Internet of Things (IoT) - Trustworthiness principles

ISO/IEC TS 30149:2024 provides principles for IoT trustworthiness based on ISO/IEC 30141 - IoT Reference Architecture.

General Information

Status
Published
Publication Date
23-May-2024
Current Stage
PPUB - Publication issued
Start Date
05-Apr-2024
Completion Date
24-May-2024
Ref Project

Buy Standard

Technical specification
ISO/IEC TS 30149:2024 - Internet of Things (IoT) - Trustworthiness principles Released:5/24/2024 Isbn:9782832284063
English language
34 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)


ISO/IEC TS 30149
Edition 1.0 2024-05
TECHNICAL
SPECIFICATION
Internet of Things (IoT) – Trustworthiness principles

All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or
by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either
IEC or IEC's member National Committee in the country of the requester. If you have any questions about ISO/IEC
copyright or have an enquiry about obtaining additional rights to this publication, please contact the address below or
your local IEC member National Committee for further information.

IEC Secretariat Tel.: +41 22 919 02 11
3, rue de Varembé info@iec.ch
CH-1211 Geneva 20 www.iec.ch
Switzerland
About the IEC
The International Electrotechnical Commission (IEC) is the leading global organization that prepares and publishes
International Standards for all electrical, electronic and related technologies.

About IEC publications
The technical content of IEC publications is kept under constant review by the IEC. Please make sure that you have the
latest edition, a corrigendum or an amendment might have been published.

IEC publications search - webstore.iec.ch/advsearchform IEC Products & Services Portal - products.iec.ch
The advanced search enables to find IEC publications by a Discover our powerful search engine and read freely all the
variety of criteria (reference number, text, technical publications previews, graphical symbols and the glossary.
committee, …). It also gives information on projects, replaced With a subscription you will always have access to up to date
and withdrawn publications. content tailored to your needs.

IEC Just Published - webstore.iec.ch/justpublished
Electropedia - www.electropedia.org
Stay up to date on all new IEC publications. Just Published
The world's leading online dictionary on electrotechnology,
details all new publications released. Available online and once
containing more than 22 500 terminological entries in English
a month by email.
and French, with equivalent terms in 25 additional languages.

Also known as the International Electrotechnical Vocabulary
IEC Customer Service Centre - webstore.iec.ch/csc
(IEV) online.
If you wish to give us your feedback on this publication or need

further assistance, please contact the Customer Service
Centre: sales@iec.ch.
ISO/IEC TS 30149
Edition 1.0 2024-05
TECHNICAL
SPECIFICATION
Internet of Things (IoT) – Trustworthiness principles

INTERNATIONAL
ELECTROTECHNICAL
COMMISSION
ICS 35.020; 35.030 ISBN 978-2-8322-8406-3

– 2 – ISO/IEC TS 30149:2024  ISO/IEC 2024
CONTENTS
FOREWORD . 4
INTRODUCTION . 5
1 Scope . 6
2 Normative references . 6
3 Terms and definitions . 6
4 Abbreviated terms . 7
5 Concept of trustworthiness . 7
5.1 Relation to trust . 7
5.2 Relation to context . 8
5.3 Relation to characteristics, behaviour, assurance and confidence . 9
6 Characteristics . 9
6.1 Safety . 9
6.1.1 General . 9
6.1.2 Safety goals . 10
6.1.3 Safety design . 10
6.1.4 Safety assurance and control. 10
6.2 Security . 10
6.2.1 General . 10
6.2.2 Security goals . 10
6.2.3 Security assumptions . 11
6.2.4 Security design . 12
6.2.5 Security assurance and control . 12
6.3 Privacy . 12
6.3.1 Overview . 12
6.3.2 Privacy goals . 13
6.3.3 Privacy assumptions . 14
6.3.4 Privacy design . 14
6.3.5 Privacy assurance and control . 15
6.4 Resilience . 15
6.5 Reliability . 16
7 Managing trustworthiness . 16
7.1 General . 16
7.2 Assumptions . 17
7.3 Assurance . 17
7.4 Risks . 18
7.5 Composition . 18
7.6 Trustworthiness profiles . 19
8 Building trustworthiness . 19
8.1 General . 19
8.2 Capability viewpoint . 19
8.3 Risk viewpoint . 20
8.4 Assurance viewpoint . 21
8.5 Operationalization . 21
Annex A (informative) Best practices for IoT trustworthiness . 25
A.1 Relation with ISO/IEC 30141 . 25
A.2 Concerns . 25

