While marketers and promoters bask in and expound the great abundance they would like to associate with the Internet of Things (IoT), it’s very easy for all involved to get distracted from the most basic and most important human qualities. Right now, personal privacy and security should be the number one priority of all, from consumers to tech pros. These are the only qualities of life one still has the choice to either retain or, foolishly, relinquish.
It is true that the IoT will provide many good and great things from e-commerce to personal fitness and healthcare, and just about everything in between. It also stands to reason that anything on and/or related to the internet provides equal, if not greater opportunities for those who have their “personal abundance” in mind.
NIST fellow and leader of the task force that updated the publication Ron Ross says,
SP 800-53 Revision 5 adds two new control families that focus solely on privacy; the remaining privacy controls are integrated throughout the rest of the control families. For example, one privacy control addresses the data captured by sensors such as those used in traffic-monitoring cameras in smart cities. The control advises configuring such sensors in a way that minimizes their capturing data about individuals that’s not necessary for the traffic-monitoring system to carry out its function.
While previous versions targeted federal agencies, other organizations, particularly industry, are voluntarily adopting SP 800-53. The controls have been updated to address the needs of a more diverse user group, including enterprise-level security and privacy professionals, component product developers, and systems engineers who are now working on privacy and security.
For example, an IT system may employ cameras. Security experts determine security controls for the camera sensor, while privacy professionals decide on privacy controls such as a control to preserve a passerby’s privacy. Also, the control selection process is now separated from the security control catalog and included in the NIST Risk Management Framework, described in NIST Special Publication 800-37, so that organizations outside of the federal government can more easily use the NIST controls with the frameworks they currently use, such as ISO 270001 and the Framework for Improving Critical Infrastructure Cybersecurity, also known as the Cybersecurity Framework.
The authors also request comments on the Revision 5 draft by September 12, 2017. If this interests you, and indeed it should, you can easily, without having to fill in a form, download a copy of Draft NIST Special Publication 800-53, Revision 5 - Security and Privacy Controls for Information Systems and Organizations. And remember; take care of your personal privacy and security by reading more.