The life cycle and scope of information pertinent to an IoT device can be narrowly defined or quite broad. In a PIA, one of the first activities is to identify information that will originate in, terminate in, or pass through the IoT-enabled system. At this point, one should create tables for the different life cycle phases and the data relevant to each. In addition, it is useful to use at least three different first-order ratings to give each information type based on sensitivity. For simplicity, in the following examples we use:
- Not sensitive
- Moderately sensitive
- Very sensitive
Other rating types can be used depending on your organization, industry, or any regulatory requirements. Keep in mind that ...