A.3 Patterns . 26
A.3.1 General . 26
A.3.2 Trustworthiness characterization method pattern . 27
A.3.3 Trustworthiness maturity model pattern . 28
A.3.4 Trustworthiness impact assessment pattern . 28
A.3.5 Trustworthiness engineering pattern . 30
A.3.6 Trustworthiness assurance pattern . 32
Bibliography . 33

Figure 1 – Relationship between ISO/IEC TS 30149 and ISO/IEC 30141 . 5
Figure 2 – Trustworthiness and trust . 8
Figure 3 – Concepts of characteristics, behaviour, assurance and confidence . 9
Figure 4 – Relationship between security and privacy . 13
Figure 5 – Trustworthiness characteristics examples . 16
Figure 6 – Goal oriented trustworthiness . 20
Figure 7 – Risk oriented trustworthiness . 21
Figure 8 – Assurance based on claims, arguments, and evidence . 21
Figure 9 – Conceptual model for trustworthiness . 22
Figure 10 – Determining risk factors within an RA . 23

Table 1 – Example of goals and properties . 20
Table 2 – Principles for trustworthiness operationalization . 22
Table A.1 – Concerns for an implementation architecture . 25
Table A.2 – Trustworthiness characterization pattern . 27
Table A.3 – Trustworthiness maturity model pattern . 28
Table A.4 – Trustworthiness impact assessment pattern . 28
Table A.5 – Trustworthiness engineering pattern . 30
Table A.6 – Trustworthiness assurance pattern . 32

– 4 – ISO/IEC TS 30149:2024  ISO/IEC 2024
INTERNET OF THINGS (IoT) –
TRUSTWORTHINESS PRINCIPLES
FOREWORD
1) ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission)
form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC
participate in the development of International Standards through technical committees established by the
respective organization to deal with particular fields of technical activity. ISO and IEC technical committees
collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental,
in liaison with ISO and IEC, also take part in the work.
2) The formal decisions or agreements of IEC and ISO on technical matters express, as nearly as possible, an
international consensus of opinion on the relevant subjects since each technical committee has representation
from all interested IEC and ISO National bodies.
3) IEC and ISO documents have the form of recommendations for international use and are accepted by IEC and
ISO National bodies in that sense. While all reasonable efforts are made to ensure that the technical content of
IEC and ISO documents is accurate, IEC and ISO cannot be held responsible for the way in which they are used
or for any misinterpretation by any end user.
4) In order to promote international uniformity, IEC and ISO National bodies undertake to apply IEC and ISO
documents transparently to the maximum extent possible in their national and regional publications. Any
divergence between any IEC and ISO document and the corresponding national or regional publication shall be
clearly indicated in the latter.
5) IEC and ISO do not provide any attestation of conformity. Independent certification bodies provide conformity
assessment services and, in some areas, access to IEC and ISO marks of conformity. IEC and ISO are not
responsible for any services carried out by independent certification bodies.
6) All users should ensure that they have the latest edition of this document.
7) No liability shall attach to IEC and ISO or their directors, employees, servants or agents including individual
experts and members of its technical committees and IEC and ISO National bodies for any personal injury,
property damage or other damage of any nature whatsoever, whether direct or indirect, or for costs (including
legal fees) and expenses arising out of the publication, use of, or reliance upon, this ISO/IEC document or any
other IEC and ISO documents.
8) Attention is drawn to the Normative references cited in this document. Use of the referenced publications is
indispensable for the correct application of this document.
9) IEC and ISO draw attention to the possibility
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.