5.8: Ensure that personal data is protected 5.9: Make systems resilient to perform the alerting function. 5.8-1: The confidentiality of personal data transiting between a device and a service, especially associated services, should be protected, with best practice cryptography. 5.8-2: The confidentiality of sensitive personal data communicated between the device and associated services shall be protected, with cryptography appropriate to the properties of the technology and usage. 5.8-3: All external sensing capabilities of the device shall be documented in an accessible way that is clear and transparent for the user. 5.9-1: Resilience should be built in to consumer IoT devices R R R M R M R M Supporting following: evidence shall list the 1. All sensitive personal data communicated between the device and associated services, and describe how they are adequately secured to address the risk and usage scenario, and the best practice cryptography that were referenced (if used). 2. All external sensing capabilities available on the device and state where this information is provided to the user. R M M M R R R R Supporting evidence shall describe how these provisions are fulfilled. CLS Publication #2 | Page 38 of 49

Select target paragraph3