5.7: Ensure software integrity 5.6-7: Software should run with least necessary privileges, taking account of both security and functionality. R R R R Supporting evidence shall list the software services that are running on the device, and the corresponding privileges assigned to each of them, along with a description of the rationale behind the assignment of the level of privileges to each of these services. Supporting evidence shall describe the hardware-level access control mechanism for memory employed. 5.6-8: The device should include a hardware-level access control mechanism for memory. 5.6-9: The manufacturer should follow secure development processes for software deployed on the device. 5.7-1: The consumer IoT device should verify its software using secure boot mechanisms. 5.7-2: If an unauthorized change is detected to the software, the device should alert the user and/or administrator to the issue and should not connect to wider networks than those necessary to R R R R R R R R Please refer to clause CK-LP-02. R R R R R R R R Supporting evidence shall describe the secure boot mechanism used (use of certified IoT platform, or the hardware root of trust utilised, the secure boot process), and the device's behaviour following the detection of unauthorised changes to its software. CLS Publication #2 | Page 37 of 49

Select target paragraph3