YD/T 6039-2024 in English
VALIDFundamental Security of Internet of Things Platform Security Graded and Categorized Management Evaluation Method
- Issued on:2024-10-24
- Implemented on:2025-02-01
- File Format:PDF
- Delivery:Via email within 5 business days
$801.00
| Standard No: | YD/T 6039-2024 |
| Document status: | VALID |
| Title in English: | Fundamental Security of Internet of Things Platform Security Graded and Categorized Management Evaluation Method |
| Title in Chinese: | 物联网基础安全 物联网平台安全分级分类管理评估方法 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2024-10-24 |
| Implemented on: | 2025-02-01 |
| ICS Classification: | 33.020-Telecommunications in general |
| Chinese Classification: | M10-Communication network in general |
| Professional Classification: | YD-Telecommunication |
Introduction
Overview of IoT Platform Security Grading and Assessment System
YD/T XXXX—XXXX "IoT Basic Security IoT Platform Security Grading and Classification Management Assessment Method" is an important standard in my country's IoT security field, constructing a complete five-level security assessment system. This standard provides a systematic security assessment methodology for platform types such as IoT connection management, device management, and application development support.
Standard Development Background and Technological Evolution
With the rapid development of IoT technology, the security threats faced by IoT platforms are becoming increasingly complex. This standard, as an important component of the IoT Basic Security series of standards, is compatible with the IoT Platform Security Grading and Classification Management Technical Requirements, forming a complete system of technical requirements and assessment methods. The standard development process fully considered the technical characteristics and business scenarios of IoT platforms, reflecting a progressive security concept from basic protection to advanced defense.
Comparative Analysis of the Hierarchical Assessment Framework
| Security Level | Data Security Requirements | Access Security Requirements | System Security Requirements | Management Requirements |
|---|---|---|---|---|
| Level 1 | Critical Data Encryption Storage and Transmission, Data Usage Authorization Verification | Single Factor Authentication, OTA Secure Transmission | Basic Host Security, Network Architecture Security | Risk Assessment, Configuration Management |
| Level 2 | Data Classification, Integrity Detection, Multiple Replica Backup | Preventing Unauthorized Access, Intrusion Detection, Integrity Identification | Virtualization Security, Security Audit, Regular Upgrades | Regular security assessment, configuration change control |
| Level 3 | Data storage integrity, critical data auditing, off-site disaster recovery | Two-factor authentication, brute-force attack prevention | Important program integrity testing, virtual machine migration security | Code auditing, vulnerability management |
| Level 4 | Data replay attack protection, dual-active data center construction | Advanced intrusion prevention | Integrity testing and recovery, boundary security monitoring | Advanced security management |
| Level 5 | To be determined | To be determined | To be determined |
Data Security and Personal Information Protection Assessment Requirements
Data security assessment is a core component of IoT platform security. The standard constructs a complete protection system from five dimensions: data storage, data transmission, data usage, data migration and backup, and personal information protection. Level 1 requires encrypted storage and transmission of critical data such as authentication information, sensitive personal information, and important business data to ensure authorization verification during data use.
Data Classification and Hierarchical Protection
Starting from Level 2, the standard requires the development of data classification strategies based on data category, attributes, and sensitivity, and the implementation of differentiated protection measures based on the classification results. The data storage stage requires support for optional configuration of encryption parameters, and the data transmission stage adds integrity detection requirements to ensure that data is not tampered with during transmission.
Advanced Data Protection Mechanisms
Level 3 assessment adds requirements for data storage integrity protection, critical data usage auditing, and off-site disaster recovery backup. Level 4 further strengthens the data's resistance to replay attacks and the requirements for dual-active data centers to ensure business continuity under extreme conditions.
Access Security Assessment Technical Requirements
Access security assessment focuses on authentication, intrusion prevention, and OTA upgrade security for IoT devices and cards. Level 1 requires the use of one or more authentication technologies in combination for authentication, ensuring upgrade files are transmitted via secure links.
