In other words, this framework is established on the assumption of the assurance of four
requirements, namely, safety, confidentiality, integrity, and availability.
3. Basic Principles
Physical components in IoT systems are subject to existing legal requirements and practices
for ensuring security and/or performance. Communication networks used by IoT system vary
in their operational or management organizations, communication mode, network
configurations, connections and quality. Therefore, it is necessary to choose an optimal
network system that meets requirements for the services provided by such system. However,
at this moment, because both the device-side personnel and the network-side personnel do
not necessarily know much about the industrial environment or characteristics of one
another, connecting objects may not provide sufficient safety and/or quality performance
and may cause violation of law as well.
Based these concerns, issues on the network-side could potentially impact security
requirements for the device-side and so it is necessary to consider ensuring safety including
future network operation.
To create new value-added benefits from integrating networks and devices through mutual
understanding and trust among stakeholders, it is necessary to develop an environment that
creates more secure IoT systems through the close partnership between public and private
sectors. In particular, it is essential to acknowledge that IoT systems have different
characteristics from existing information systems, and take measures on the device-side and
network-side to ensure security for the whole system that consists of both objects and
networks.
Taking these needs into consideration, “Security by Design” should be a fundamental
principle in designing, deploying and operating IoT systems. A framework is needed to
confirm and verify the fundamental principle prior to deployment. To ensure IoT system
security, requirements should be defined and achieved during basic policy development, risk
assessment, system design, system development, and system operations and maintenance.
The following items should be clarified.
a) Definitions (including the applicability and the scope) of wide-ranging IoT systems
should be determined and clarified. Such systems should be categorized based on
2