5.5-6: Critical security parameters should be encrypted in transit, with such encryption appropriate to the properties of the technology, risk and usage. 5.5-7: The consumer IoT device shall protect the confidentiality of critical security parameters that are communicated via remotely accessible network interfaces. 5-5.8: The manufacturer shall follow secure management processes for critical security parameters that relate to the device. 5.6: Minimise exposed attack surfaces 5.6-1: All unused network and logical interfaces shall be disabled. R R R R R R R M R M M M R R R M Supporting evidence shall list all critical security parameters that are communicated across devices, associated services, or companion mobile applications, and describe the encryption used to protect them during transit. Supporting evidence that describes the critical security parameters that are communicated via remotely accessible network interfaces and the mechanism used to protect them. Supporting evidence (e.g. key lifecycle diagram) shall describe the lifecycle (creation, provisioning, renewal, revocation) of critical security parameters. Please state referenced standards/best practices for secure management processes, if used. Supporting evidence shall list all network and logical interfaces that are currently enabled in the device's default configuration and provide a description for their functionality and purpose. If a firewall is available on the device, the CLS Publication #2 | Page 35 of 49

Select target paragraph3