w3c / wot-security

a repo exclusively for security to better manage issues and security considerations for WoT
https://w3c.github.io/wot-security/
18 stars 22 forks source link

Add and Update Cloud References #206

Open mmccool opened 2 years ago

mmccool commented 2 years ago

The following references may need to be added to Security and Privacy Guidelines:

mlagally commented 2 years ago

https://www.ncsc.gov.uk/collection/cloud-security/implementing-the-cloud-security-principles

mmccool commented 2 years ago

The UK document is almost like a blog article than a citable document, unfortunately. At any rate we probably should cite the whole thing: https://www.ncsc.gov.uk/collection/cloud-security We should probably also look at what it cites in turn. Although it has some weird self-references, too.

mmccool commented 2 years ago

Also, I note the NIST reference is for "Information Systems" which is quite broad, but we consulted with them specifically on considerations for IoT system, which would be more focused. Also, these are "national" documents, international ones might be better (e.g. ISO). If do cover national standards, we should have a semi-complete list, including e.g. EU, Canada, etc. Impossible (nearly) to be complete for national standards, so these should be "e.g." citations, and "Compliant with national standards such as ...".

mmccool commented 2 years ago

There is this ISO standard, which is under development but will be published in June. It specifically refers to IoT Security and Privacy: ISO 44373. There is a more general ISO standard for Data Privacy also: ISOIEC-27001. However, ISOIEC-27001 is not one standard, but dozens. SOME may be applicable.

JKRhb commented 2 years ago

For Europe, the ETSI standard EN 303 645 for Consumer Internet of Things devices is probably also relevant.

mmccool commented 1 year ago

So probably best to focus this on IoT/Cloud integration, but the above references are about the broader context of cloud security. So we probably want to look for better, more focused references for IoT-Cloud integration. Second we probably want to think about specific threats and risks for cloud integration but that can be a separate issue... https://github.com/w3c/wot-security/issues/228

Also, I think we should deal with the "Terminology" reference above separately and focus in this issue on finding an including a good reference for IoT-Cloud integration security.

mmccool commented 1 year ago

Some possible references:

mahdanoura commented 1 year ago

I found the following IoT security standards, which do not focus on cloud-IoT integration: