Overview
ISO/IEC 24767-1:2008 - Information technology - Home network security - Part 1: Security requirements - defines security requirements and guidance for home electronic systems (HES) and home networks. It addresses threats originating inside or outside the home, offers risk-analysis approaches for each networked device, and gives design guidance for security mechanisms implemented locally or via the Internet. The standard is advisory (guidelines rather than prescriptive conformance clauses) and is intended as a foundation for developing HES security services.
Key topics and technical requirements
- Scope and purpose: Security requirements for a range of home devices (A/V “brown goods”, appliances “white goods”, informational devices) and the home network as a whole.
- Risk and threat analysis: Identification of threats such as unauthorized access, malicious software, denial-of-service (DoS/DDoS), unintended data modification, user errors and system failures.
- Security services & requirements:
- Access control and user authentication to ensure only authorized users/processes access devices and services.
- Data and message authentication and data integrity to verify source and prevent tampering.
- Protection of communications (confidentiality and secure channels).
- Remote access control for services accessed from outside the home.
- Firewalls, virus/malware protection, and DoS mitigation.
- Auditing and recovery capabilities to support incident analysis and system restoration.
- Operational challenges: Always-on devices, power-line and wireless vulnerabilities, diverse device capabilities and user requirements, and complex device assortments.
- Security models: Deployment models with differing responsibilities and requirements - Owner Supported Single home (OSS), Externally Supported Single home (ESS), Externally Supported Multiple homes (ESM).
- Design constraints: Multiple security levels per application, emphasis on convenience/usability, and requirement that the homeowner remains the security manager (even if functions are outsourced).
Applications and who should use it
- Product designers and firmware developers for connected appliances and entertainment devices.
- Home network architects, integrators and system engineers designing secure HES deployments.
- Service providers and content providers defining contractual security expectations for customer premises equipment.
- Security analysts and risk managers performing threat assessments for smart-home environments.
- Policy makers and consultants preparing home security guidance and best practices.
Related standards
- Other parts of the ISO/IEC 24767 series (see IEC web site for the list) and broader IT/security standards (e.g., authentication, secure communications) are complementary to this Part 1 guidance.
Keywords: ISO/IEC 24767-1:2008, home network security, security requirements, HES, access control, threat analysis, remote access, firewalls, data integrity.