
With the rapid proliferation of IoT, the importance of security measures is increasing. Not only stakeholders of IoT devices, systems, and services, but also general users can no longer afford to be indifferent to security measures. Here, we explain the " IoT Security Guidelines " that form the basis of all IoT security measures.
What is IoT?
IoT (Internet of Things) is an abbreviation for "Internet of Things." Also called the " Internet of Things, " it refers to a mechanism that connects various things to the Internet and exchanges data. It enables remote control of devices via the Internet and storage and analysis of collected data.
A familiar example of IoT is a system that uses smartphones to operate air conditioners and lighting equipment from outside the home. IoT targets a very wide range of objects, from home appliances to various sensors, factory production machinery, transportation, and lifeline control equipment, providing solutions in various fields.
However, in recent years, the risk of IoT devices with inadequate security measures becoming targets of cyberattacks has become apparent. Not only are there cases of direct attacks on IoT devices, but large-scale attacks using them as stepping stones have also occurred.
Purpose of the " IoT Security Guidelines "
In response to this situation, the " IoT Security Guidelines ver1.0 " were jointly formulated • and published by the IoT Acceleration Consortium, the Ministry of Internal Affairs and Communications, and the Ministry of Economy, Trade and Industry in July 2016. The guidelines were developed based on the recognition that guidelines for IoT security were necessary, with cyberattacks targeting IoT devices in mind.
While these guidelines also mention general users, they primarily focus on content for stakeholders of IoT devices, systems, and services. This includes device manufacturers, system providers, service providers, as well as executives and users.
The guidelines aim to clarify what initiatives are necessary to ensure IoT security, primarily for these stakeholders. Furthermore, they are expected to lead to active development in the industry and the creation of an environment where IoT can be utilized with confidence.
They do not define legal responsibilities in the event of cyberattack damage. The purpose is to clarify the security measures that stakeholders should undertake, and they do not uniformly require the implementation of specific security measures, so consideration is required according to what each party should protect, the magnitude of risks, roles, • positions, etc.
Overview of the " IoT Security Guidelines "
In explaining security measures related to IoT, the guidelines divide them into five stages: " policy, analysis, design, construction • connection, operation • maintenance, " and establish five principles. Furthermore, for each principle, specific measures are summarized as key points.

[Policy] Principle 1: Establish a basic policy considering the nature of IoT
Since IoT risks may affect corporate survival and risk countermeasures require costs, it is recommended that executives take the lead in implementing measures. The guidelines also advocate the necessity of measures that anticipate internal fraud and human error.
[Analysis] Principle 2: Recognize IoT risks
The guidelines raise awareness by highlighting various potential risks of IoT devices and systems. Recognizing what risks exist enables the implementation of countermeasures.
First, identify the functions and information that should be protected, such as the original functions of IoT devices. Then, consider how far the impact will spread when problems occur due to connectivity. Even for closed network systems, it is necessary to recognize risks on the premise of connectivity. The possibility of unauthorized operation of devices due to loss or theft and information leakage from discarded devices should also be considered.
[Design] Principle 3: Consider design that protects what should be protected
As this is a principle about design, it involves technical content. It states that design must take into account that unexpected risks may arise when devices are combined.
Key points include: the need for design that reliably detects abnormalities in IoT devices and systems, isolates those parts from the network as necessary, and enables early recovery; design that ensures safety even when devices with low reliability are connected; and the need for " evaluation " of whether the design meets safety and security requirements.
[Construction • Connection] Principle 4: Consider measures on the network
This section covers security measures for the networks that connect IoT devices and systems, in addition to security measures for the devices and systems themselves.
First, it is necessary to consider network connection methods based on the functions and uses of IoT systems and services, and the functions and performance of IoT devices. Also, when starting use, it is important to perform initial settings with security in mind and provide alerts to users. Authentication functions to identify users and encryption are also necessary to prevent unauthorized actions through impersonation.
[Operation • Maintenance] Principle 5: Maintain a safe and secure state and disseminate • share information
Regarding operation • maintenance, these are points of caution for manufacturers and service companies that provide systems and devices. Since vulnerabilities may be discovered after shipment or release, it is necessary to perform updates appropriately at the required timing. Important security matters should not only be explained to users in advance but also disseminated and shared after shipment or release.
Specific examples of security measures
We introduce two specific examples of security measures implemented according to the above principles and key points, quoted from the " IoT Security Guidelines ver1.0. "
Assume risks as IoT devices • systems even for closed networks
Devices and systems with IoT connectivity functions should be designed and operated on the premise that they will be used as IoT devices • systems, even if they are intended for use on home or corporate LANs.
Specific examples are shown below.
- Do not use the same initial password at shipment. Also, make it difficult to guess.
- Make password changes mandatory on the user side, and automatically generate passwords or check the strength of passwords entered by users.
- Implement functional restrictions after a certain number of failures.
- Do not provide server functions unless essential. If provided, minimize the ports used and disable others.
- Do not grant administrator privileges to all internal functions; assign appropriate user privileges.
- Install antivirus software on devices and systems on isolated networks, or perform virus checks on computers and USB devices brought in.
Appropriate password setting • management
By appropriately setting and managing passwords for administrator and user privileges, prevent unauthorized access from malicious third parties through impersonation.
Specific examples are shown below.
- Do not leave passwords at their initial settings; change them appropriately (paying attention to the number of characters, character types, etc. after change) and manage them strictly to prevent disclosure to third parties.
- Do not share passwords with unauthorized users.
- Do not reuse passwords across other systems • services.
Summary
The guidelines also devote one chapter to explaining rules for general users. When considering the introduction of IoT, regardless of your position, it is advisable to first review the " IoT Security Guidelines. "
" IoT Security Guidelines ver1.0 "
" IoT Security Guidelines ver1.0 Overview "(IoT Acceleration Consortium • Ministry of Internal Affairs and Communications • Ministry of Economy, Trade and Industry)