<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.element14.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>FTC Asks Companies to Get Serious About IoT Security</title><link>https://community.element14.com/technologies/internet-of-things/w/polls/20654/ftc-asks-companies-to-get-serious-about-iot-security</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>FTC Asks Companies to Get Serious About IoT Security</title><link>https://community.element14.com/technologies/internet-of-things/w/polls/20654/ftc-asks-companies-to-get-serious-about-iot-security</link><pubDate>Mon, 11 Oct 2021 15:01:42 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:ea9de086-4a92-4851-aa5c-fa83d7befba1</guid><dc:creator>GardenState</dc:creator><comments>https://community.element14.com/technologies/internet-of-things/w/polls/20654/ftc-asks-companies-to-get-serious-about-iot-security#comments</comments><description>Current Revision posted to Polls by GardenState on 10/11/2021 3:01:42 PM&lt;br /&gt;
&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;&lt;a href="http://www.michaelwaynejones.com/wp-content/uploads/2014/11/hacking.jpg"&gt;&lt;img alt="hacking.jpg" class="image-3 jive-image" src="http://www.michaelwaynejones.com/wp-content/uploads/2014/11/hacking.jpg" style="height:auto;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;When you add them all up—health and fitness monitors, connected cars, home automation systems, smart meters, etc.—the Internet of Things (IoT) total reaches an estimated 10 billion devices worldwide.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;All of these devices collect, store and transmit information about who we are and what we do and as such &lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;raise privacy and security concerns. &lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;A connected home lighting system, smart refrigerator or any other &lt;/span&gt;&lt;span style="font-size:12.0pt;color:black;background:white;"&gt;IoT device is a potential beachhead for attackers and the &lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;I&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;nformation obtained could have a negative effect on our employability, credit rating or insurance premiums. The trend toward “big data”– collecting terabytes of information that can be mined for marketing purposes—also means that IoT information has become a valuable commodity. I&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;f security issues are not addressed, leaks of the very personal information tracked by IoT products (e.g., your location, mood, smoking habits, exercise regimen and&amp;nbsp; the medications you take, for instance) could also create a consumer backlash that would prevent the benefits of the IoT from being fully realized. &lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;Understanding the importance of providing consumers with the protections they want &lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;the staff of the Federal Trade Commission (FTC) earlier this year recommended a series of steps that businesses can take to enhance and protect consumers’ IoT privacy and security.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;In January the FTC issued a staff report on IoT privacy and security.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;&lt;a href="https://www.ftc.gov/system/files/documents/reports/federal-trade-commission-staff-report-november-2013-workshop-entitled-internet-things-privacy/150127iotrpt.pdf" rel="nofollow ugc noopener" target="_blank"&gt;&lt;img loading="lazy" alt="logo_0.jpg" class="jive-image image-4" height="150" src="https://www.ftc.gov/sites/default/files/images/public_events/logo_0.jpg" style="height:150.33px;width:285px;" width="285" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;The report is partly based on input from leading technologists and academics, industry representatives, consumer advocates and others who participated in the &lt;/span&gt;&lt;a class="jive-link-external-small" href="https://www.ftc.gov/news-events/events-calendar/2013/11/internet-things-privacy-security-connected-world" rel="nofollow ugc noopener" target="_blank"&gt;&lt;span style="font-size:12pt;color:black;"&gt;FTC’s Internet of Things workshop&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:12.0pt;"&gt; held in Washington D.C. on Nov. 19, 2013, as well as those who submitted public comments to the Commission. The scope of the report is limited to IoT devices that are sold to or used by consumers. No discussion of&amp;nbsp; the Industrial Internet of Things (IIoT, sometimes known as Industry 4.0) is included.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;The report includes the following “recommendations&lt;em&gt;”&lt;/em&gt; (the quotation marks are mine, for reasons that will become apparent shortly) for companies developing Internet of Things devices:&lt;/span&gt;&lt;/p&gt;&lt;ul style="list-style-type:disc;"&gt;&lt;li&gt;&lt;span style="font-size:12.0pt;"&gt;build security into devices at the outset, rather than as an afterthought in the design process;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:12.0pt;"&gt;train employees about the importance of security, and ensure that security is managed at an appropriate level in the organization;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:12.0pt;"&gt;ensure that when outside service providers are hired, that those providers are capable of maintaining reasonable security, and provide reasonable oversight of the providers;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:12.0pt;"&gt;when a security risk is identified, consider a “defense-in-depth” strategy whereby multiple layers of security may be used to defend against a particular risk;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:12.0pt;"&gt;consider measures to keep unauthorized users from accessing a consumer’s device, data, or personal information stored on the network;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:12.0pt;"&gt;monitor connected devices throughout their expected life cycle, and where feasible, provide security patches to cover known risks.