To help gather information on customer goals, manufacturers should answer the following questions for
each of the expected device use cases:
- How will the device interact with the physical world?Anticipate the potential impact of an IoT device making changes to physical systems. In some cases, performance requirements might stand at odds with cybersecurity goals.
- How will the IoT device need to be accessed, managed, and monitored by authorized people, processes, and other devices? Examining the methods used by customers to manage the device is of crucial importance. Generally, an organization will appreciate a device with multiple configurations and features more so than a home or consumer client.Consider “an IoT food vending machine in a public place, which is internet-connected so suppliers can track inventory and machine status. Vending machine users would not be required to authenticate themselves in order to insert money and purchase a snack. However, the vending machine would also be highly susceptible to physical attack."
- How will the IoT device's use of device cybersecurity capabilities be affected in terms of the device's availability, efficiency, and effectiveness? Think of a device on a low bandwidth network - will it possess the ability to download large firmware updates from the supplier? Probably not.
- What will the nature of the IoT's device's data be? Understanding what type of data, the IoT device will encounter will directly impact the type of cybersecurity controls a customer should rightly possess to secure the IoT device. For example, data encryption functionality should be offered for a device that stores PII but may not be necessary for a device that does not store any data.
- What are the known cybersecurity requirements for the IoT device? Identify known laws and regulations (often country-specific) and be mindful of those during capability identification.
-
What complexities will be introduced by the IoT device interacting with other devices, systems, and environments?
An example would be the complexities introduced by a smart oven or thermostat. What kinds of risks would be introduced by the ability to remotely heat your oven to 400º, or to set it for 450º indefinitely?