US Insurance Underwriters Launch Cyber Security Program

900303.gif

Underwriters Laboratories (UL) is the largest and best known independent, not-for-profit U.S testing laboratory. 

It appears the White House's vision of an Underwriters Laboratories-type certification for Internet of Things products could become a reality: a UL official says the organization is involved with the US government's initiative to promote such security certification standards.
"We are involved with those initiatives," says Maarten Bron, director of innovations at UL, of the White House's interest in coming up with a UL-type program for increasingly Internet-connected consumer devices. "The White House is trying to achieve is to foster collaboration between private and government sectors to come up with these standards … Plans are still in the making from the White House" side, he says, so he can't share any additional details at this time.

UL, meanwhile, also is putting the final touches on a test and certification program of its own for IoT products, Bron says. "For us, cybersecurity and IoT have been on the radar screen for a long time already. We are prepared to release a test and certification program for this" that draws from its customers' needs and concerns, he says.
"While many details of The White House initiative are still in development at this early stage, UL is prepared to align with the initiative in its goal to bring the public and private sectors closer together in fighting cybercrime," UL's Bron says.
The White House has been mulling a UL "seal" model for IoT security: Michael Daniel, special assistant to the President and the nation's cybersecurity coordinator, in an interview in April with Dark Reading, said the Obama administration considers an Underwriters Laboratories-type certification model a good fit for driving vendors to secure their increasingly Internet-connected consumer products.
"We are very much interested in voluntary models" for this, Daniel said in the interview. "A nonprofit consortium that would rate products … I find that model very intriguing and similar in the development" of IoT security and safety, he said.
Rumblings that the White House may be ready to take action on a cybersecurity UL emerged last week after Peiter C. Zatko, aka Mudge, tweeted that he was leaving Google's ATAP group to create a "#CyberUL." "Goodbye Google ATAP, it was a blast. The White House asked if I would kindly create a#CyberUL, so here goes!"

No official word from the White House nor details yet from Zatko, but UL's Bron confirmed that his organization was aware of and involved with the administration's initiative. UL's traditional role has been testing and certifying appliances for electrical safety, but it also created a cyber security division about four years ago. "It's about security in the virtual world," Bron says, including transaction-oriented electronic payments, namely certification of chip and PIN technologies, he says.
"We developed automated testing tools that … retrieve those settings from bank card chips and cross-validate against Visa best practices," for instance, he says. "In our labs, we accredit and certify components on behalf of Visa and MasterCard," for instance.

As for IoT, UL is looking at health and industrial controls systems, for example. "We're very much focused on trying to detect and mitigate known vulnerabilities … in devices such as for health and industrial control systems. We really see a strong need in the market."
Dark Reading: http://ubm.io/1KMNefT

 

« Countdown: 10 Things Cyber Crooks Could Do To Your Computer, Without Even Touching It
Assange Advised Snowden To Go to Russia »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Brookings Institution

Brookings Institution

The Brookings Institution is a nonprofit public policy organization. Cyber security is covered within the various study areas.

Thinklogical

Thinklogical

Thinklogical manufactures secure, KVM, video, audio, and computer peripheral signal switching solutions for defence C4ISR applications.

Invensis Learning

Invensis Learning

Invensis Learning is a professional training and certification company providing IT Service Management, IT Security & Governance, DevOps, Cloud Computing and Digital Awareness training.

GlassSquid

GlassSquid

glasssquid.io simplifies your cyber security job search. We want to help you find your next perfect fit opportunity by removing the confusion.

ETSI

ETSI

ETSI is a European Standards Organization dealing with telecommunications, broadcasting and other electronic communications networks and services including cybersecurity.

NeuroChain

NeuroChain

NeuroChain is an intelligent ecosystem that is more secure, more reliable and much faster than blockchain.

Techleap.nl

Techleap.nl

Techleap.nl is a non-profit publicly funded organisation helping to quantify and accelerate the tech ecosystem of the Netherlands.

ZARIOT

ZARIOT

ZARIOT's mission is to restore order to what is becoming connected chaos in IoT by bringing unrivalled security, control and quality of service.

GoVanguard

GoVanguard

GoVanguard is an boutique information security team delivering robust, business-focused information security solutions.

CYMOTIVE Technologies

CYMOTIVE Technologies

Combining Israeli cyber innovation with a century of German automotive engineering. CYMOTIVE operates under the assumption that connectivity is a game changer for the automotive industry.

PCS Security (PCSS)

PCS Security (PCSS)

PCS Security provides secure, reliable and state-of-the-art security solutions to help our customers address their security concerns.

Dope Security

Dope Security

Dope Security is a fly-direct Secure Web Gateway that eliminates the data center stopover architecture required by legacy providers, instead performing security directly on the endpoint.

AI Spera

AI Spera

AI-Driven Cyber Threat Intelligence Security. AI Spera provides real-time intelligence to empower your security competences in all aspects of the business.

Space Hellas

Space Hellas

Space Hellas is a dynamic, established System Integrator and Value Added Solutions Provider, holding a leading position in the high technology arena.

Dion Training Solutions

Dion Training Solutions

Dion Training Solutions offer comprehensive training in areas such as project management, cybersecurity, agile methodologies, and IT service management.

Edge Security

Edge Security

Edge Security is an information security research and consulting firm of expert hackers.