TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

    November 7, 2022

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

      November 7, 2022

      Devialet brings its sci-fi design aesthetics to a $790 portable speaker

      November 7, 2022

      Elon Musk’s response to fake verified Elon Twitter accounts: a new permanent ban policy for impersonation

      November 7, 2022

      The iPhone 14 Pro and Pro Max will come with ‘longer wait times’ due to factory lockdown

      November 6, 2022

      Meta’s reportedly planning to lay off ‘thousands’ of workers this week

      November 6, 2022
    • Business
    • Cyber Security
      National Security News

      List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

      September 24, 2022

      Cybersecurity ranked most serious enterprise risk in 2022

      August 31, 2022

      Registration open for CISA virtual summit on K-12 school safety

      August 31, 2022

      What do the Trickbot leaks reveal about Russian cybercrime?

      August 31, 2022

      What cybersecurity measures do CISOs outsource?

      August 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»European Telecommunications Standards Institute Publishes New IoT Security Standard
    Cyber Security

    European Telecommunications Standards Institute Publishes New IoT Security Standard

    February 25, 2019Updated:February 25, 2019No Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email


    On February 19, the European Telecommunications Standards Institute (ETSI) published the ETSI TS 103 645 V1.1.1 — or more simply, a high-level outcome-focused standard (PDF) for cybersecurity in the consumer-oriented Internet of Things (IoT).

    ETSI is an independent not-for-profit standards organization based in France with 800 members in 66 countries across the world. It is one of just three bodies officially recognized by the EU as a European Standards Organization (ESO).

    The hope of the new standard is that it will provide the basis for future IoT certification schemes designed to prevent the loss of users’ personal data in breach of GDPR, and the recruitment of consumer IoT devices into botnets (think Mirai) used to DDoS corporations.

    The cybersecurity provisions are provided in section 4 of the standard. There are thirteen in total, some being simple statements and others comprising multiple subsections. For example, the total of provision 4.1 requires little more than its heading: “No universal default passwords.”

    Provision 4.3 (“Keep software updated”), however, has nine subsections. 4.3.8, as an example, demands: “For constrained devices that cannot have their software updated, the product should be isolable and the hardware replaceable.”

    The remaining eleven provisions at their highest level are, manage vulnerability reports; securely store security-sensitive data; communicate securely; minimize attack surfaces; ensure software integrity; protect personal data; be resilient to outages; make use of telemetry data; allow users to delete personal data; make installation and maintenance easy; and validate input data. Most provisions then have multiple sub-sections providing more detailed specifications.

    There can be little doubt that manufacturers’ adherence to this standard would lead to a more secure IoT. But there is a common belief that if a standard isn’t required, it won’t be adopted. Without enforcement, the danger is that the ETSI standard is little more than a list of best practices that are already well-known within the industry. The question is not whether the standard is good — it is — but whether it will be used. Without enforcement, the danger is that the commercial pressures of speed-to-market will continue to suppress best practice and security-by-design in IoT device manufacture.

    Fausto Oliveira, principal security architect at Acceptto, believes that lack of enforcement may be problematic. “ETSI is a respected standards body that does not have legal power to enforce standards,” he told SecurityWeek. “Therefore, the real question is will any of the EU member states adopt legislation that would make this standard mandatory? Only time can tell if this standard will be adopted into law.”

    There is, however, a mechanism that could effectively make the standard enforceable in Europe and wider without new legislation. If the European regulators individually — but better collectively under the aegis of the European Data Protection Board — provide advice to IoT manufacturers that the ETSI standard will be taken into consideration in any GDPR action against those manufacturers, then conformance will be a way of complying with GDPR.

    GDPR compliance was certainly top-of-mind in developing the standard. In its announcement, ETSI commented, “As many IoT devices and services process and store personal data, this specification can help ensure that these are compliant with the General Data Protection Regulation (GDPR).”

    “Weíve already seen consumer devices pulled from the shelves or online stores in the EU due to privacy concerns, and this will help manufacturers avoid such a fate in the future,” adds David Ginsburg, VP of marketing at Cavirin. Earlier this month, the European Commission ordered the recall of a children’s smart watch manufactured in Germany, saying, “the watch has unencrypted communications with its backend server and the server enables unauthenticated access to data.”

    The underlying question with the ETSI standard is whether it can stand on its own without actual legislative support. One possible route is by reference, and NIST is an example. NIST guidelines do not have legal weight outside of government departments and agencies — nevertheless, its guidelines are often referenced within legislation, giving them the weight of law.

    “Remember that any regulations need some “source of truthí as a baseline, and this will fulfill that role,” explains Ginsburg. “If we look at California, the planned consumer IoT law (SB-327 – Information privacy: connected devices) calls for many of the same protections, but the ability to reference something like what ETSI has published would make it more rigorous.î

    The closest parallel that Europe has to NIST is ENISA. ENISA has already published a far more demanding IoT document: “Baseline Security Recommendations for IoT in the context of Critical Information Infrastructures”. ENISA is also likely to play an important part in the future of the ETSI standard. The EU’s Cybersecurity Act now only requires formal adoption by the European Parliament (starting in March 2019) and the agreement of the Council of the EU before becoming law. Part of that law will establish ENISA as the EU certification body. It needs only develop an official certification for the ETSI standard to ensure its future.

    ETSI states in its announcement that its standard is designed “to establish a security baseline for internet-connected consumer products and provide a basis for future IoT certification schemes.”

    There will still be difficulties. As Oliveira notes, “If it is a self-certification scheme then it becomes a paper exercise; on the other hand, if it requires access to source code in order to achieve certification, I imagine that there will be a great degree of opposition from businesses.”

    ETSI’s standard is aimed at consumer IoT, while ENISA’s existing recommendations are aimed at critical infrastructure IoT. The basic principles of secure design, manufacture and use will be common to both areas. The strength of ETSI’s document is that it is eminently approachable and easy to understand. Whether or not it ever gains any legislative force or reference, it is a valuable central source for best practices.

    Related: As IoT Grows, Confidence in Security Remains Low 

    Related: Industrial Internet Consortium Develops New IoT Security Maturity Model 

    Related: Mozilla, Others Want Big Retailers to Pledge Minimum IoT Security 

    Related: NIST Working on Global IoT Cybersecurity Standards 

    Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

    Previous Columns by Kevin Townsend:
    Tags:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Security News

    List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

    September 24, 2022 Cyber Security

    Cybersecurity ranked most serious enterprise risk in 2022

    August 31, 2022 Cyber Security

    Registration open for CISA virtual summit on K-12 school safety

    August 31, 2022 Cyber Security

    What do the Trickbot leaks reveal about Russian cybercrime?

    August 31, 2022 Cyber Security

    What cybersecurity measures do CISOs outsource?

    August 30, 2022 Cyber Security

    SIA announces Women in Security Forum scholarship recipients

    August 30, 2022 Cyber Security
    Editors Picks

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022

    Google Cloud Says Running Validator on Solana Blockchain

    November 7, 2022

    European stocks rise as investors boosted by China speculation

    November 7, 2022
    Trending Now

    Evergrande creditors sell ‘Versailles mansion’ plot in Hong Kong

    By techbizweb

    OpenSea Creates Tool for NFT Creators to Enforce Royalties On-Chain

    By techbizweb

    FTSE chairs warn of declining relations with institutional investors

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2023 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.