system characteristics reflecting their inherent risks and steps taken to properly
address those risks.
b) Essential requirements for ensuring the users’ safety should be determined, as well
as the confidentiality, integrity and availability of information in IoT systems,
including functions of devices.
c) Requirements should be determined to ensure secure system operation and service
resilience in case of disruptions of functions, including mission assurance rules.
d) Safety assurance standards, including statutory and customary requirements, should
be determined for connected things and networks.
e) Confidentiality, integrity, availability, and safety should be ensured in the case of
mechanical failure or a cyber-attack, and swift service restoration in case of a system
trouble should be planned.
f) Responsibility demarcation boundaries and way of data management issues
including the discussions of information ownership regarding IoT systems should be
clarified.
Items a)-f) should also be applied to the requirements for other cases such as those related
to interconnection of IoT systems.
4. Policy Measures
4.1
Clarification of Requirements
The following requirements should be clarified on connected things and networks to IoT
systems;
a) Statutory and regulatory requirements;
b) Essential requirements not stated in a) and,
c) Additional requirements recognized as necessary by industry and others.
4.2
IoT system Modeling
The structure of IoT systems is multilayered. Proper modeling should be conducted
through analysis on layer by layer basis, such as device, network, platform including
certification, and service. Security requirements should be assessed with reference to
such model.
3