as possible are present during the process or their influence is minimized. For example, if wireless interference is a risk, calibration can be performed in a controlled environment like a Faraday cage. Thirdly, if applicable the cross-validation can be done to ensure the quality of calibration. In this step we can compare results with a secondary reference device and apply statistical checks to detect anomalies.</p>
                        <p>
5.3 Post-Calibration Security Measures. At this step following tasks should be executed: Digital Certification &amp; Logging, Tamper-Evident Sealing and Data Sync &amp; Backup. A digitally signed calibration certificate will be generated, with its hash stored in a secure ledger to ensure authenticity. All actions, including the responsible technician, timestamps, and adjustments, will be logged for audit purposes. Tamper-evident seals will be applied to calibration ports, and each seal&#x2019;s unique ID will be recorded in the calibration log. Calibration data will be securely transmitted to the central IoT management system, and backup logs will be preserved in a write-once, read-many (WORM) system to prevent tampering.</p>
                        <p>
5.4 Anomaly Handling. During calibration, unexpected events may occur that may affect the overall performance of the measurement system, therefore, after the process we must investigate if calibration results deviate beyond acceptable limits. If so, we should flag the device for investigation. During calibration, data are exchanged between the reference device and the calibrated device. At this point, hacking is possible, therefore, a check for potential cybersecurity breaches (e.g., firmware tampering) must be performed. If malicious activity is suspected the steps of escalation of the IT security team should be defined.</p>
                    </list-item>
                    <list-item>
                        <label>6.</label>
                        <p>Records &amp; Compliance. All mandatory documentation must be maintained, including digitally signed calibration certificates, access logs identifying the personnel, who performed the calibration, environmental condition records (where applicable), and cryptographic hash values of calibration parameters. An audit trail shall be preserved for a minimum of several years in accordance with regulatory requirements, with all logs stored in an immutable format&#x2014;preferably using blockchain or WORM-based systems.</p>
                    </list-item>
                    <list-item>
                        <label>7.</label>
                        <p>Training &amp; Compliance. All personnel are required to complete training in both calibration procedures and cybersecurity awareness, and annual re-certification is mandatory to maintain compliance and competence for persons involved in the calibration process.</p>
                    </list-item>
                </list>
            </p>
        </sec>
        <sec id="sec7" sec-type="conclusions">
            <title>4. Conclusions</title>
            <p>Although we can say in a simplified way that only data is exchanged during the calibration process, it is particularly important to understand how important this data is for the safety of devices. The development of the Standard Operating Procedure helps to avoid malfunctions in measuring instruments, which can result in huge losses or even fatalities, when it comes to medical devices. After conducting a literature review on the cybersecurity of medical measuring instruments, calibration and IoT devices, it is quite clear that metrology is closely related to IT and medicine and when solving the issue of security of medical measuring instruments, knowledge of only one area is not enough. Therefore, interdisciplinary cooperation is necessary, i.e. after calibration, anomaly handling must be performed by a medical technician or measurement specialist, who will be able to notice deviations of the measuring instrument from the usual mode. The IT professional from his side can program that the malfunction is noticed as soon as possible after using AI and ML tools.</p>
            <p>The ever-increasing number of IoT devices, including in medicine, poses increasing security and metrology problems, which can be solved only by digitizing the international metrology system. The use of digital calibration certificates, the creation of calibration as a service and calibration as infrastructure are the first steps towards ensuring the quality of a global quality infrastructure. As the only way to ensure the quality of the measurements made, we see ensuring periodic calibration of measuring instruments, which due to the abundance of IoT devices will be forced to move from physical laboratories as close as possible to the sensors, i.e. more and more wandering will be carried out on site instead of doing it in the laboratory.</p>
            <p>Interdisciplinary projects within educational programs are fundamentally important. They unite students from diverse fields such as medicine, electronics, and IT, providing crucial exposure to the integrated processes that ensure the reliable operation of medical Internet of Things (IoT) devices.</p>
            <p>A practical example of this approach was a project that brought together three different institutions. Under the guidance of a professor from measurement sciences, a team was formed comprising students from medical, IT, and electronics disciplines. This collaboration was highly productive, resulting in the creation of a detailed Standard Operating Procedure (SOP).</p>
            <p>This SOP is not merely an academic exercise; it is designed to serve as the foundational framework for future experiments and development. Its primary future application will be in the creation of a &#x201c;calibration-as-a-service&#x201d; solution for medical IoT devices. This service will streamline the development process and ensure consistent, traceable calibration.</p>
            <p>Therefore, promoting this type of interdisciplinary cooperation between the scientific fields of IT, medicine, electronics, and measurement engineering is essential. It is through such partnerships that we can develop the necessary infrastructure to guarantee data security and establish measurement uniformity. As a direct result, we will be able to confidently rely on the data generated by measuring instruments used in clinical medicine, thereby enhancing patient care and safety.</p>
            <p>Declaration of Generative AI and AI-assisted technologies in the writing process.</p>
            <p>The GPT-5 was used for language improvement and idea exploration.</p>
        </sec>
    </body>
    <back>
        <sec id="sec10" sec-type="data-availability">
            <title>Data availability</title>
            <p>No data are associated with this article.</p>
        </sec>
        <ref-list>
            <title>References</title>
            <ref id="ref1">
                <label>1</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kairi&#x016b;k&#x0161;tis</surname>
                            <given-names>L</given-names>
                        </name>
</person-group>:
                    <article-title>Metrology Challenges in Implementing Digital Calibration Certificates for Internet of Things Measurement (Iotm) Devices.</article-title>
                    <year>2023</year>.</mixed-citation>
            </ref>
            <ref id="ref2">
                <label>2</label>
                <mixed-citation publication-type="other">
                    <article-title>International vocabulary of metrology &#x2013; Basic and general concepts and associated terms (VIM) 3rd edition.</article-title>
                    <year>2012</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.bipm.org/documents/20126/2071204/JCGM_200_2012.pdf/f0e1ad45-d337-bbeb-53a6-15fe649d0ff1">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref3">
                <label>3</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <collab>Department of Pharmaceutics, Government Pharmacy Institute, Patna, Bihar-800007, India</collab>

