07/18/17 Communicating Upgradability and Improving Transparency Working Group,NTIA Multistakeholder Process on Internet of Things Security Upgradability andPatching,Working Group Co-Chairs: Harley Geiger(Rapid7), Aaron Kleiner(Microsoft), Beau Woods(Atlantic Council)1 I.Introductionand Scope Security of Internet of Things (IoT) devices is increasingly important to the security and safetyof consumers, businesses, and others.Security updatesare a key way toprotect IoT deviceswhenvulnerabilities are discovered and attacks evolve, though themethod andcapability ofIoT devices to receive security updatesvaries across devices, services, and deployments.ConsumersofIoTdevicesmay desirebasicinformationabout their devices’ securitycapabilities,particularly with regard towhether and how devices receive security updates.There isalsointerest on the part of many policymakers and technologists for promotingtransparency for consumers about the security needs and capabilities of internet-enableddevices.2In support of thisconcept, some stakeholders haveurged the development of anaccessible means of communicating security information to consumers prior to purchase.Ideas include product packaging labels, consumer-facing websites,and more. To advancethatdialogue,this document outlines information that manufacturerscancommunicate to better inform consumers and the marketplaceaboutIoTdevices’ capabilitytoreceivesecurityupdates(i.e., the"elements of updatability").This document is not intended torecommendexact language manufacturers must use, nor a specificmethod orvehicle forcommunicating the elements to consumers. Itis also important to note that updates and patches do not offer completedeviceprotectionand are not the sole security measuresIoTmanufacturers or consumers should take.Manufacturersmay alsoconsider advisingconsumers and industry partnerson additionalsecurity practices and policies that apply to the device, includingprudentstepsconsumersshould take tomaintain device security–such as password management, physical security, securing home wireless networks,privacy protection,and more.3However, this documentfocuses ondevicesecurity updates and does not discuss additional topics in detail. Tohelpidentify theelementsof IoTdeviceupdatability, thisworking groupleveraged a broadrange ofinputs.The working group looked to IoT security guidance from government sources(e.g., FederalTradeCommission, Department ofHomelandSecurity), non-profit organizations(e.g., Online Trust Alliance), and corporations (e.g., Microsoft), as well as public reportingabout IoT security developments (e.g., Mirai botnet).4The working group also consideredparticipants’ personaland anecdotalexperiences withinternet-connected devices.Theelements listed below represent the working group’s consensus recommendations, drawn fromparticipants’ perspectives as technologists, public policy specialists, and other relevantdisciplines. II.Elements of IoTsecurity updatability The working group developed two categories of informationabout updatabilitythat IoTdevicemanufacturers should consider communicating: keyelements and additionalconsiderations.Thefirstcategorylists what wedeterminedto be the most important elements for transparencyand informed choice, information thatmanufacturers should consider communicatingtoconsumers prior to purchase. The secondcategory lists considerations that may be helpful forconsumers but are not asfundamental to updatability as the first category, and which may bemade available to consumers before or after purchase. The working group observed that the elements below can be communicated in a variety ofways, though consideration should be given tocontext and ease of understanding.For allthese issues, the ideal level of detail and the method of communication may differ acrossmanufacturers, software providers, and product and service categories, as well as acrossbuyer types.Thesevoluntarycommunications may evolve over timeas threats, solutions, andproducts change, and as neededto be consistent with consumers’ familiarity, expectations,and security needs. A.Keyelementsthatmanufacturers should considercommunicatingto consumers prior to purchase Describewhether the device can receive security updates This description could provide a simple statement of whether the device is capable of receivingsecurity updates. A.2.Describehow the device receivessecurity updates This summarycould address thefollowing questions: oCan the device receive security updates automatically?Consumersmay have differentpreferences about updates and security management. For example, thosewithout ahigh degree of technical expertise maybe interested in automatic updates.oWhat user action is required to ensure the device is updatedcorrectly and inatimelyfashion?Understandingthe stepsconsumersmust take to keep the device updatedmightprovidesomeindication of the level ofend usercommitmentneeded to maintainthe device.Ifconsumersmust pay additional costs as a norma