Secure by Design Code of Practice: Why it is important
Code outlines guidelines that manufacturers of consumer IoT devices should implement into their product’s design to keep consumers safe.
We’ve all heard the stats before. By 2020, over 12bn consumer devices will be internet connected. From your smart meter to your smart TV, these Internet of Things (IoT) devices can bring a range of benefits to consumers such as greater user experience and lower costs.
Concerns, however, have been raised about the poor security inherent within some of the connected consumer devices currently on the market and the lack of incentives for manufacturers to build security into the devices from the outset. Some of this is down to the lack of awareness amongst consumers of security weaknesses when buying devices, whilst others have argued that the multitude of standards and guidelines out there have made things too complicated for those creating IoT products and services.
That is why we at techUK were so keen to support the Department for Digital, Culture, Media and Sport (DCMS) in its ‘Secure by Design’ review, since it sought to address these problems by:
- Creating a Code of Practice for manufacturers of consumer IoT products and services
- Mapping guidelines in the Code of Practice to existing UK and international recommendations and standards
- Issuing consumer guidance on smart devices in the home
The publication of the Code of Practice is a watershed moment for the UK IoT and cyber security community. Developed in consultation with experts in government, industry and academia, the Code of Practice outlines thirteen guidelines that manufacturers of consumer IoT should implement into their product’s design to keep consumers safe and secure, ranging from the removal of default passwords to keeping software updated.
What has been refreshing about the development of the Code of Practice has been the enthusiasm from a range of stakeholders to get this right. From manufacturers and retailers to consumer groups and trade bodies, there has been agreement that we have to move the burden of responsibility for ensuring the security of the devices away from the consumer to one where strong cyber security is built into consumer IoT products by design and consumers can easily set up and manage a device in a secure manner.
The Government has also sought to make it easier for manufacturers to implement the Code by publishing a mapping document which links the thirteen guidelines to existing standards, recommendations and guidance on IoT security and privacy from around the world, representing one of the largest collections of guidance on IoT security and privacy to date.
A key aspect to the Code’s success will be through the international efforts that the Government undertakes, ensuring that guidelines from the Code drive global alignment across the IoT supply chain. Government can also help move the market towards a secure by design approach by ensuring that government departments purchase devices from suppliers that are adopting, or working towards adopting, the Code in a similar way that Cyber Essentials is now slowly being mandated across suppliers to local and central government.
The next step in the process is, of course, getting manufacturers to commit to implementing the Code and giving advice and guidance to consumers in order for them to set up and manage their devices in a secure manner. techUK will be continue supporting the Code, and working with its members as to strengthen consumer trust in the security of IoT products and services.
techUK’s CEO, Julian David, recently said “The Internet of Things (IoT) can benefit consumers by providing them with greater insight and control over their lifestyles. But citizens still have justified concerns about the level of security in IoT devices and we must address these if the IoT is ever to reach its full potential.
“We are pleased to have worked with Government and security experts to develop this Code of Practice and related documents as part of its Secure by Design Project. These offer companies a baseline to build on as they design their products and services with security front of mind. While it might take time for companies to fully align to all of the commitments, working towards achieving this will help strengthen consumer trust in the security of IoT”.
Latest News from
Call for #CounciloftheFuture guest blogs!15/10/2019 14:25:00
techUK want your guest blogs on what the future of local public services will look like in a digital age #CounciloftheFuture.
techUK Members win at WITSA 2019 Global ICT Excellence Awards15/10/2019 11:25:00
techUK is pleased to announce that our members Yoti and Chipside have pick up awards at the prestigious WITSA 2019 Global ICT Excellence Awards.
How can regulators help the UK achieve net zero?14/10/2019 11:20:00
The National Infrastructure Commission has reported on how regulation needs to shift to meet net-zero.
£13 million announced for new AI conversion courses14/10/2019 10:25:00
DCMS and the Office for AI have announced £13 million for AI and data science conversion courses over the next three years to help encourage a more diverse workforce.
The Schools & Academies Show returns to Birmingham10/10/2019 14:25:00
The event is taking place on the 13 – 14 November at the NEC in Birmingham. With only 34 days to go, register now!
Early Tech Career Network: Intro to Data Ethics10/10/2019 11:25:00
Connect with others who are also new to the tech sector! techUK's next Early Tech Career Network event will provide an introduction to Data Ethics with some great...
World Trade Report 2019 focuses on the future of services trade09/10/2019 16:25:00
Today, in Geneva, the World Trade Organisation has published its latest World Trade Report, focused on the future of services trade.
techUK responds to the release of the No-Deal Readiness Report09/10/2019 11:25:00
The No-Deal Readiness Report details the business conditions UK companies will face in the event of a no deal exit and highlights guidance provided by Government.