The following are the lifecycle security considerations of the IMDA IoT Cyber Security Guide.
CK-LP-01
Have you conducted threat
modelling
to
identify,
analyse
and
mitigate
threats to the device?
-
M
M
M
Provide internal document(s) which
defines the process of threat modelling
including:
• Identify the potential
target(s)/assets/ areas of interest to
be protected
• Define the security problem
• Conduct risk assessment
• Determine the security objectives
• Define the security requirements
• Design and implement
• Validate and verify that the
capabilities address the security
requirements
CK-LP-02
Did you design and develop
the device using a secure
engineering approach?
-
M
M
M
Provide supporting document(s) to
provide
confidence
that
secure
engineering approaches have been
adopted and are effective. Examples
include the following:
• Reuse existing, well-secured
software: evidence showing the
code repository used to store and
maintain secured software for
reuse when suitable, or internal
documents describing the process
for the storage and usage of
CLS Publication #2 | Page 44 of 49