← All writing

Fundamental Cybersecurity Controls

Introduction

For designers of Internet of Things (IoT) devices, cybersecurity is a necessary provision. This series of posts will review what I regard as the basic fundamental items which should be included in the design of an IoT device.

Cybersecurity is not (usually) the focus of the design, which is of course to provide some valuable function to the customers. Customers of IoT devices also do not wish to think about cybersecurity – they will trust the company to have done a sufficiently good job. This may or may not be a warranted trust!

There is increasing regulation and legislation which covers this topic, which we will be able to bring to the discussion.

We will consider a relatively straightforward “mock” IoT device, which communicates with some back-end server. The data in this communication includes:

  • Confidential data about the customer
  • Data to and from the IoT device which enables its function. This data must not be able to be manipulated by an adversary.
  • Confidential data about the device and the company that makes it
  • Data, important to the company, which transfers between the server and the device. Again we wish to defend this from adversarial manipulation. This includes software updates to the device.

The list of controls we will put in place covers:

  • Locking of debug ports
  • Authenticated access to development interfaces
  • Authentication and Encryption of data between the device and the server
  • Authentication of software updates
  • Appropriate use of standard cryptographic protocols and primitives