                        <name name-style="western">
                            <surname>Kumar</surname>
                            <given-names>R</given-names>
                        </name>
</person-group>:
                    <article-title>Calibration of Medical Devices: Method and Impact on Operation Quality.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Pharm. Sci.</italic>
</source>
                    <year>2023</year>;<volume>16</volume>:<fpage>1</fpage>&#x2013;<lpage>14</lpage>.
                    <pub-id pub-id-type="doi">10.31531/2231-5896.1000128</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref4">
                <label>4</label>
                <mixed-citation publication-type="other">
                    <collab>Global Market Insights Inc</collab>:
                    <article-title>Medical Equipment Calibration Services Market &#x2013; By Service Type, By Equipment Type, By Calibration Type, By End Use &amp; Global Forecast, 2025-2034.</article-title>
                    <year>2025</year>.</mixed-citation>
            </ref>
            <ref id="ref5">
                <label>5</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mustapaa</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Autiosalo</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Nikander</surname>
                            <given-names>P</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Digital Metrology for the Internet of Things.</chapter-title>
                    <source>

                        <italic toggle="yes">2020 Global Internet of Things Summit (GIoTS).</italic>
</source>
                    <publisher-loc>Dublin, Ireland</publisher-loc>:
                    <publisher-name>IEEE</publisher-name>;<year>2020</year>; pp.<fpage>1</fpage>&#x2013;<lpage>6</lpage>.
                    <pub-id pub-id-type="doi">10.1109/GIOTS49054.2020.9119603</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref6">
                <label>6</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Balslev-Harder</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bo&#x0161;njakovi&#x0107;</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Brown</surname>
                            <given-names>C</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>DCC2GO &#x2013; Supporting the implementation of Digital Calibration Certificates in the European metrology community.</article-title>
                    <source>

                        <italic toggle="yes">Measurement: Sensors.</italic>
</source>
                    <year>2025</year>;<volume>38</volume>:<fpage>101499</fpage>.
                    <pub-id pub-id-type="doi">10.1016/j.measen.2024.101499</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref7">
                <label>7</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hutzschenreuter</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>H&#x00e4;rtig</surname>
                            <given-names>F</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Wiedenh&#x00f6;fer</surname>
                            <given-names>T</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>SmartCom Digital-SI (D-SI) XML exchange format for metrological data version 1.3.0.</article-title>
                    <year>2019</year>.
                    <pub-id pub-id-type="doi">10.5281/ZENODO.3366902</pub-id>
                    <ext-link ext-link-type="uri" xlink:href="https://zenodo.org/record/3366902">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref8">
                <label>8</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Nikander</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Elo</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mustap&#x00e4;&#x00e4;</surname>
                            <given-names>T</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Document specifying rules for the secure use of DCC covering legal aspects of metrology.</article-title>
                    <year>2020</year>.
                    <pub-id pub-id-type="doi">10.5281/ZENODO.3664211</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref9">
                <label>9</label>
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Grasso Toro</surname>
                            <given-names>F</given-names>
                        </name>
</person-group>:
                    <article-title>PDF/A-3 solution for digital calibration certificates.</article-title>
                </mixed-citation>
            </ref>
            <ref id="ref10">
                <label>10</label>
                <mixed-citation publication-type="other">
                    <article-title>Grand View Research: Wearable Medical Devices Market Summary. </article-title>
                    <year>2024</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.grandviewresearch.com/industry-analysis/wearable-medical-devices-market">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref11">
                <label>11</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Canali</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Schiaffonati</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Aliverti</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Challenges and recommendations for wearable devices in digital health: Data quality, interoperability, health equity, fairness.</article-title>
                    <source>

                        <italic toggle="yes">PLOS Digit. Health.</italic>
</source>
                    <year>2022</year>;<volume>1</volume>:<fpage>e0000104</fpage>.
                    <pub-id pub-id-type="pmid">36812619</pub-id>
                    <pub-id pub-id-type="doi">10.1371/journal.pdig.0000104</pub-id>
                    <pub-id pub-id-type="pmcid">PMC9931360</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref12">
                <label>12</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Iqbal</surname>
                            <given-names>SMA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mahgoub</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Du</surname>
                            <given-names>E</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Advances in healthcare wearable devices.</article-title>
                    <source>

                        <italic toggle="yes">NPJ Flexible Electron.</italic>
</source>
                    <year>2021</year>;<volume>5</volume>:<fpage>9</fpage>.
                    <pub-id pub-id-type="doi">10.1038/s41528-021-00107-x</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref13">
                <label>13</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Godinho</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Domingos</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Cunha</surname>
                            <given-names>G</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>A systematic review of the characteristics and validity of monitoring technologies to assess Parkinson&#x2019;s disease.</article-title>
                    <source>

                        <italic toggle="yes">J. NeuroEngineering Rehabil.</italic>
</source>
                    <year>2016</year>;<volume>13</volume>:<fpage>24</fpage>.
                    <pub-id pub-id-type="pmid">26969628</pub-id>
                    <pub-id pub-id-type="doi">10.1186/s12984-016-0136-7</pub-id>
                    <pub-id pub-id-type="pmcid">PMC4788909</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref14">
                <label>14</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Azodo</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Williams</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sheikh</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Opportunities and Challenges Surrounding the Use of Data From Wearable Sensor Devices in Health Care: Qualitative Interview Study.</article-title>
                    <source>

                        <italic toggle="yes">J. Med. Internet Res.</italic>
</source>
                    <year>2020</year>;<volume>22</volume>:<fpage>e19542</fpage>.
                    <pub-id pub-id-type="pmid">33090107</pub-id>
                    <pub-id pub-id-type="doi">10.2196/19542</pub-id>
                    <pub-id pub-id-type="pmcid">PMC7644375</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref15">
                <label>15</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Hall</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Walton</surname>
                            <given-names>G</given-names>
                        </name>
</person-group>:
                    <article-title>Information overload within the health care system: a literature review.</article-title>
                    <source>

                        <italic toggle="yes">Health Inf. Libr. J.</italic>
</source>
                    <year>2004</year>;<volume>21</volume>:<fpage>102</fpage>&#x2013;<lpage>108</lpage>.
                    <pub-id pub-id-type="doi">10.1111/j.1471-1842.2004.00506.x</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref16">
                <label>16</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chandrasekaran</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sadiq</surname>
                            <given-names>TM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Moustakas</surname>
                            <given-names>E</given-names>
                        </name>
</person-group>:
                    <article-title>Usage Trends and Data Sharing Practices of Healthcare Wearable Devices Among US Adults: Cross-Sectional Study.</article-title>
                    <source>

                        <italic toggle="yes">J. Med. Internet Res.</italic>
</source>
                    <year>2025</year>;<volume>27</volume>:<fpage>e63879</fpage>.
                    <pub-id pub-id-type="pmid">39982763</pub-id>
                    <pub-id pub-id-type="doi">10.2196/63879</pub-id>
                    <pub-id pub-id-type="pmcid">PMC11890132</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref17">
                <label>17</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Dick Cheney</surname>
                            <given-names>RB</given-names>
                        </name>
</person-group>:
                    <article-title>Reflections of a Former Vice President on Long-Time Cardiac Experiences.</article-title>
                    <source>

                        <italic toggle="yes">Baylor Univ. Med. Cent. Proc.</italic>
</source>
                    <year>2009</year>;<volume>22</volume>:<fpage>276</fpage>&#x2013;<lpage>278</lpage>.
                    <pub-id pub-id-type="pmid">21240297</pub-id>
                    <pub-id pub-id-type="doi">10.1080/08998280.2009.11928531</pub-id>
                    <pub-id pub-id-type="pmcid">PMC2709093</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref18">
                <label>18</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Best</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <article-title>Could implanted medical devices be hacked?</article-title>
                    <source>

                        <italic toggle="yes">BMJ.</italic>
</source>
                    <year>2020</year>;<volume>368</volume>:<fpage>m102</fpage>.
                    <pub-id pub-id-type="pmid">31937555</pub-id>
                    <pub-id pub-id-type="doi">10.1136/bmj.m102</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref19">
                <label>19</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rehman</surname>
                            <given-names>MMU</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rehman</surname>
                            <given-names>HZU</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Khan</surname>
                            <given-names>ZH</given-names>
                        </name>
</person-group>:
                    <article-title>Cyber-Attacks on Medical Implants: A Case Study of Cardiac Pacemaker Vulnerability.</article-title>
                    <source>

                        <italic toggle="yes">IJCDS.</italic>
</source>
                    <year>2020</year>;<volume>09</volume>:<fpage>1229</fpage>&#x2013;<lpage>1235</lpage>.
                    <pub-id pub-id-type="doi">10.12785/ijcds/0906020</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref20">
                <label>20</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pugh</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Pycroft</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sandberg</surname>
                            <given-names>A</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Brainjacking in deep brain stimulation and autonomy.</article-title>
                    <source>

                        <italic toggle="yes">Ethics Inf. Technol.</italic>
</source>
                    <year>2018</year>;<volume>20</volume>:<fpage>219</fpage>&#x2013;<lpage>232</lpage>.
                    <pub-id pub-id-type="pmid">30595661</pub-id>
                    <pub-id pub-id-type="doi">10.1007/s10676-018-9466-4</pub-id>
                    <pub-id pub-id-type="pmcid">PMC6290799</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref21">
                <label>21</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ravizza</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>De Maria</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Di Pietro</surname>
                            <given-names>L</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Comprehensive Review on Current and Future Regulatory Requirements on Wearable Sensors in Preclinical and Clinical Testing.</article-title>
                    <source>

                        <italic toggle="yes">Front. Bioeng. Biotechnol.</italic>
</source>
                    <year>2019</year>;<volume>7</volume>:<fpage>313</fpage>.
                    <pub-id pub-id-type="pmid">31781554</pub-id>
                    <pub-id pub-id-type="doi">10.3389/fbioe.2019.00313</pub-id>
                    <pub-id pub-id-type="pmcid">PMC6857326</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref22">
                <label>22</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zhang</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chen</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Lee</surname>
                            <given-names>I</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>A survey on security and privacy issues in wearable health monitoring devices.</article-title>
                    <source>

                        <italic toggle="yes">Comput. Secur.</italic>
</source>
                    <year>2025</year>;<volume>155</volume>:<fpage>104453</fpage>.
                    <pub-id pub-id-type="doi">10.1016/j.cose.2025.104453</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref23">
                <label>23</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ramalingam</surname>
                            <given-names>PS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Muthunayagam</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <chapter-title>Medical device portfolio cleanup.</chapter-title>
                    <source>

                        <italic toggle="yes">Trends in Development of Medical Devices.</italic>
</source>
                    <publisher-name>Elsevier</publisher-name>;<year>2020</year>; pp.<fpage>155</fpage>&#x2013;<lpage>176</lpage>.
                    <pub-id pub-id-type="doi">10.1016/B978-0-12-820960-8.00009-5</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref24">
                <label>24</label>
                <mixed-citation publication-type="other">
                    <article-title>WELMEC Guide 7.6 Software Risk Assessment for Measuring Instruments. </article-title>
                    <year>2021</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.welmec.org/welmec/documents/guides/7.6/2021/WELMEC_Guide_7.6_v2021.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref25">
                <label>25</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Karie</surname>
                            <given-names>NM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sahri</surname>
                            <given-names>NM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Yang</surname>
                            <given-names>W</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>A Review of Security Standards and Frameworks for IoT-Based Smart Environments.</article-title>
                    <source>

                        <italic toggle="yes">IEEE Access.</italic>
</source>
                    <year>2021</year>;<volume>9</volume>:<fpage>121975</fpage>&#x2013;<lpage>121995</lpage>.
                    <pub-id pub-id-type="doi">10.1109/ACCESS.2021.3109886</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref26">
                <label>26</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pandey</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gupta</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <chapter-title>Image encryption of medical images.</chapter-title>
                    <source>

                        <italic toggle="yes">Advances in Computers.</italic>
</source>
                    <publisher-name>Elsevier</publisher-name>;<year>2025</year>; pp.<fpage>345</fpage>&#x2013;<lpage>406</lpage>.
                    <pub-id pub-id-type="doi">10.1016/bs.adcom.2024.05.002</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref27">
                <label>27</label>
                <mixed-citation publication-type="other">
                    <article-title>Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (Text with EEA relevance.).</article-title>
                    <year>2025</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://eur-lex.europa.eu/eli/reg/2017/745/oj/eng">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref28">
                <label>28</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Karner</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Peltola</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jerne</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <source>

                        <italic toggle="yes">Intelligent Secure Trustable Things.</italic>
</source>
                    <publisher-loc>Cham</publisher-loc>:
                    <publisher-name>Springer Nature Switzerland</publisher-name>;<year>2024</year>.
                    <pub-id pub-id-type="doi">10.1007/978-3-031-54049-3</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref29">
                <label>29</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Xie</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Song</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shi</surname>
                            <given-names>Z</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Reinforcement learning for vehicle-to-grid: A review.</article-title>
                    <source>

                        <italic toggle="yes">Advances in Applied Energy.</italic>
</source>
                    <year>2025</year>;<volume>17</volume>:<fpage>100214</fpage>.
                    <pub-id pub-id-type="doi">10.1016/j.adapen.2025.100214</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref30">
                <label>30</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Yalli</surname>
                            <given-names>JS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hasan</surname>
                            <given-names>MH</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jung</surname>
                            <given-names>LT</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Authentication schemes for Internet of Things (IoT) networks: A systematic review and security assessment.</article-title>
                    <source>

                        <italic toggle="yes">Internet of Things.</italic>
</source>
                    <year>2025</year>;<volume>30</volume>:<fpage>101469</fpage>.
                    <pub-id pub-id-type="doi">10.1016/j.iot.2024.101469</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref31">
                <label>31</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Villarreal</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Fontecha</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hervas</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Mobile and ubiquitous architecture for the medical control of chronic diseases through the use of intelligent devices: Using the architecture for patients with diabetes.</article-title>
                    <source>

                        <italic toggle="yes">Futur. Gener. Comput. Syst.</italic>
</source>
                    <year>2014</year>;<volume>34</volume>:<fpage>161</fpage>&#x2013;<lpage>175</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.future.2013.12.013</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref32">
                <label>32</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Chhor</surname>
                            <given-names>CM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Raichandani</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Du Preez</surname>
                            <given-names>L</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Data governance in radiology Part I: Overview of data management approaches to radiology.</article-title>
                    <source>

                        <italic toggle="yes">Curr. Probl. Diagn. Radiol.</italic>
</source>
                    <year>2025</year>;<volume>54</volume>:<fpage>554</fpage>&#x2013;<lpage>561</lpage>.
                    <pub-id pub-id-type="pmid">40506277</pub-id>
                    <pub-id pub-id-type="doi">10.1067/j.cpradiol.2025.06.004</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref33">
                <label>33</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Johnson</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Morais</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Patelli</surname>
                            <given-names>E</given-names>
                        </name>
</person-group>:
                    <article-title>Enhancing procedure quality: Advanced language tools for identifying ambiguity and high-potential violation triggers.</article-title>
                    <source>