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="margin:0;padding:0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;background:#FDFDFD;"&gt;&lt;span style="font-size:12.0pt;color:black;"&gt;Now back to the reason for the quotation marks in the word “recommendations” above. The FTC report includes a great many suggestions as to what business should do to insure IoT data privacy. But these are only suggestions, things to consider and courses of action that one might “take under advisement.” The FTC wants IoT entities to use its guidelines and&lt;/span&gt;&lt;span style="font-size:12.0pt;color:#333333;"&gt; “self-regulate.” &lt;/span&gt;&lt;span style="font-size:12.0pt;color:black;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;margin-bottom:.0001pt;background:#FDFDFD;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;background:#FDFDFD;"&gt;&lt;span style="font-size:12.0pt;color:black;"&gt;Well, the&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt; only thing missing in the FTC report is the phrase “pretty please”. &lt;span style="color:black;"&gt;There is not one “a company must” in the entire document and deliberately so, because, again, these are just in the FTC’s words, “best practices”, not formal regulatory measures. The commission believes that at this point &lt;/span&gt;specific legislation would be premature.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;margin-bottom:.0001pt;background:#FDFDFD;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;color:black;"&gt;I disagree, but before I explain why you should know that in general I don’t like to see legislative bodies trying to mandate how individuals or corporate entities behave except when clearly needed for the public good.&amp;nbsp; And overall I don’t like it when government decides to micromanage society.&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt; I also recognize that an overly regulatory approach to IoT data protection could potentially stifle our burgeoning digital economy. &lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;What’s more, &lt;span style="color:#333333;"&gt;I am by nature a capitalist and I believe that a business deserves a return on its investment. Even companies I don’t immediately trust, such as those collecting, analyzing and selling information on people. Overall I don’t categorize firms as&amp;nbsp; either&amp;nbsp; good or bad, but I do realize that unchecked they will do whatever the law allows to increase profitability and make their stock more attractive to shareholders. This is how the system works and we must adjust our rules, guidelines and regulations to account for it, creating, when needed, tools to protect the public welfare. And the best tools we have to do so are called laws.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="color:#333333;font-size:12.0pt;"&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="color:#333333;font-size:12.0pt;"&gt;&lt;em&gt;&lt;a href="http://www.nextavenue.org/sites/default/files/7_steps_to_protect_your_online_security_148650499.jpg"&gt;&lt;img loading="lazy" alt="7_steps_to_protect_your_online_security_148650499.jpg" class="image-5 jive-image" src="http://www.nextavenue.org/sites/default/files/7_steps_to_protect_your_online_security_148650499.jpg" style="height:auto;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="color:#333333;font-size:12.0pt;"&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="color:#333333;font-size:12.0pt;"&gt;&lt;em&gt;(Source: The annual IT Risk/Reward Barometer, a study conducted by ISACA, a global association of more than 115,000 IT security, assurance, risk and governance professionals.) &lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="color:#333333;font-size:12.0pt;"&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;There is precedence here. We have on the books a blueprint to help guide us through the process of protecting sensitive data. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) includes Privacy, Security and Breach Notification Rules to protect individually identifiable health information. It &lt;/span&gt;&lt;span style="font-size:12.0pt;color:black;background:white;"&gt;sets national standards for the security of electronic health data&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt; and it specifies the rights granted to individuals as well as breach notification requirements, enforcement activities, etc. &lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="font-size:12.0pt;color:black;background:white;"&gt;HIPAA includes a Privacy Rule&amp;nbsp; whose &lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt; goal is to assure that individuals’ health information is properly protected while allowing the flow of health information needed to provide and promote high quality health care and to protect the public&amp;#39;s health and well-being.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;color:black;background:white;"&gt;By all accounts—over the nearly twenty years since the rule’s inception—it has worked very well and could be used as a template for similar IoT legislation.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;background:#FDFDFD;"&gt;&lt;span style="font-size:12.0pt;color:black;"&gt;Even the FTC admits that eventually the Internet of Things will require privacy and security rules. So to give them a head start, here are a few things that I think must be included, in no particular order:&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;margin-bottom:.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;&lt;em&gt;Minimize the amount of information collected.&lt;/em&gt;&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt; The FTC staff recommends that companies limit the collection of consumer data, and retain that information only for a set period of time, and not indefinitely. This is a good idea. Under the recommendations, companies can choose to collect no data, data limited to certain categories to provide a particular service offered, identify less sensitive data, or choose to de-identify-- that is, strip out information from the data collected that could &lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;provide a reasonable basis for identifying an individual, the individual’s relatives, household members, friends and employers&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;.