US Insurance Underwriters Launch Cyber Security Program

900303.gif

Underwriters Laboratories (UL) is the largest and best known independent, not-for-profit U.S testing laboratory. 

It appears the White House's vision of an Underwriters Laboratories-type certification for Internet of Things products could become a reality: a UL official says the organization is involved with the US government's initiative to promote such security certification standards.
"We are involved with those initiatives," says Maarten Bron, director of innovations at UL, of the White House's interest in coming up with a UL-type program for increasingly Internet-connected consumer devices. "The White House is trying to achieve is to foster collaboration between private and government sectors to come up with these standards … Plans are still in the making from the White House" side, he says, so he can't share any additional details at this time.

UL, meanwhile, also is putting the final touches on a test and certification program of its own for IoT products, Bron says. "For us, cybersecurity and IoT have been on the radar screen for a long time already. We are prepared to release a test and certification program for this" that draws from its customers' needs and concerns, he says.
"While many details of The White House initiative are still in development at this early stage, UL is prepared to align with the initiative in its goal to bring the public and private sectors closer together in fighting cybercrime," UL's Bron says.
The White House has been mulling a UL "seal" model for IoT security: Michael Daniel, special assistant to the President and the nation's cybersecurity coordinator, in an interview in April with Dark Reading, said the Obama administration considers an Underwriters Laboratories-type certification model a good fit for driving vendors to secure their increasingly Internet-connected consumer products.
"We are very much interested in voluntary models" for this, Daniel said in the interview. "A nonprofit consortium that would rate products … I find that model very intriguing and similar in the development" of IoT security and safety, he said.
Rumblings that the White House may be ready to take action on a cybersecurity UL emerged last week after Peiter C. Zatko, aka Mudge, tweeted that he was leaving Google's ATAP group to create a "#CyberUL." "Goodbye Google ATAP, it was a blast. The White House asked if I would kindly create a#CyberUL, so here goes!"

No official word from the White House nor details yet from Zatko, but UL's Bron confirmed that his organization was aware of and involved with the administration's initiative. UL's traditional role has been testing and certifying appliances for electrical safety, but it also created a cyber security division about four years ago. "It's about security in the virtual world," Bron says, including transaction-oriented electronic payments, namely certification of chip and PIN technologies, he says.
"We developed automated testing tools that … retrieve those settings from bank card chips and cross-validate against Visa best practices," for instance, he says. "In our labs, we accredit and certify components on behalf of Visa and MasterCard," for instance.

As for IoT, UL is looking at health and industrial controls systems, for example. "We're very much focused on trying to detect and mitigate known vulnerabilities … in devices such as for health and industrial control systems. We really see a strong need in the market."
Dark Reading: http://ubm.io/1KMNefT

 

« Countdown: 10 Things Cyber Crooks Could Do To Your Computer, Without Even Touching It
Assange Advised Snowden To Go to Russia »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

IT GRC Forum

IT GRC Forum

The IT GRC Forum is an online resource and networking platform for the Governance, Risk Management, and Compliance (GRC) community

Red Hat

Red Hat

Red Hat is a leader in open source software development. Our software security team proactively identifies weaknesses before they become problems.

Openminded (OPMD)

Openminded (OPMD)

Openminded is a French security and network services company.

National Cybersecurity and Communications Integration Center (NCCIC) - USA

National Cybersecurity and Communications Integration Center (NCCIC) - USA

NCCIC is a cyber situational awareness, incident response, and management center for the US Government, intelligence community, and law enforcement.

Introspective Networks

Introspective Networks

Introspective Networks (IN) is a Cybersecurity company focusing on securing data in the network and automating knowledge work to decrease vulnerability points to critical infrastructure.

Magal Security Systems (Magal S3)

Magal Security Systems (Magal S3)

Magal Security Systems is a leading international provider of integrated solutions and products for physical and cyber security, safety and site management.

infySEC

infySEC

InfySEC is an information security services organization offering Security Technology services, Security Consulting, Security Training, Research & Development.

Information System Authority (RIA) - Estonia

Information System Authority (RIA) - Estonia

RIA ensures the interoperability of the state’s information system, organises activities related to information security, and handles security incidents in Estonian computer networks.

FifthDomain

FifthDomain

We are a specialist cyber security education and training company tackling the global cyber security skills shortage.

Hawk Network Defense

Hawk Network Defense

HAWK.io is the First Fully Automated, Multi-Tenant, Cloud-Based, MDR Service Company.

Absa Cybersecurity Academy

Absa Cybersecurity Academy

Absa Cybersecurity Academy is an initiative aimed at empowering marginalised South African youths to become certified cybersecurity specialists.

CyberUK

CyberUK

CYBERUK is the UK government’s flagship cyber security event and the authoritative event for the UK’s cyber security community.

Alkira

Alkira

Alkira has reinvented networking for the cloud era by delivering the network cloud, the first global unified network infrastructure with on-demand hybrid and multi-cloud connectivity.

Cheops Technology

Cheops Technology

Cheops is a specialist in IT Business Technology Services. We help SMEs and large companies build, optimize and manage their IT so they can focus on their core business.

International Association of Financial Crimes Investigators (IAFCI)

International Association of Financial Crimes Investigators (IAFCI)

International Association of Financial Crimes Investigators provides services and information about financial fraud, fraud investigation and fraud prevention.

CRYPTIQ

CRYPTIQ

CRYPTIQ empowers businesses to navigate the ever-evolving cybersecurity landscape with confidence and clarity.