Kaspersky has been actively involved in the development of trust principles for IoT devices as laid out by the ISO/IEC TS 30149:2024 specification.
The ISO/IEC 30141 standard defines reference architecture for IoT solutions, reducing user dependence on the manufacturer and enabling different products to interoperate.
Standards can describe not only the features of a finished product but also how to manufacture it, addressing both hardware and software aspects.
Standardization based on this specification addresses how to eliminate vendor lock-in and cut the number of IoT devices with security issues.
ISO/IEC TS 30149:2024 details how trustworthiness, trust, and risk correlate and outlines principles for IoT trustworthiness.
Trustworthiness is ensured through specific approaches to system design and construction, covering safety, security, privacy, resilience, and reliability.
In a few years, significant improvements in the security of both industrial and consumer IoT devices are expected, including secure default settings, publicly-verified communication protocols, and secure-by-design approaches.
The ultimate goal is for consumers to know for sure that the IoT devices they purchase are secure, reliable, and resilient to threats throughout the entire lifecycle of those IoT devices.