&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt; By minimizing the amount of data collected &lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;a company also becomes a less inviting target for data thieves or hackers.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;margin-bottom:.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:12.0pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;&lt;em&gt;Require that authorization must be obtained&lt;/em&gt;&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt; to use or disclose protected IoT information. This should take the form of either written permission from the individual &lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;who is the subject of the information &lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;to be used or via an easy to understand “opt out” feature. If the latter route is taken it should be made to be more effective than the telephone “Do Not Call Registry” which in my experience worked well initially but then was largely ignored by telemarketers.&lt;/span&gt;&lt;strong&gt; &lt;/strong&gt;&lt;span style="font-size:12.0pt;"&gt;FTC staff also sensibly recommends that companies notify consumers and give them choices about how their information will be used, particularly when the data collection is beyond consumers’ expectations.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;em&gt;&lt;span style="font-size:12.0pt;color:black;"&gt;Privacy Practices Notice&lt;/span&gt;&lt;span style="font-size:12.0pt;color:black;"&gt;. &lt;/span&gt;&lt;/em&gt;&lt;span style="font-size:12.0pt;color:black;"&gt;As with current procedure for banks, credit card agencies and major retailers, entities collecting IoT data should provide consumers with notice of its privacy practices. The notice should describe the ways in which they use IoT data and how they protect privacy in doing so. It should describe the individuals’ rights, including the right to complain to the entity or a government agency if they believe their privacy rights have been violated.&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt; The notice also should include a point of contact for further information and for making complaints.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;margin-bottom:.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="color:black;font-size:12.0pt;"&gt;&lt;em&gt;Public interest and benefit exceptions.&lt;/em&gt;&lt;/span&gt;&lt;strong&gt; &lt;/strong&gt;&lt;span style="font-size:12.0pt;color:black;"&gt;These next few elements are&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt; tricky, but I believe there are circumstances in which IoT data holders may (one can argue should) disclose protected Information to local, state or federal authorities &lt;/span&gt;&lt;span style="font-size:12.0pt;color:black;"&gt;without an individual’s authorization or permission; for example &lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;if it is necessary to prevent or lessen a serious and imminent threat to the public&lt;/span&gt;&lt;span style="font-size:12.0pt;color:black;"&gt; (as long as appropriate checks and balances are put in place to prevent abuse of this exception).&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;margin-bottom:.0001pt;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;&lt;em&gt;Law enforcement exceptions. &lt;/em&gt;&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;Provision should be made so that&lt;em&gt; &lt;/em&gt;p&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;rotected IoT information may be given to law enforcement officials under certain circumstances, and subject to strictly regulated conditions. Examples include the process of trying to identify or locate a suspect, fugitive, material witness, or missing person. Exceptions should also be considered in response to a law enforcement official’s request for information about a victim of a crime, or&lt;strong&gt; &lt;/strong&gt;&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt;for preventing recurring criminal acts (such as when an IoT home monitoring device captures incidences of child abuse or domestic violence). Also, I can envision the need to allow IoT data to be used when such disclosure is needed to identify or apprehend an escapee or violent criminal.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;&lt;em&gt;Other law-based exceptions.&lt;/em&gt;&lt;/span&gt;&lt;span style="font-size:12.0pt;"&gt; Similarly, privacy protection exemptions should be allowed when the request for the information is through an order from a court or in response to a subpoena, warrant or other lawful process. &lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;"&gt;&lt;span style="color:black;font-size:12.0pt;"&gt;&lt;em&gt;Penalties&lt;strong&gt;.&lt;/strong&gt;&lt;/em&gt;&lt;/span&gt;&lt;strong&gt; &lt;/strong&gt;&lt;span style="font-size:12.0pt;"&gt;Any rules that emerge regarding IoT data privacy should impose financial penalties or even allow for criminal prosecution if the wrongful conduct is willful.&amp;nbsp; One example would be if information continues to be collected surreptitiously after the consumer has specifically prohibited it. So as not to be unjustly harsh in cases not involving willful release of data wrongdoers should be allowed to simply correct the violation within a specified (and timely) period, provided it can be demonstrated that no harm had been done.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;margin-bottom:.0001pt;"&gt;&lt;span style="font-size:12.0pt;"&gt;Add it all up and the rule-makers have plenty to concentrate on and more than a little bit to worry about. But rules to protect privacy and secure important information have worked in the past and they can do so again.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0;padding:0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin:0;"&gt;&lt;span style="color:#0000ff;font-size:12.0pt;"&gt;&lt;strong&gt;What do you think? Cast your vote and click the &lt;em&gt;Submit&lt;/em&gt; button below.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;p align="center"&gt;[Please visit the site to access the poll]&lt;/p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item></channel></rss>