Overview
ISO/IEC 27402:2023 - "Cybersecurity - IoT security and privacy - Device baseline requirements" defines a baseline set of ICT requirements that IoT devices should provide to support security and privacy controls. The standard is intended as a globally harmonized foundation for device capabilities, documentation and processes so that higher-risk sectors or vertical markets (health, industrial, transportation, consumer electronics, etc.) can build additional, sector-specific requirements on top.
Key topics and technical requirements
ISO/IEC 27402:2023 focuses on practical, device-level requirements that enable system-level security and privacy controls. Key technical topics include:
-
Risk management and documentation
- Devices shall have documentation recording the results of a device-level risk assessment performed in the context of system-level risk analysis.
- Risk assessments must consider intended use, interested parties, physical/logical undesired effects and constrained-device characteristics (battery, memory, CPU).
- Requirements to select risk treatment options and map required controls to device features.
-
Policy, disclosure and vulnerability handling
- Requirements for information disclosure, vulnerability disclosure policies and vulnerability handling processes to support responsible reporting and remediation.
-
Device capabilities and operations
- Baseline device features and operational controls, including:
- General security capability expectations
- Configuration management and secure defaults
- Software reset and factory default behavior
- User data removal and data lifecycle controls
- Protection of data (confidentiality, integrity - with consideration for cryptographic modules, CSP/SSP)
- Interface access controls for APIs and management interfaces
- Software and firmware updates processes and secure update mechanisms
- User notifications for security- and privacy-relevant events
-
Terminology and scope
- Defines IoT-specific terms (IoT device, IoT system, trusted computing base, cryptographic module) to ensure consistent interpretation.
Applications - who uses this standard
ISO/IEC 27402 is primarily useful for:
- IoT device developers and manufacturers designing baseline security/privacy features
- IoT system integrators and service providers evaluating device capabilities
- Product managers and security architects defining device requirements
- Regulators, certification bodies and conformity assessment schemes developing baseline compliance criteria
- Security assessors and vulnerability response teams leveraging documented disclosure/handling expectations
Related standards
- ISO/IEC 27400 (IoT security and privacy - Guidelines)
- ISO/IEC 27000 (Information security management vocabulary)
- ISO 31000 (Risk management guidance)
- Sector-specific references often cited with this baseline: ETSI EN 303 645 (consumer IoT), IEC 62443 (industrial automation security)
Keywords: ISO/IEC 27402:2023, IoT security, device baseline requirements, IoT privacy, risk assessment, firmware updates, vulnerability disclosure, data protection.