vz-risk / veris

Vocabulary for Event Recording and Incident Sharing (VERIS)
http://verisframework.org
Other
576 stars 161 forks source link

How should devices falling under 'IOT' be recorded? #122

Closed gdbassett closed 7 years ago

gdbassett commented 8 years ago

How should devices falling under 'IOT' be recorded?

Options include coding them as "SCADA" (becoming 'ICS').

Maybe a separate code? (It would be a group code that might have to be subsetted later)

gdbassett commented 8 years ago

We agreed to create new enumerations for IoT. We also discussed creating a new superset. There was some desire for 'IoT', however it is a use, not a device type. The other option is something like 'embedded'.

gdbassett commented 8 years ago

My opinion would be to add a superset of embedded with varieties of telemetry and telematics asset.assets.e - telemetry - Embedded - A dedicated device which collects data about the physical world asset.assets.e - telematics - Embedded - A dedicated device which affects the real world

Spitler commented 8 years ago

After trying to improve on the above, I like what Gabe presented more and more. We don't want to enumerate specific objects/things or groups (wearables, home automation, etc.). The definitions of the above almost read like they are devices interacting with 'things' (collecting data from sensors or controlling them) as opposed to the objects or things themselves. I think we want to use DCS for the servers in the IoT environment, so we may want to add a bit of text that clears that up

gdbassett commented 8 years ago

Added in [v1_3_1 3e138cc].