Cybersecurity Guidelines for the Internet of Things

Traffic Light Protocol (TLP):

  • This marking protocol is widely used around the world. It has four colors (traffic lights):

    • Red – Personal, Confidential and for Intended Recipients Only The recipient has no rights to share information classified in red with any person outside the defined range of recipients either inside or outside the organization.

    • Amber – Restricted Sharing The recipient may share information classified in amber only with intended recipients inside the organization and with recipients who are required to take action related to the shared information.

    • Green – Sharing within The Same Community The recipient may share information classified in green with other recipients inside the organization or outside it within the same sector or related to the organization. However, it is not allowed to exchange or publish this information on public channels.

    • White – No Restriction

Executive Summary

The National Cybersecurity Authority has prepared the Cybersecurity Guidelines for the Internet of Things (CGIoT-1:2024), which are recommended for implementation in all entities using Internet of Things technology in the Kingdom; this is to reduce the cybersecurity risks associated with the widespread adoption of the Internet of Things.

These guidelines cover four main components: Cybersecurity Governance, Cybersecurity Enhancement, Cybersecurity Resilience, and Cybersecurity related to Third Parties and Cloud Computing.

The (Cybersecurity Governance) component is concerned with ensuring that the entity’s strategy, vision, roadmap, and objectives take into account the cybersecurity of the Internet of Things. This includes compliance with relevant regulations and legislations. This component also involves documenting and publishing cybersecurity policies and procedures related to the Internet of Things, in addition to ensuring the identification of cybersecurity roles and responsibilities for the Internet of Things for all relevant parties within the entity, within the governance structure. This component also clarifies the recommended guidelines to be applied regarding the management of cybersecurity risks for the Internet of Things, and ensures the inclusion of cybersecurity requirements for the Internet of Things in the lifecycle of information and technology project management. Furthermore, it focuses on the cybersecurity aspect of the Internet of Things concerning human resources, and the development of awareness and training programs for employees in the field of cybersecurity related to the Internet of Things.

Regarding the (Cybersecurity Enhancement) component, it is concerned with ensuring the application of appropriate cybersecurity mechanisms for the Internet of Things technology system in order to protect information and its assets against cyberattacks. Meanwhile, the (Cybersecurity Resilience) component is concerned with enhancing the entity’s ability to withstand the impacts that may arise due to incidents related to the cybersecurity of the Internet of Things.
The (Cybersecurity related to Third Parties and Cloud Computing) component addresses the need for effective management of cybersecurity risks related to third parties that support Internet of Things operations; including risks associated with cloud computing services.

This document also contains the cybersecurity principles for the Internet of Things for manufacturers, as detailed in Annex (A), which are recommended to be applied by companies manufacturing Internet of Things technology, in order to reduce cybersecurity risks in Internet of Things products and services.

Introduction

The term Internet of Things refers to sensors and devices ("things") connected to the internet and/or other networks, which add value based on data; such as facilitating tasks. Internet of Things technology supports many use cases including smart homes, smart cities, smart healthcare, and smart vehicles. Due to the widespread adoption of this technology, entities using Internet of Things technology may be more exposed to cyber threats and risks.

Accordingly, the National Cybersecurity Authority, hereinafter referred to in this document as (the Authority), has prepared the Cybersecurity Guidelines for the Internet of Things (CGIoT-1:2024). This was done after conducting a comprehensive study of several global guidelines, standards, frameworks, and regulations related to cybersecurity, as well as analyzing the current situation; legislative and regulatory requirements in the field of Internet of Things technology in the Kingdom, and analyzing previously observed cyber incidents and attacks related to the Internet of Things. The Cybersecurity Guidelines for the Internet of Things (CGIoT-1:2024) provide general guidelines concerning Internet of Things technology, and for the Industrial Internet of Things, compliance with the Cybersecurity Controls for Operational Technology Systems (OTCC-1:2022) is required.

The Cybersecurity Guidelines for the Internet of Things consist of:

• 4 Main Domains.

• 27 Subdomains.

• 81 Guidelines.

In addition, the document contains (11) cybersecurity principles for the Internet of Things for manufacturers, detailed in Annex (A).

Objectives

This document aims to provide non-binding guidelines intended to incorporate best cybersecurity practices for entities using Internet of Things technology. These practices are based on leading standards, which help entities, when applied, to mitigate cybersecurity risks of the Internet of Things arising from internal and external threats.
With the increasing reliance on interconnected technologies, potential cybersecurity risks may emerge within the Internet of Things ecosystem. Therefore, it is recommended to continuously incorporate cybersecurity requirements into the governance, development, maintenance, and management of the Internet of Things to ensure the protection of the interests of the stakeholders in this ecosystem.

These guidelines take into account the four fundamental pillars on which cybersecurity is based, namely:

• Strategy

• People

• Process

• Technology

Scope of Work and Applicability

The Authority recommends that all entities using the Internet of Things in the Kingdom, hereinafter collectively referred to in this document as (the Entity), follow these guidelines to ensure the application of a minimum standard of best practices and to reduce the cybersecurity risks that may arise from the use of this technology. The Authority also encourages manufacturers of Internet of Things technology products to adhere to the guidelines contained in this document, as well as the Cybersecurity Principles for Internet of Things Manufacturers (set forth in Annex (A)) when developing Internet of Things products and services.

Due to the constantly evolving nature of cyber threats, the Authority urges all entities and manufacturers to conduct periodic reviews and cybersecurity risk assessments to determine the need for additional measures regarding Internet of Things cybersecurity.

Components and Structure of Cybersecurity Guidelines for the Internet of Things

Cybersecurity Guidelines for the Internet of Things

Annexes

Annex (A): Cybersecurity Principles for the Internet of Things for Manufacturers

Annex (B): Terms and Definitions

Next section title

Next section content