{"id":2756,"date":"2024-03-20T08:00:00","date_gmt":"2024-03-20T13:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification"},"modified":"2024-03-20T08:00:00","modified_gmt":"2024-03-20T13:00:00","slug":"connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/20\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification\/","title":{"rendered":"Connectivity Standards Alliance Meets Device Security Challenges With a Unified Standard and Certification"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltdfc947df346390a0\/656e035859f08b040ab06283\/Hollie_Hennessy_2023.png?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since the discovery of the Mirai Botnet in 2016, governments, enterprises, and consumers have seen the impact of insecure Internet of Things (IoT) devices.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It has become commonplace for numerous Internet-connected consumer devices, such as smart home security cameras and home routers, to be in use with unchanged default usernames and passwords, allowing attackers to take control and turn them into a network of &#8220;zombie&#8221; devices. Together, they create a botnet of compromised devices, used in large-scale network attacks, impacting the availability of many websites, Internet-driven services, and network availability.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While it may seem like common sense to avoid using default usernames and passwords, many IoT devices do not have adequate security protection, even at the most basic level. Following Mirai, a remarkable amount of work has been performed by standards bodies, industry groups, and governments to ensure new IoT devices placed on the market have a baseline of security by design.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Still, insecure IoT can also impact the individual consumer. It is not clear to consumers whether their devices are secure, have been protected, or will be protected. Certification, verification, standards, and regulation seek to make devices more secure and empower consumers to make informed purchasing decisions.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In an effort to change that, on March 19, the Connectivity Standards Alliance Product Security Working Group (PSWG) released its Internet of Things Device Security Specification 1.0, as well as an accompanying certification program and Product Security Verified Mark for compliant products.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The work aims to establish a unified IoT device security standard, alleviating the challenge for manufacturers to certify their devices and comply with international requirements, as well as inform consumers in regard to devices that meet this set of security requirements. The Cloud Security Alliance (CSA) has factored in the existing requirements from international standards, including the&nbsp;European Telecommunications Standards Institute&nbsp;(ETSI) and the National Institute of Standards and Technology (NIST), as well as current regulations, when creating the specification.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Secure by Design Baseline\">Secure by Design Baseline<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security by design calls for device manufacturers to consider and implement security from the early stages of device design and manufacturing, instead of as an afterthought. Three key existing standards have defined the security baseline requirements:&nbsp;<\/span><\/p>\n<div data-component=\"basic-list\" class=\"BasicList BasicList_nestedLevel_0 BasicList_variant_unordered BasicList_limited\">\n<ul data-testid=\"basic-list-unordered\" class=\"BasicList-UnorderedList\">\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"7.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"10\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ETSI EN 303 645, &#8220;Cybersecurity for Consumer Internet of Things: Baseline Requirements&#8221; \u2014 ETSI is Europe-based, but is widely used across geographies.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"7\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"9\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NIST IR 8425, &#8220;Profile of the IoT Core Baseline for Consumer IoT Products&#8221; \u2014 Published as part of the National Institute of Standards and Technology&#8217;s response to White House Executive Order 14028.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"7.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"10\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ISO\/IEC 27402:2023 \u2014 Published most recently by the international, non-government organization, entitled &#8220;Cybersecurity \u2014 IoT security and privacy \u2014 Device baseline requirements.&#8221;<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<\/ul>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Governments have adopted these standards to varying degrees in their guidance and legislation (planned or implemented). Largely, across regions, the three requirements of no default passwords, transparency on security updates, and clear vulnerability disclosure create the minimum baseline.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While this acceleration and focus on device security is positive, there remain a number of issues in solving the problem:&nbsp;<\/span><\/p>\n<div data-component=\"basic-list\" class=\"BasicList BasicList_nestedLevel_0 BasicList_variant_unordered BasicList_limited\">\n<ul data-testid=\"basic-list-unordered\" class=\"BasicList-UnorderedList\">\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"7\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"9\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While some government requirements overlap, there is no unified regulation \u2014 the picture is fragmented.&nbsp;<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"7.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"10\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Likewise, there are multiple standards, with no clear route for manufacturers to follow if selling into multiple markets.&nbsp;<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"7.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"10\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Most of the industry guidance is voluntary, with only the UK government and Singapore with mandatory requirements, some yet to be enforced.&nbsp;<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<\/ul>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition, consumers are looking to manufacturers for information that their devices are secure. Omdia&#8217;s survey asked, &#8220;How do you know how secure your devices are,&#8221; and the most commonly cited source (68%) was information from the manufacturer.<\/span><\/p>\n<div readability=\"12\"><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_center\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification-1.png\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification-1.png?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"Survey question: Do you know how secure your devices are?\" title=\"Survey question: Do you know how secure your devices are?\"><\/p>\n<p class=\"ContentImage-Link\">Source: Omdia, Consumer IoT Device Cybersecurity Standards, Policies, and Certification Schemes, sponsored by Connectivity Standards Alliance<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At this point in time, without mandatory requirements or widespread use of independently verified security testing and requirements, there is no clear way for consumers to access this information from manufacturers or verify its accuracy.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The CSA intends to change that with its new standard. Notably, it recognizes the work already done and standards previously established \u2014 the effort combined requirements from the above security baselines, as well as Singaporean and European guidance, into one single specification and certification program.