2.4 Technical Construction File IoTSCS IoT F03 TCF Issue 4.0
2.4 Technical Construction File IoTSCS IoT F03 TCF Issue 4.0
Security Requirements for IoT Devices (for security, privacy and supply chain)
IoT device is defined as “an entity of an IoT system that interacts and communicates with the physical
world through sensing or actuating” [Source: ISO/IEC 27400:2022]. With the increasing number of
Internet of Things (IoT) devices and increasing reliance on such devices, the security and privacy risks
relating to those “things” are expected to grow. Their widespread deployment in networks and systems
make them easy and prime targets for cyber-attacks.
This document provides a set of security, privacy and supply chain requirements for IoT devices.
Adhering to these requirements will provide adequate confidence to the users in respect of security,
privacy and supply chain security of these devices.
Not all requirements outlined in this document are universally applicable to every IoT device. Users or
organizations have to assess and determine the specific security, privacy, and supply chain requirements
relevant to their use of these devices.
This document defines four assurance levels, with each level increasing in depth of testing.
Users/organizations can choose the appropriate assurance level depending on area of applicability,
sensitivity of data and operational needs.
• Level 0 is for minimal assurance level. Within 01 year of obtaining Level 0 compliance the IoT
devices has to seek certification for Level 1/Level 2/Level 3
• Level 1 is for low assurance levels and all IoT devices are expected to meet these requirements
• Level 2 is for IoT devices that contain sensitive data, which requires protection and is the
recommended level for most IoT devices
• Level 3 is for the most critical IoT devices - applications that perform high value transactions,
contain sensitive medical data, or any application that requires the highest level of trust.
Each IoT device can undergo certification any of these four levels as provided below:
Note:
1. Level 0 certification is valid for only one year and is a onetime occurrence. Developers are
encouraged to pursue Level 1/Level 2/Level 3 certification within this timeframe.
2. Level 1, Level 2, and Level 3 certifications are valid for three years, with one surveillance audit
required each year.
Page | 3
Document No.
Government of India STQC/IoTSCS/F03,
Ministry of Electronics & IT (MeitY) Issue No. 04
STQC Directorate Date: 13-09-2024
IT &eGov Division
Annexure ‘A’
Page | 6
Document No.
Government of India STQC/IoTSCS/F03,
Ministry of Electronics & IT (MeitY) Issue No. 04
STQC Directorate Date: 13-09-2024
IT &eGov Division
Page | 9
Document No.
Government of India STQC/IoTSCS/F03,
Ministry of Electronics & IT (MeitY) Issue No. 04
STQC Directorate Date: 13-09-2024
IT &eGov Division
Page | 16
Document No.
Government of India STQC/IoTSCS/F03,
Ministry of Electronics & IT (MeitY) Issue No. 04
STQC Directorate Date: 13-09-2024
IT &eGov Division
Annexure B
Page | 22
Document No.
Government of India STQC/IoTSCS/F03,
Ministry of Electronics & IT (MeitY) Issue No. 04
STQC Directorate Date: 13-09-2024
IT &eGov Division
Page | 47
Document No.
Government of India STQC/IoTSCS/F03,
Ministry of Electronics & IT (MeitY) Issue No. 04
STQC Directorate Date: 13-09-2024
IT &eGov Division
Annexure C
Supply Chain Security Requirements
Page | 48
Document No.
Government of India STQC/IoTSCS/F03,
Ministry of Electronics & IT (MeitY) Issue No. 04
STQC Directorate Date: 13-09-2024
IT &eGov Division
documents.
tools).
SC7 Supply chain risk Supply chain
identification, risk/business
assessment, continuity planning
prioritization, and policy documents,
mitigation shall be playbooks reflecting
conducted. how to handle supply
chain disruption,
post-incident
summary documents
need to be
submitted and
demonstrate
the same.
References
Page | 50