Authentication Strengthening Mechanism
As security levels increase, authentication requirements become progressively stronger. Level 2 adds the requirement to block unauthorized access, and Level 3 requires the use of two or more authentication technologies in combination, with anti-brute-force attack capabilities. This progressive strengthening mechanism effectively addresses authentication risks at different security levels.
Intrusion Detection and Prevention
The standard requires the IoT platform to detect network attacks initiated by malicious access devices, record detailed information such as the attack source IP, attack type, attack purpose, and attack time, and promptly issue alerts in the event of a serious intrusion. Higher-level assessments also require real-time blocking and handling of attacks.
Basic Hardware and Software System Security Assessment
System security assessment covers multiple levels, including host security and virtualization security. Level 1 focuses on basic requirements such as authentication, access control, intrusion prevention, and malicious code prevention, adopting a minimal installation principle to ensure the necessity of system components.
Virtualization Security Requirements
Starting from Level 2, the standard adds virtualization security assessment requirements, including virtual machine security, network virtualization security, and system virtualization security. It requires support for isolation between virtual machines, deployment of antivirus software, and identification of malicious attack behaviors to ensure the security of the virtualization environment.
Security Audit Mechanism
The standard establishes a comprehensive security audit system, requiring audits to cover every user and audit important user behaviors and important security events. Audit information should include detailed information such as the date and time of the event, the user, and the event type, and audit records should be retained for no less than 6 months.
Key Points of Business and Application Security Assessment
Business and application security assessment focuses on authentication, access control, web security, and interface security. The standard requires security verification of input from all sources, assuming that all input may contain malicious information, and prioritizes the use of whitelist verification methods.
Web Security Protection
Starting from Level 2, server-side input verification is required to prevent client-side input verification from being bypassed. Level 3 adds code auditing requirements, requiring code audits before or after web application deployment to ensure that it does not contain high-risk or higher vulnerabilities released by CNVD and CNNVD more than 6 months ago.
Interface Security Control
High-level assessment requires data validity verification functions to ensure that the data format or length input through web interfaces or communication interfaces meets the system's set requirements, effectively preventing security threats such as injection attacks.
Security Management Assessment System
Security management assessment covers three dimensions: risk assessment, maintenance and upgrades, and configuration management.
The standard requires the establishment of a continuous risk identification and handling mechanism, timely patching of discovered security vulnerabilities and hidden dangers, and regular security assessments covering the entire platform. The standard requires recording and storing basic configuration information such as the platform's network topology, software components installed on each device, software component versions and patches, and recording and controlling changes to configuration information to ensure traceability of configuration management. Based on the standard requirements, the security construction of IoT platforms should follow the principle of **tiered implementation and continuous improvement**. It is recommended that enterprises first complete the construction of the first level of basic security requirements, and then gradually evolve to higher levels based on business needs and security risks. At the technical implementation level, a sound identity verification and access control system should be established first to ensure the effectiveness of basic security protection. Subsequently, advanced security functions such as data classification, security auditing, and intrusion detection should be gradually deployed to form a defense-in-depth system. Management System Construction At the management level, a dedicated security management team should be established, comprehensive security management systems and processes should be formulated, and regular security training and drills should be conducted to ensure the effective implementation and execution of security management requirements. Continuous Monitoring and Improvement A continuous security monitoring mechanism should be established, and regular security assessments and vulnerability scans should be conducted to promptly identify and address security risks. Simultaneously, security protection strategies and measures should be continuously optimized based on technological developments and threat changes. The implementation of this standard will effectively improve the overall security level of my country's IoT platforms and provide a solid security guarantee for the healthy development of the IoT industry. All relevant units should formulate practical implementation plans based on their own business characteristics and security needs to ensure the effective implementation of the standard requirements.
Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

YD/T 6185-2024 in English
Telecommunication data specification in the perspective of machine learning data service interface
2024-12-10 -

YD/T 6038-2024 in English
Fundamentals of Internet of Things (IoT) Security and Graded Technical Requirements for Categorized Management of IoT Platform Security
2024-10-24