Endpoint
10/29/2015
04:25 PM
Dark Reading
Dark Reading
Products and Releases
100%
0%

Online Trust Alliance Releases New Internet of Things Trust Framework to Address Global Concerns

Business and government leaders to attend upcoming summit to roll out IoT security, privacy and sustainability code of conduct

BELLEVUE, Wash. – Oct. 28, 2015 – The Online Trust Alliance (OTA), the non-profit with the mission to enhance online trust, today released the last-call update of the Internet of Things (IoT) Trust Framework. The Framework is a comprehensive global initiative that provides guidance for device manufacturers and developers to enhance the security, privacy and sustainability of connected home devices, wearable fitness and health technologies, and the data they collect.

The newest version includes U.S. and international feedback from more than 100 companies and organizations ranging from major retailers and device manufacturers to security and privacy subject matter experts including Underwriters Laboratories, the National Association of Realtors, the Center for Democracy and Technology, the International Telecommunications Union (ITU) and the European Union Agency for Network and Information Security. Underscoring the collaboration behind this effort, standards bodies and other working groups including I Am The Cavalry and BuildItSecure.ly provided insights from their work and testing in other key IoT segments. This multi-stakeholder effort is a major step forward in what may ultimately serve as a foundation for an international certification program.

OTA also announced today that it will hold an all-day Summit in Washington D.C. on Nov. 18 for the general security and privacy community. This Summit will review and discuss the Framework’s final criteria and implementation guidelines, and solicit input for the forthcoming self-regulatory code-of-conduct and planned certification programs. To attend OTA’s IoT Trust Framework Summit, register here.

“As someone with a long career in the technology industry and as an entrepreneur, I know firsthand how quickly technologies have developed to become critical to our daily lives,” said Congresswoman Suzan DelBene (WA-01), who co-chairs the Congressional IoT Caucus. “We’re in the dawn of a new innovation era, with everything from cars to wristbands connecting to the Internet. But we don’t want to wake up one morning to find ourselves asking, ‘Who hacked my coffeemaker?’ Lawmakers and industry leaders like the OTA need to work together to ensure we’re protecting consumers while also enabling these new technologies to thrive.”

Global Feedback 

After releasing an early draft for public comment in August, OTA received worldwide feedback from organizations, individuals, NGOs and government entities supporting the Framework’s goals and recognizing the global need for concrete IoT guidelines. Industry support includes AVG Technologies, DigiCert, Identity Guard, LifeLock, Mark Monitor, Microsoft, SiteLock, Symantec, TRUSTe, Verisign and others.

“The Trust Framework represents a significant level of international collaboration. Organizations, advocate groups and NGOs through the world have recognized the importance and criticality of developing a baseline Framework to help protect consumers, businesses and the associated data,” said Craig Spiezle, Executive Director and President of the Online Trust Alliance. “Unfortunately, in this rush to market we have witnessed the perils of the lack of robust security and responsible privacy practices. The Trust Framework has been designed to address these issues and represents a significant step forward to protect consumers and their data today and in the years ahead.” 

OTA IoT Framework Goals

The improvements to the newly revised Framework further advance OTA’s key objectives:

·       Deliver guidance to manufacturers and developers to help reduce attack surface and vulnerabilities, and adopt responsible privacy and data stewardship practices.

·       Drive the adoption of “privacy and security by design” as a model for a voluntary, yet enforceable code of conduct.

·       Provide positive affirmation and recognition to companies, products, and retailers who embrace the code of conduct and meet minimum standards.

·       Publish the criteria and mechanisms leading an enforceable code of conduct and certification program.

To review the Framework, provide feedback, or find information on joining the IoT Working Group, go to https://otalliance.org/IoT.

About OTA: 

The Online Trust Alliance (OTA) is a non-profit with the mission to enhance online trust and user empowerment while promoting innovation and the vitality of the Internet. Its goal is to help educate businesses, policy makers and stakeholders while developing and advancing best practices and tools to enhance the protection of users' security, privacy and identity. OTA supports collaborative public-private partnerships, benchmark reporting, and meaningful self-regulation and data stewardship. Its members and supporters include leaders spanning the public policy, technology, ecommerce, social networking, mobile, email and interactive marketing, financial, service provider, government agency and industry organization sectors.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Cybersecurity's 'Broken' Hiring Process
Kelly Jackson Higgins, Executive Editor at Dark Reading,  10/11/2017
Ransomware Grabs Headlines but BEC May Be a Bigger Threat
Marc Wilczek, Digital Strategist & CIO Advisor,  10/12/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Search Cybersecuruty and you will get unicorn.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.