Characterizing collected information

The life cycle and scope of information pertinent to an IoT device can be narrowly defined or quite broad. In a PIA, one of the first activities is to identify information that will originate in, terminate in, or pass through the IoT-enabled system. At this point, one should create tables for the different life cycle phases and the data relevant to each. In addition, it is useful to use at least three different first-order ratings to give each information type based on sensitivity. For simplicity, in the following examples we use:

  • Not sensitive
  • Moderately sensitive
  • Very sensitive

Other rating types can be used depending on your organization, industry, or any regulatory requirements. Keep in mind that ...

Get Practical Internet of Things Security - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.