The following are the lifecycle security considerations of the IMDA IoT Cyber Security Guide. CK-LP-01 Have you conducted threat modelling to identify, analyse and mitigate threats to the device? - M M M Provide internal document(s) which defines the process of threat modelling including: • Identify the potential target(s)/assets/ areas of interest to be protected • Define the security problem • Conduct risk assessment • Determine the security objectives • Define the security requirements • Design and implement • Validate and verify that the capabilities address the security requirements CK-LP-02 Did you design and develop the device using a secure engineering approach? - M M M Provide supporting document(s) to provide confidence that secure engineering approaches have been adopted and are effective. Examples include the following: • Reuse existing, well-secured software: evidence showing the code repository used to store and maintain secured software for reuse when suitable, or internal documents describing the process for the storage and usage of CLS Publication #2 | Page 44 of 49

Select target paragraph3