Endpoint

10/29/2015
04:25 PM
Dark Reading
Dark Reading
Products and Releases
100%
0%

Online Trust Alliance Releases New Internet of Things Trust Framework to Address Global Concerns

Business and government leaders to attend upcoming summit to roll out IoT security, privacy and sustainability code of conduct

BELLEVUE, Wash. – Oct. 28, 2015 – The Online Trust Alliance (OTA), the non-profit with the mission to enhance online trust, today released the last-call update of the Internet of Things (IoT) Trust Framework. The Framework is a comprehensive global initiative that provides guidance for device manufacturers and developers to enhance the security, privacy and sustainability of connected home devices, wearable fitness and health technologies, and the data they collect.

The newest version includes U.S. and international feedback from more than 100 companies and organizations ranging from major retailers and device manufacturers to security and privacy subject matter experts including Underwriters Laboratories, the National Association of Realtors, the Center for Democracy and Technology, the International Telecommunications Union (ITU) and the European Union Agency for Network and Information Security. Underscoring the collaboration behind this effort, standards bodies and other working groups including I Am The Cavalry and BuildItSecure.ly provided insights from their work and testing in other key IoT segments. This multi-stakeholder effort is a major step forward in what may ultimately serve as a foundation for an international certification program.

OTA also announced today that it will hold an all-day Summit in Washington D.C. on Nov. 18 for the general security and privacy community. This Summit will review and discuss the Framework’s final criteria and implementation guidelines, and solicit input for the forthcoming self-regulatory code-of-conduct and planned certification programs. To attend OTA’s IoT Trust Framework Summit, register here.

“As someone with a long career in the technology industry and as an entrepreneur, I know firsthand how quickly technologies have developed to become critical to our daily lives,” said Congresswoman Suzan DelBene (WA-01), who co-chairs the Congressional IoT Caucus. “We’re in the dawn of a new innovation era, with everything from cars to wristbands connecting to the Internet. But we don’t want to wake up one morning to find ourselves asking, ‘Who hacked my coffeemaker?’ Lawmakers and industry leaders like the OTA need to work together to ensure we’re protecting consumers while also enabling these new technologies to thrive.”

Global Feedback 

After releasing an early draft for public comment in August, OTA received worldwide feedback from organizations, individuals, NGOs and government entities supporting the Framework’s goals and recognizing the global need for concrete IoT guidelines. Industry support includes AVG Technologies, DigiCert, Identity Guard, LifeLock, Mark Monitor, Microsoft, SiteLock, Symantec, TRUSTe, Verisign and others.

“The Trust Framework represents a significant level of international collaboration. Organizations, advocate groups and NGOs through the world have recognized the importance and criticality of developing a baseline Framework to help protect consumers, businesses and the associated data,” said Craig Spiezle, Executive Director and President of the Online Trust Alliance. “Unfortunately, in this rush to market we have witnessed the perils of the lack of robust security and responsible privacy practices. The Trust Framework has been designed to address these issues and represents a significant step forward to protect consumers and their data today and in the years ahead.” 

OTA IoT Framework Goals

The improvements to the newly revised Framework further advance OTA’s key objectives:

·       Deliver guidance to manufacturers and developers to help reduce attack surface and vulnerabilities, and adopt responsible privacy and data stewardship practices.

·       Drive the adoption of “privacy and security by design” as a model for a voluntary, yet enforceable code of conduct.

·       Provide positive affirmation and recognition to companies, products, and retailers who embrace the code of conduct and meet minimum standards.

·       Publish the criteria and mechanisms leading an enforceable code of conduct and certification program.

To review the Framework, provide feedback, or find information on joining the IoT Working Group, go to https://otalliance.org/IoT.

About OTA: 

The Online Trust Alliance (OTA) is a non-profit with the mission to enhance online trust and user empowerment while promoting innovation and the vitality of the Internet. Its goal is to help educate businesses, policy makers and stakeholders while developing and advancing best practices and tools to enhance the protection of users' security, privacy and identity. OTA supports collaborative public-private partnerships, benchmark reporting, and meaningful self-regulation and data stewardship. Its members and supporters include leaders spanning the public policy, technology, ecommerce, social networking, mobile, email and interactive marketing, financial, service provider, government agency and industry organization sectors.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
The Fundamental Flaw in Security Awareness Programs
Ira Winkler, CISSP, President, Secure Mentem,  7/19/2018
Number of Retailers Impacted by Breaches Doubles
Ericka Chickowski, Contributing Writer, Dark Reading,  7/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19990
PUBLISHED: 2018-07-23
October CMS version prior to build 437 contains a Cross Site Scripting (XSS) vulnerability in the Media module and create folder functionality that can result in an Authenticated user with media module permission creating arbitrary folder name with XSS content. This attack appear to be exploitable v...
CVE-2018-19990
PUBLISHED: 2018-07-23
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend pat...
CVE-2018-19990
PUBLISHED: 2018-07-23
FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fix...
CVE-2018-19990
PUBLISHED: 2018-07-23
FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow vulnerability in asf_o format demuxer that can result in heap-buffer-overflow that may result in remote code execution. This attack appears to be exploitable via specially crafted ASF file that has to be provide...
CVE-2018-19990
PUBLISHED: 2018-07-23
FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in a Vulnerability that allows attackers to consume excessive amount of resources like CPU and RAM. This attack appear to be exploitable via specially c...