Data Protection

See also the technical counterpart to this section

The management and operational controls to support securing IoT device data according to organizationally-defined requirements.

Policies and procedures for IoT device data security roles.

Policies and procedures provide the details necessary to implement management and operational controls for establishing roles and responsibilities for IoT device data security. Actions that may be necessary:

Manufacturer:

Agency:

Policies and procedures for IoT device data integrity.

Policies and procedures provide the details necessary to implement management and operational controls to support IoT device and associated systems data integrity, including establishing the purpose, scope, roles, responsibilities, management commitment, and coordination of IoT devices among organizational entities, and the associated compliance activities. Actions that may be necessary:

Manufacturer:

Agency:

Policies and procedures to establish IoT device data integrity controls.

Policies and procedures provide the details necessary to implement management and operational controls that support secure implementation of the IoT device and associated systems data integrity controls. Actions that may be necessary:

Manufacturer:

Agency:

Policies and procedures for maintaining IoT device data integrity during software modifications.

Policies and procedures provide the details necessary to implement management and operational controls for reviewing and updating the current IoT device and associated systems while preserving data integrity. Actions that may be necessary:

Manufacturer:

Agency:

Policies and procedures for IoT device data handling and retention.

Policies and procedures provide the details necessary to implement management and operational controls for securely handling and retaining IoT device data, associated systems data, and data output from the IoT device, in accordance with applicable Federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements. Actions that may be necessary:

Manufacturer:

Agency:

Policies and procedures establishing IoT data backup.

Backup and recovery policies and procedures detail how to make backups of IoT device data and software as applicable. Actions that may be necessary:

Manufacturer:

Agency:

Policies and procedures for removing all data from IoT devices prior to maintenance and repairs.

Policies and procedures provide the details necessary to implement management and operational controls for when and how to remove all data from IoT devices prior to removing the devices from facilities for offsite maintenance or repairs. Actions that may be necessary:

Manufacturer:

Agency: