Table 9.1.
Cybersecurity measures for an IoT device and an IoT system (Source: ETSI).

The IoT Devices or the IoT System requires at least one administrative user, that is, a user having the ability to operate with elevated privileges inside the IoT Devices or the IoT System (e.g., definition of other users, reset of their passwords).

The IoT Devices or the IoT System requires the passing of an authentication procedure (e.g., login) before being able to allow the processing of any personal data. This authentication procedure verifies the username and a password of at least of 8 characters in length and containing alphanumeric, special, and uppercase characters.

The IoT Devices or the IoT System requires strong authentication e.g., (multi-factor authentication, possession or biometrics). For IoT Devices or the IoT System that have stateless systems in general, the IoT Devices or the IoT System generates a token to associate to the session. The token associated with the session of the web IoT Devices or the IoT System or stateless systems is sufficiently long (64 or more alphanumeric characters) and impossible to guess. The token associated with the session of the IoT Devices or the IoT System or stateless systems has an expiration time.

The IoT Devices or the IoT System stores the password within its database in encrypted form.

The IoT Devices or the IoT System uses a hashing algorithm suitable for password encryption.

The IoT Devices or the IoT System implements automated password selection restrictions (e.g., a minimum number of characters is set, and it ignores common or user-referenced passwords). When the user ID is associated to an email address, the IoT Devices or the IoT System requires such email address to be verified. Email addresses associated with a user ID are periodically verified to ensure that the email is still valid and in use.

The IoT Devices or the IoT System limits or throttles the availability of logins in the event of an abnormal number of unsuccessful access attempts occurring within a short time frame.

The IoT Devices or the IoT System allows each of its administrative users to assign different permission levels to different users.

The IoT Devices or the IoT System prevents any non-administrative user from changing the permission levels assigned to other users.

The IoT Devices or the IoT System protects the data it allows to be processed through pseudonymization techniques.

The IoT Devices or the IoT System protects the data that it allows to be processed through transparent encryption techniques. Data processed through the IoT Devices or the IoT System are appropriately classified (e.g., common, particular, judicial, subdivisions in personalized under systems).

The IoT Devices or the IoT System transmits network traffic in a protected from via stateof-the-art security protocols (e.g., TLS1.2, valid certificates, HSTS). Data processed with the help of the IoT Devices or the IoT System are backed up at least daily. Data processed with the help of the IoT Devices or the IoT System can be restored quickly.

The IoT Devices or the IoT System is currently supported (e.g., through the release of security updates and patches).

The IoT Devices or the IoT System is constantly kept up to date. The IoT Devices or the IoT System is periodically subjected to sessions of vulnerability assessment and penetration testing to assert its robustness to cyberattacks.

The IoT Devices or the IoT System generates access logs.

The IoT Devices or the IoT System generates logs of critical actions (e.g., creation or removal of content or users).

The IoT Devices or the IoT System generates logs of the performed processes.

The logs are complete, unalterable, and stored for at least six months; the integrity of the logs can be verified. If the IoT Devices or the IoT System is connected with smartphones and requires permissions on the device, it provides policies that describe the purposes of the processing enabled by each permission. If the IoT Devices or the IoT System is connected with smartphones, it never uses the Device ID as a key to identify a record. If the IoT Devices or the IoT System is for smartphones, it uses certified pinning techniques to avoid MITM attacks.

The IoT Devices or the IoT System code does not contain confidential credential components (e.g., passwords, tokens, keys …). The IoT code is developed in accordance with the guidelines for secure code (e.g., CERT, OWASP …).

or Create an Account

Close Modal
Close Modal