NTIA Issues Request For Comments On Policies Related To Cyber Threats Surrounding Internet Of Things

SM
Sheppard Mullin Richter & Hampton

Contributor

Sheppard Mullin is a full service Global 100 firm with over 1,000 attorneys in 16 offices located in the United States, Europe and Asia. Since 1927, companies have turned to Sheppard Mullin to handle corporate and technology matters, high stakes litigation and complex financial transactions. In the US, the firm’s clients include more than half of the Fortune 100.
NTIA defines IoT broadly to include connection of physical objects, infrastructure, and environments to various identifiers, sensors, networks, and/or computing capability...
United States Media, Telecoms, IT, Entertainment
To print this article, all you need is to be registered or login on Mondaq.com.

On April 6, 2016, National Telecommunications and Information Administration (NTIA) issued a federal notice to request public comment on the benefits, challenges, and potential roles for the government in fostering the advancement of the Internet of Things (IoT).  (RFC at http://www.ntia.doc.gov/files/ntia/publications/fr_rfc_iot_04062016.pdf).

Comments are due on May 23, 2016.

NTIA defines IoT broadly to include connection of physical objects, infrastructure, and environments to various identifiers, sensors, networks, and/or computing capability – in essence, any device that gets data and sends instructions to devices and components over the Internet. IoT technology includes your refrigerator, a light bulb (or a light bulb in your refrigerator)  if it is connected to the Internet.  Until now, it has often seemed as though the focus of IoT product and application development is to provide basic connectivity without addressing any security concerns.  Establishing even minimal security, it was thought, was but an unnecessary cost that degrades device performance to boot.  But not surprisingly, this approach makes IoT devices more vulnerable to attacks – for example, by permitting a hacker to access sensitive user information by entering a user's home system through an unsecure IoT device.  An unsecure IoT device can provide a gateway by which a hacker can gain significant access to sensitive user information held by an unsuspecting consumer who simply wants his smart phone to control his ceiling fan.

NTIA seeks comment on a wide range of issues related to technology, infrastructure, economics, policy and those implicating international legal and policy considerations.  From the standpoint of privacy, the notice seeks comment on ways in which the government should respond and address confidentiality of personal data specific IoT, cybersecurity concerns about IoT, categorization of IoT, different treatment of consumer as opposed to commercial or industrial data, as well as comments related to disproportionate economic equity and the impact on disadvantaged communities.

In the best cases, government regulation could promote consumer privacy and security safeguards.  Industry standard setting organizations might lead to standardization of basic protocols including security authentication.  Many IoT devices today do not have even basic-password authentication.  A smart home security system may be tied to the home's original owner and changing  to security protocols to new homeowner (or renters) could be cumbersome.  By establishing a standardized means to address basic issues of security and customer service, IoT devices could promote interoperability between different manufacturers, streamline the practical aspects of unrelated transactions (like home sales) and, in turn, promote faster evolution and use of the technology.  This, indeed, appears to be NTIA's mission in the proceeding.

By promoting IoT and requesting comments on IoT cybersecurity issues, the NTIA IoT proceeding seeks to train the spotlight on what might be the weakest link in the consumer  and industrial "security chain:"  IoT devices.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

NTIA Issues Request For Comments On Policies Related To Cyber Threats Surrounding Internet Of Things

United States Media, Telecoms, IT, Entertainment

Contributor

Sheppard Mullin is a full service Global 100 firm with over 1,000 attorneys in 16 offices located in the United States, Europe and Asia. Since 1927, companies have turned to Sheppard Mullin to handle corporate and technology matters, high stakes litigation and complex financial transactions. In the US, the firm’s clients include more than half of the Fortune 100.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More