战略与国际研究中心-Privacy,-Security,-and-the-Internet-of-Things_71页_925kb
报告摘要
Internet of Things: Privacy & Security Summary
Core Content
The Internet of Things (IoT) refers to the network of physical objects embedded with sensors, software, and connectivity, allowing them to collect and exchange data. As of 2015, the number of IoT devices exceeded the number of people globally, and this trend is expected to continue, with estimates of 25 billion devices by 2015 and 50 billion by 2020. The FTC hosted a workshop in 2013 to examine the privacy and security implications of IoT devices sold to or used by consumers, focusing on consumer-facing products rather than business-to-business or machine-to-machine communications.
Main Benefits of IoT
- Healthcare: Connected medical devices like insulin pumps and blood-pressure cuffs enable patients to monitor their health remotely, improve disease management, and reduce healthcare costs.
- Home Automation: Smart meters and home automation systems allow consumers to monitor and manage energy use, enhance home security, and control various household devices through a single app.
- Transportation: Connected cars provide real-time diagnostics, navigation, and safety features, and may eventually enable self-driving capabilities, improving convenience and safety.
- General Convenience: IoT devices can notify users of environmental conditions, automate tasks, and offer new ways to interact with the environment, enhancing daily life.
Key Risks of IoT
- Security Vulnerabilities: IoT devices may be exploited to access and misuse personal information, launch attacks on other systems, and create physical safety risks.
- Privacy Concerns: Continuous data collection on personal habits, locations, and physical conditions raises privacy issues, with potential misuse of data for credit, insurance, and employment decisions.
- Consumer Confidence: Perceived risks may deter widespread adoption of IoT technologies, even if the actual risks are not realized.
- Data Breaches: Expansive data collection increases the risk of data theft and unauthorized access, potentially harming both personal information and device functionality.
Privacy Principles and Recommendations
The FTC workshop focused on applying Fair Information Practice Principles (FIPPs) to IoT, particularly security, data minimization, notice, and choice.
1. Security
- Companies should implement reasonable security measures from the start of product development.
- Best practices include:
- Conducting privacy or security risk assessments.
- Minimizing data collection and retention.
- Testing security measures before product launch.
- Ensuring employee training on security practices.
- Using trusted service providers with strong security protocols.
- Adopting a defense-in-depth approach to security.
- Implementing access control to prevent unauthorized access.
- Monitoring and patching vulnerabilities throughout the product lifecycle.
2. Data Minimization
- Companies should collect only the data necessary for the product or service.
- Options include:
- Not collecting data at all.
- Collecting only essential data.
- Collecting less sensitive data.
- De-identifying data when possible.
- If additional data is needed, consumer consent should be obtained.
3. Notice and Choice
- Notice and choice remain important for consumer privacy, but they should be context-sensitive.
- Choices are not required for data uses consistent with the transaction or consumer relationship.
- For unexpected data uses, companies should provide clear and prominent choices.
- Use-based models could be used as a supplement to notice and choice, but the FTC prefers a notice and choice approach due to the lack of comprehensive use-based frameworks and the need to address consumer concerns about sensitive information.
4. Legislation
- The FTC believes IoT-specific legislation is premature but supports flexible, technology-neutral federal privacy and security laws.
- Legislation should:
- Strengthen data security enforcement tools.
- Provide notification requirements in case of data breaches.
- Protect both personal information and device functionality.
- The FTC also recommends self-regulatory programs and multi-stakeholder collaboration to develop best practices and standards for IoT privacy and security.
FTC Initiatives
In the absence of comprehensive legislation, the FTC will continue to use existing tools to ensure IoT companies address privacy and security issues, including:
- Law Enforcement: Enforcing existing laws like the FTC Act, FCRA, and HI-TECH Act.
- Consumer and Business Education: Developing educational materials to raise awareness about IoT privacy and security.
- Multi-Stakeholder Participation: Engaging in groups to develop IoT-related guidelines, such as those on facial recognition and smart meters.
- Advocacy: Collaborating with other agencies, state legislatures, and courts to promote consumer protections.
Conclusion
The Internet of Things presents significant opportunities for consumers, but also substantial privacy and security risks. The FTC emphasizes the importance of reasonable security, data minimization, and contextual notice and choice as best practices. While legislation is not currently seen as necessary, the FTC advocates for flexible, technology-neutral laws to address emerging risks and protect consumer interests.
试读结束,高清完整版pdf/doc/ppt,请点下载