IoTSec:Privacy Label explanation
From its-wiki.no
Revision as of 14:27, 20 November 2017 by Josef.Noll (Talk | contribs)
Security in IoT for Smart Grids | |||||||
---|---|---|---|---|---|---|---|
|
Four areas
- which data are collected
- sharing to my phone, my cloud, public cloud,...
- data communication integrity and storage
- further distribution of data, ownership of data, further processing
Open issues
- access control (authentication) - transparency of authentication level
- maintenance and update
A++
- no data are shared
A+
A - Very high
- supplier should bear the risk of incidents, e.g. they rathe than I get penalised when things go wrong - equivalent to finansavtaleloven
- if device is stolen - nobody else
B
- customizable access control, eg.. add stronger authentication or consent requirements
- must be able to trade off the various security requirements, e.g. confidentiality agains availability - i.e. I want flexibility
- compliance with other standards - and this be listed (information requirement) - clipper compatible
- anonymity of my interaction with the supplier
- customer can control with how the information is transferred and used by a third party
C
- must be possible to withdraw consent - and that this results in all relevant information being deleted - and proof of deletion
D
- Data is not sold without consent/knowledge
- transparency - I get told about the criteria that the supplier has used in their information classification
- Information is only used for its legitimate purpose
E
- in compliance with GDPR
- if data is stolen, I will get told
- notification if DSO is hacked
F - Failure
- nothing , no expectations