This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Navigating the vast ocean of cyber security standards and regulations

Download resources

About this session

Joseph Dawson of Intertek (formerly EWA Canada), who tests everything from light bulbs to pacemakers for cybersecurity, draws a parallel between today's unregulated IoT market and the unsafe early days of consumer electrical appliances, arguing that just as electrical safety standards eventually made outlets and irons trustworthy, cybersecurity standards and regulations are now emerging to do the same for connected devices. He distinguishes voluntary standards from legally binding regulations and surveys about a dozen current frameworks: California's SB 327 and its Oregon copy, the UK's PSTI, the EU's upcoming Cyber Resilience Act, ETSI EN 303645, Cyber Assured (which tests the device, its cloud backend and its mobile app together using OWASP standards), the Radio Equipment Directive, the Digital Light Consortium requirements, IEC 62443-4-1 for secure development lifecycles, and UL 2900. He explains that many standards overlap, so meeting the strictest one usually satisfies several others, and that manufacturers can self-attest or seek third-party certification, with buyers advised to ask which path a vendor took. A closing Q&A covers centralizing these standards, the gap between certification requirements and what is actually sold at retail, and whether GDPR gives European consumers stronger protection.

The past decade has witnessed a dramatic surge in the number of consumer, industrial, and medical products that are directly or indirectly linked to the internet. This connectivity brings with it novel risks and challenges. Both consumers and businesses are grappling with the uncertainty of which devices are trustworthy. In the face of this emerging issue, the question arises - do we need a fresh approach to security? Or have we encountered this issue in the past, and can we draw on historical lessons to address this problem?

Key takeaways

  • When buying a connected device, ask the manufacturer which standards it followed and whether it self-attested or obtained third-party certification, rather than assuming a compliance sticker means the same thing everywhere.
  • Evaluate IoT products as a system, not in isolation: security of the device itself means little if its cloud backend or companion mobile app is untested.
  • Prioritize compliance with the strictest applicable standard (such as the EU Cyber Resilience Act or ETSI EN 303645); it typically covers most requirements of the others.
  • Require a patchable, digitally-signed update mechanism as a baseline; devices that cannot be securely updated cannot meet most current IoT standards.
  • Track your software bill of materials and monitor open-source components in shipped products; manufacturers remain responsible for vulnerabilities in dependencies they did not write.

Speakers

Joseph Dawson
Joseph Dawson
Principal Software Security Analyst · Intertek
Joe Dawson, is a Principal Software Security Analyst, for EWA-Canada (an Intertek company) with a career spanning over thirty years in Software Development, Data Communications, and Information Security. He is currently engaged in aiding device… Read moreRead less

Joe Dawson, is a Principal Software Security Analyst, for EWA-Canada (an Intertek company) with a career spanning over thirty years in Software Development, Data Communications, and Information Security. He is currently engaged in aiding device manufacturers in fortifying the cyber security of their internet-connected devices. Joe is an active participant in the Standards Technical Panels for all UL 2900 standards, contributes to one of the IEC 62443 standards committees, and is instrumental in the creation of several other security standards.

Resources

Tags

More from GoSec 2024

Also from Joseph Dawson

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.