                        <italic toggle="yes">Reliab. Eng. Syst. Saf.</italic>
</source>
                    <year>2025</year>;<volume>264</volume>:<fpage>111308</fpage>.
                    <pub-id pub-id-type="doi">10.1016/j.ress.2025.111308</pub-id>
                </mixed-citation>
            </ref>
        </ref-list>
    </back>
    <sub-article article-type="reviewer-report" id="report453628">
        <front-stub>
            <article-id pub-id-type="doi">10.5256/f1000research.189694.r453628</article-id>
            <title-group>
                <article-title>Reviewer response for version 1</article-title>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author">
                    <name>
                        <surname>Cook</surname>
                        <given-names>David M.</given-names>
                    </name>
                    <xref ref-type="aff" rid="r453628a1">1</xref>
                    <role>Referee</role>
                    <uri content-type="orcid">https://orcid.org/0000-0002-2264-8719</uri>
                </contrib>
                <aff id="r453628a1">
                    <label>1</label>Edith Cowan University, Joondalup, Australia</aff>
            </contrib-group>
            <author-notes>
                <fn fn-type="conflict">
                    <p>
                        <bold>Competing interests: </bold>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>20</day>
                <month>2</month>
                <year>2026</year>
            </pub-date>
            <permissions>
                <copyright-statement>Copyright: &#x00a9; 2026 Cook DM</copyright-statement>
                <copyright-year>2026</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access peer review report distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <related-article ext-link-type="doi" id="relatedArticleReport453628" related-article-type="peer-reviewed-article" xlink:href="10.12688/f1000research.172017.1"/>
            <custom-meta-group>
                <custom-meta>
                    <meta-name>recommendation</meta-name>
                    <meta-value>approve-with-reservations</meta-value>
                </custom-meta>
            </custom-meta-group>
        </front-stub>
        <body>
            <p>This article makes an argument that because of the sheer number of IoTs that their calibration must be handled through service-driven systems that reside on-site rather than in their own location or in buildings, labs and other areas.&#x00a0; Whilst the paper argues for a standardised approach in terms of procedure, there is an opportunity to build this into a more structured and articulated threat model. The article is well grounded and has incorporated a broad range of appropriate ISO standards to create the right connectors for this type of standard operating procedure to have merit. My suggestion to the authors is simply to take it further and devise an appropriate threat model to complete the process.</p>
            <p> </p>
            <p> With a clearly described threat model - this article can then lay a much stronger claim to assist with a greater number of calibration extensions - allowing for calibration workflows for attack surfaces, assets and trust boundaries.&#x00a0; This would also allow for a strong link between standard operating procedures, standards controls, and specific threats.</p>
            <p> </p>
            <p> I also suggest to the authors to consider strengthening the reference material upon which this article is anchored. Some of the narrative that describes bold numbers such as wearables value by the year 2030, and numbers such as "seven billion IoT measuring devices" as stated in the abstract would seem more credible with greater support from quality citations. It is important to go beyond unsupported claims or just claims that are supported by market reports. Please consider a stronger connection to the literature that includes genuinely robust citations that are reputable and demonstrate the article's connection to a wider range of respected and valued field-weighted citations. I think there is considerable room to clarify the key area of measurement integrity. It would be very useful to show differentiation between problem areas such as metrology uncertainty, and drift, and the other side of this narrative in terms of cyber integrity such as Man in the Middle attacks, spoofing, and rollback integrity where we can get a sense of the need for the ability to restore data, restore software and return to uncorrupted environments. My suggestion is that the authors should look to clarify, define and differentiate these areas.</p>
            <p> </p>
            <p> There are several linkages to market reports and internal company reports, which are insufficient as reference material unless there is also the strong inclusion of peer-reviewed sources that carry greater weight and provide better validity to claims, especially where there are opportunities to include individual technical sources that provide more strongly weighted&#x00a0; support in areas relating to threats and their mitigations.</p>
            <p> </p>
            <p> Overall, the article is readable and accessible. there are some annoying inconsistencies with terminology acronyms such as the different versions of IOT vs IoT vs IoTM and even IoTM devices and Iotm. I suggest a cleanup in that sense.</p>
            <p>Is the review written in accessible language?</p>
            <p>Yes</p>
            <p>Are all factual statements correct and adequately supported by citations?</p>
            <p>Partly</p>
            <p>Are the conclusions drawn appropriate in the context of the current research literature?</p>
            <p>Partly</p>
            <p>Is the topic of the review discussed comprehensively in the context of the current literature?</p>
            <p>Partly</p>
            <p>Reviewer Expertise:</p>
            <p>My research areas are strongly anchored to NIST-driven environments. I am genuinely interested in the subject matter of this article and its usability if improved on a more robust level.</p>
            <p>I confirm that I have read this submission and believe that I have an appropriate level of expertise to confirm that it is of an acceptable scientific standard, however I have significant reservations, as outlined above.</p>
        </body>
    </sub-article>
</article>
