5 th ITU Green Standards Week Nassau, The Bahamas December 2015 Taming The IoT Security & Privacy Beast Craig Spiezle, Executive Director, Online Trust Alliance #otalliance
Mobile app Fitness Wearables Service/Data Providers IoT Data Processing IoT Provider Website Connected Home Entertainment Devices Challenges - IoT Ecosystem Highly personal, dynamic, persistent collection and transfer of data. A combination of devices, apps, platforms and cloud services. Multiple data flows, touch points and disclosures. Lack of defined standards. Non-traditional vendors 3 sides of the same coin – Privacy, Security & Sustainability
IoT Working Group Goals 1.Provide guidance to help reduce vulnerabilities and adopt responsible privacy and data practices. 2.Drive the adoption of best practices; embracing as a voluntary, yet enforceable, code of conduct. 3.Provide recognition to companies, products and retailers who embrace the code of conduct. 4.Think globally; where possible, apply international standards and practices. 5.Encourage collaboration, sharing of best practices and threat intelligence. 6.Evaluate gating issues and considerations which may lead to the development – Voluntary, yet enforceable code of conduct – Seal or certification program.
Global Collaboration
Ambient Data – Smart City Growing number of devices & sensors Use & sharing with unknown/undisclosed third parties May be “benign” today, but harmful tomorrow
Trust Framework – Pre Release
Partnership with the National Association of Realtors Security, Privacy & Personal Safety Steps to “re-provision” your home Prior to occupancy, rental & at “closing” Prescriptive advice Released Oct 21st Education - The Connected Home
Connected devices within the connected city & home. Targeting buyers / recipients of connected devices during 2015 Holiday Prior to purchase & set up. Help proactively raise awareness of key Security & Privacy considerations. Released December 8th Education – Connected Devices
Release January / February 2015 Develop an implementation guide Drive a proof of concept “pilot” Expand collaboration with other organizations. Secure funding & grants for pilot projects Develop incentives, recognize early adopters. Develop criteria as the basis for a certification program. What’s Next?
More Information IoT Initiative Smart Home Craig Spiezle