6 ASSESSMENT TIER #4 – BLACK BOX PENETRATION TESTING 6.1 OBJECTIVE 6.1.1 The objective of this activity is to determine if the DUT is resistant to the common IoT device attacks through black-box penetration testing. 6.1.2 Devices that passes Assessment Tier 4 should be capable of providing resistance against attacks conducted by a basic attacker on exposed interfaces. 6.1.3 The black box penetration test does not seek to assert that the DUT is resistant to all attacks. 6.1.4 However, the penetration test should provide basic assurance that the DUT is adequate to ward off the commonly known and straightforward attacks against such devices. 6.2 PRE-REQUISITES 6.2.1 The developer shall provide the following to the testing laboratory: 1. Guidance document (installation/operation guide) 2. Sufficient number of DUT to meet testing laboratory’s requirements 6.3 SCOPE 6.3.1 This activity comprises the following tasks: No. Tasks 1 Device setup and verification of guidance documents 2 ESTI Conformance Verification - verifying that the device indeed implemented the security measures that the developer has declared and specified in the checklist. 3 Scheme-mandated minimum test specifications 4 Search for potential vulnerabilities in the public domain 5 Vulnerability analysis and freeform penetration testing, devising test cases based on: a) The report from Assessment Tier #3; b) Known threat vectors; c) The laboratory’s expertise and experience. 6 Password cracking (if applicable) Table 3 – Assessment Tier #4 tasks 6.3.2 The testing laboratory shall conduct the abovementioned tasks concurrently where possible by leveraging on multiple units of the device and it is expected that it should take no longer than 15 working days, inclusive of drafting the test report. 6.3.3 Nonetheless, the testing laboratory is required to spend a minimum of 4 CLS Publication #2 | Page 15 of 49

Select target paragraph3