Risk-based Automated Assessment and Testing for the Cybersecurity Certification and Labelling of IoT Devices
Nowadays, security aspects represent one of the most significant barriers for the adoption of large-scale Internet of Things (IoT) deployments. In this sense, being able to certify and communicate the security level of a certain device is crucial for their acceptance. Towards this end, we propose a security certification methodology designed for IoT to empower different stakeholders with the
ability to assess security solutions for large-scale IoT deployments in a automated way. It also supports transparency on the IoT security level to the consumers because the methodology provides a label as one of the main results of the certification process. The certification approach represents an instantiation of the Risk-based Security Assessment and Testing methodologies presented by ETSI based on the ISO 31000 and ISO 29119, and it is built on top of different technologies and approaches for security testing and risk assessment adapted to the IoT landscape. As a proof of concept, the proposed methodology is applied to one of the scenarios proposed in the scope of the
Horizon 2020 ARMOUR project for assessing the fulfilment of several security properties of IoT devices.
MATHEU GARCIA Sara Nieves;
HERNANDEZ RAMOS Jose Luis;
SKARMETA Antonio;
BALDINI Gianmarco;
2018-11-19
ELSEVIER SCIENCE BV
JRC111554
0920-5489 (online),
https://www.sciencedirect.com/science/article/pii/S0920548918301375,
https://publications.jrc.ec.europa.eu/repository/handle/JRC111554,
10.1016/j.csi.2018.08.003 (online),
Additional supporting files
| File name | Description | File type | |