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"IoT Device Security Specification 1.0 Requirements\">IoT Device Security Specification 1.0 Requirements<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Manufacturers of IoT devices (including light bulbs, switches, smart doorbells, thermostats, and more) who choose to adhere to the specification must meet a number of device security provisions. They must demonstrate compliance with these, supplying justification and evidence to an authorized testing lab that crucially has expertise and experience in security evaluation and certification.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some key requirements in the specification include:<\/span><\/p>\n<div data-component=\"basic-list\" class=\"BasicList BasicList_nestedLevel_0 BasicList_variant_unordered BasicList_limited\">\n<ul data-testid=\"basic-list-unordered\" class=\"BasicList-UnorderedList\">\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unique device identity&nbsp;<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">No default passwords&nbsp;<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"6\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"7\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Secure storage of sensitive data on the device<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"6\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"7\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Secure communications of security-relevant information&nbsp;<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"6\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"7\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Secure software updates throughout support period<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"6.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"8\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Secure development, and vulnerability management&nbsp;<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"6.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"8\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Public documentation regarding security, as well as the support period<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Transparency for Consumers&nbsp;\">Transparency for Consumers&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition to requirements that involve transparency \u2014 such as publicly documenting support periods \u2014 the specification comes alongside the Product Security Verified Mark. This product branding provides confirmation to buyers that a product has met the specification&#8217;s security requirements and helps them to make informed purchasing decisions. More information will be accessible to consumers, by one or a combination of printed URL, hyperlink, or QR code.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Omdia Analysis: Efforts From Across the Industry Will Be Key for Adoption\">Omdia Analysis: Efforts From Across the Industry Will Be Key for Adoption<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As a voluntary scheme, there is, of course, the question of how adoption will play out. Looking to government guidance, many voluntary requirements and frameworks published have not had the desired adoption \u2014 resulting in legislation and regulation passed and being planned in many regions.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That said, CSA&#8217;s scheme looks to tackle many of the issues surrounding fragmentation \u2014 making things easier and alleviating pressure on manufacturers as this regulation comes into force. In addition, existing schemes have been acknowledged \u2014 as an example, Singapore&#8217;s label and CSA&#8217;s mark will be mutually recognized, meaning certification activities for manufacturers can be significantly more cost effective.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Looking to device manufacturers and industry, manufacturers must see the value of implementing secure by design requirements and certification. Not only does certification help get ahead of and alleviate the pressure of upcoming mandatory requirements, but consumers are more likely to purchase secure devices.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Omdia&#8217;s survey of 400 consumers suggests that nearly all consumers were more likely to purchase a device with privacy and security labelling, with the majority (81%) preferring a reference URL or QR code to give them more information on privacy and security.&nbsp;<\/span><\/p>\n<div readability=\"12\"><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_center\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification-2.png\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification-2.png?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"Survey Q: Likelihood of purchasing device with privacy\/security label\" title=\"Survey Q: Likelihood of purchasing device with privacy\/security label\"><\/p>\n<p class=\"ContentImage-Link\">Source: Omdia, Consumer IoT Device Cybersecurity Standards, Policies, and Certification Schemes, sponsored by Connectivity Standards Alliance<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Connectivity Standards Alliance has nearly 200 member companies that have collaborated in the development and validation of the final specification. This includes large industry players such as Amazon, Arm, Comcast, Google, Infineon, NXP, Schneider Electric, Signify, and Silicon Labs. Industry will have a key part to play in driving product security forward, and the support from its member companies bodes well for adoption of the CSA&#8217;s program.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Crucially, botnets such as Mirai are not gone. There continue to be variants to this day, as well as devices sold that still do not have adequate protection. Efforts to improve IoT security remain a top priority for the cybersecurity industry, and efforts such as the CSA&#8217;s standard and certification serve as critical baselines in support of those efforts.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">Read Omdia&#8217;s &#8220;<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/omdia.tech.informa.com\/commissioned-research\/articles\/consumer-iot-device-cybersecurity-standards-policies-and-certification-schemes\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link ContentText-BodyTextChunk_italic\" rel=\"noopener\">Consumer IoT Device Cybersecurity Standards, Policies, and Certification Schemes<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">&#8221; report.<\/span><\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Since the discovery of the Mirai Botnet in 2016,<\/p>\n","protected":false},"author":12,"featured_media":2757,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2756","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?fit=980%2C600&ssl=1",980,600,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?fit=300%2C184&ssl=1",300,184,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?fit=640%2C392&ssl=1",640,392,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?fit=640%2C392&ssl=1",640,392,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?fit=980%2C600&ssl=1",980,600,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?fit=980%2C600&ssl=1",980,600,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?fit=980%2C600&ssl=1",980,600,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/connectivity-standards-alliance-meets-device-security-challenges-with-a-unified-standard-and-certification.png?fit=980%2C600&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2756","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2756"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2756\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2757"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2756"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2756"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2756"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}