The U.S. Cyber Trust Mark – All You Need to Know

2023-08-23 08:51:28
关注

Illustration: © IoT For All

On July 18, 2023, the U.S. Administration announced that a cybersecurity certification and labeling program known as the Cyber Trust Mark, will soon be introduced.  

The Federal Communications Commission (FCC) proposed the program to raise the bar for cybersecurity across smart devices. It intends to make it easier for consumers to make purchases that are safer and less vulnerable to cyberattacks.  

We answer some of the common questions you may have about the new program. 

What is the Cyber Trust Mark?

Under the proposed program, a “U.S. Cyber Trust Mark” in the form of a shield logo will be displayed on products that meet the established cybersecurity criteria. This makes the safer product more easily identifiable for consumers to make informed decisions about the products they choose to purchase. 

Like the forthcoming Battery Regulation in the UK, the FCC also intends the use a QR code linking to a national registry of certified devices. Giving consumers access to more information about the smart product.  

What Criteria Is the Cyber Trust Mark Based On?

Products will be based on cybersecurity criteria published by the National Institute of Standards and Technology (NIST). For example, some of the requirements set out by NIST require unique and strong default passwords and incident detection capabilities. 

Is This a New Standard?

Yes, for the U.S., but not so much on the global stage. In fact, the introduction of this program actually brings the U.S. in line with its European counterparts with the CE Marking.  

In 2022, the EU Commission made cybersecurity mandatory for CE Markings of all radio equipment via the Radio Equipment Directive (RED). The directive will take effect on April 29, 2024, and covers the majority of IoT and wireless products. 

It is likely the Biden-Harris administration will be engaging its European partners toward harmonizing international standards. 

Which Type of Devices Are Covered?

The latest brief mainly highlights smart consumer products including “smart refrigerators, smart microwaves, smart televisions, smart climate control systems, smart fitness trackers, and more.”  

The program and regulations within are likely to align with current global cybersecurity labeling standards. For instance, the European CE Mark or the PSTI Bill in the UK. Stakeholders including manufacturers, importers, and distributors will be encouraged to increase cybersecurity for the products they sell or distribute.   

Does it Extend to Non-Consumer Smart Devices?

This is highly likely. After all, NIST is simultaneously defining cybersecurity requirements for routers. After all, these can be used to eavesdrop, steal passwords, and attack other devices and high-value networks.  

Additionally, the U.S. Department of Energy is also researching cybersecurity labeling requirements for smart meters and power inverters. 

When Will Cyber Trust Mark Start?

As of writing, the FCC is preparing to seek public comment regarding the cybersecurity labeling program. The implementation of the program is expected in 2024 with a grace period for stakeholders to the company.

The FCC, together with the Cybersecurity and Infrastructure Security Agency, will take some time to educate consumers to look for the new label when making purchasing decisions. They will also be encouraging major U.S. retailers to prioritize labeled products.

The Road Ahead

As we’ve said before, cybersecurity and data privacy regulations are only going to become more robust. This is another step in the right direction to protect users from malicious actors and the increasingly complex cyber-attack landscape.

Securing IoT devices is more important than ever. So, don’t wait till you suffer a cyberattack! Take a more proactive approach to cybersecurity hygiene today.

Tweet

Share

Share

Email

  • Cybersecurity
  • Data Analytics
  • IT and Security
  • Security
  • Standards & Regulations

  • Cybersecurity
  • Data Analytics
  • IT and Security
  • Security
  • Standards & Regulations

参考译文
美国网络信任标志——您需要知道的一切
插图:© IoT For All 2023年7月18日,美国政府宣布将推出一项网络安全认证和标签计划,称为“美国网络信任标志”(Cyber Trust Mark)。该计划由联邦通信委员会(FCC)提出,旨在提升智能设备的网络安全标准。其目的是让消费者更容易购买到更安全、更不容易受到网络攻击的产品。 我们回答了您可能对这项新计划有的一些常见问题。 **什么是“美国网络信任标志”?** 根据该计划,符合既定网络安全标准的产品将显示一个以盾形标志形式存在的“美国网络信任标志”。这使得消费者可以更轻松地识别出更安全的产品,从而做出明智的购买决策。 类似于即将出台的英国电池法规,FCC也打算使用二维码链接至国家认证设备登记册,为消费者提供有关智能产品的更多信息。 **“美国网络信任标志”基于哪些标准?** 产品将根据美国国家标准与技术研究院(NIST)发布的网络安全标准进行认证。例如,NIST设定的一些要求包括使用独特且强大的默认密码,以及具备事件检测能力。 **这是新的标准吗?** 是的,对于美国而言,但在全球范围内并非如此。事实上,该计划的推出实际上使美国与欧洲国家的标准(如CE标志)趋于一致。 2022年,欧盟委员会通过《无线电设备指令》(RED),规定所有无线电设备的CE认证必须包含网络安全要求。该指令将于2024年4月29日生效,覆盖大多数物联网和无线产品。 拜登-哈里斯政府可能会与欧洲国家展开合作,以推动国际标准的统一。 **哪些类型的产品被涵盖在内?** 最新的指南主要突出智能消费产品,包括“智能冰箱、智能微波炉、智能电视、智能温控系统、智能健身追踪器等”。 该计划和相关法规预计将与当前全球的网络安全标签标准相一致。例如,欧洲的CE标志或英国的PSTI法案。制造商、进口商和分销商等利益相关方将被鼓励提升其所销售或分销产品的网络安全水平。 **它会扩展到非消费者类智能设备吗?** 可能性非常高。毕竟,NIST正在同时制定路由器的网络安全要求。毕竟,这些设备可能被用于窃听、窃取密码,并对其他设备和高价值网络发起攻击。 此外,美国能源部也在研究智能电表和逆变器的网络安全标签要求。 **“美国网络信任标志”何时启动?** 截至目前,FCC正在准备就网络安全标签计划征求公众意见。预计该计划将在2024年实施,利益相关方将获得一段宽限期。FCC将与网络和基础设施安全局合作,花费一段时间来教育消费者在购买决策中注意新的标签。 他们还将鼓励美国的主要零售商优先销售带有该标签的产品。 **未来之路** 正如我们之前所说,网络安全和数据隐私法规只会变得越来越严格。这是朝着保护用户免受恶意行为者和日益复杂的网络攻击环境影响的又一步重要举措。保护物联网设备比以往任何时候都更重要。 因此,不要等到遭受了网络攻击才采取行动!从今天起,采取更主动的网络安全措施吧。 推文分享邮件 网络安全 数据分析 IT与安全 安全 标准与法规
您觉得本篇内容如何
评分

评论

您需要登录才可以回复|注册

提交评论

广告
提取码
复制提取码
点击跳转至百度网盘