US Insurance Underwriters Launch Cyber Security Program

900303.gif

Underwriters Laboratories (UL) is the largest and best known independent, not-for-profit U.S testing laboratory. 

It appears the White House's vision of an Underwriters Laboratories-type certification for Internet of Things products could become a reality: a UL official says the organization is involved with the US government's initiative to promote such security certification standards.
"We are involved with those initiatives," says Maarten Bron, director of innovations at UL, of the White House's interest in coming up with a UL-type program for increasingly Internet-connected consumer devices. "The White House is trying to achieve is to foster collaboration between private and government sectors to come up with these standards … Plans are still in the making from the White House" side, he says, so he can't share any additional details at this time.

UL, meanwhile, also is putting the final touches on a test and certification program of its own for IoT products, Bron says. "For us, cybersecurity and IoT have been on the radar screen for a long time already. We are prepared to release a test and certification program for this" that draws from its customers' needs and concerns, he says.
"While many details of The White House initiative are still in development at this early stage, UL is prepared to align with the initiative in its goal to bring the public and private sectors closer together in fighting cybercrime," UL's Bron says.
The White House has been mulling a UL "seal" model for IoT security: Michael Daniel, special assistant to the President and the nation's cybersecurity coordinator, in an interview in April with Dark Reading, said the Obama administration considers an Underwriters Laboratories-type certification model a good fit for driving vendors to secure their increasingly Internet-connected consumer products.
"We are very much interested in voluntary models" for this, Daniel said in the interview. "A nonprofit consortium that would rate products … I find that model very intriguing and similar in the development" of IoT security and safety, he said.
Rumblings that the White House may be ready to take action on a cybersecurity UL emerged last week after Peiter C. Zatko, aka Mudge, tweeted that he was leaving Google's ATAP group to create a "#CyberUL." "Goodbye Google ATAP, it was a blast. The White House asked if I would kindly create a#CyberUL, so here goes!"

No official word from the White House nor details yet from Zatko, but UL's Bron confirmed that his organization was aware of and involved with the administration's initiative. UL's traditional role has been testing and certifying appliances for electrical safety, but it also created a cyber security division about four years ago. "It's about security in the virtual world," Bron says, including transaction-oriented electronic payments, namely certification of chip and PIN technologies, he says.
"We developed automated testing tools that … retrieve those settings from bank card chips and cross-validate against Visa best practices," for instance, he says. "In our labs, we accredit and certify components on behalf of Visa and MasterCard," for instance.

As for IoT, UL is looking at health and industrial controls systems, for example. "We're very much focused on trying to detect and mitigate known vulnerabilities … in devices such as for health and industrial control systems. We really see a strong need in the market."
Dark Reading: http://ubm.io/1KMNefT

 

« Countdown: 10 Things Cyber Crooks Could Do To Your Computer, Without Even Touching It
Assange Advised Snowden To Go to Russia »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Zertificon Solutions

Zertificon Solutions

Zertificon is a leader in professional email encryption and data security.

AuthenTrend

AuthenTrend

AuthenTrend provide biometric authentication products to achieve high security with extreme ease-of-use for the user.

Bolton Labs

Bolton Labs

Bolton Labs is a leading provider cybersecurity services, tools, and analysis for MSPs and organizations who want to scale their security offerings.

SecureBrain

SecureBrain

SecureBrain software and services help protect against Japanese-specific cybercrime and global internet security threats such as online fraud, phishing, drive-by downloads and malware attacks.

Applied Risk

Applied Risk

Applied Risk is an established leader in Industrial Control Systems security, focused on critical infrastructure security and combating security breaches that pose a significant threat.

Anitian

Anitian

The Anitian Compliance Automation platform builds, configures, and monitors cloud environments to accelerate compliance for standards such as FedRAMP, PCI, ISO/GDPR and CJIS.

Solidified

Solidified

Solidified is the largest audit platform for smart contracts. Our community has the highest concentration of top Blockchain security specialists and best-in-class code auditors.

QNu Labs

QNu Labs

QNu Labs’s quantum-safe cryptography products and solutions assure unconditional security of critical data on the internet and cloud across all industry verticals, globally.

Qualcomm Technologies

Qualcomm Technologies

Qualcomm invents breakthrough technologies that transform how the world connects, computes and communicates.

SecondWrite

SecondWrite

SecondWrite’s next-generation malware detection engine delivers a combination of automatic deep code inspection and accurate scoring of zero-day malware.

Securosys

Securosys

Securosys is a technology company dedicated to securing data and communications. We develop, produce, and distribute hardware, software and services that protect and verify data and their transmission

Navisite

Navisite

Navisite is a combination of eight respected IT consulting and managed service providers that were brought together under the Navisite brand.

PhishProtection

PhishProtection

We created Phish Protection to prevent all types of phishing including spear phishing protection and office 365 email protection for your small business.

Centroid

Centroid

Centroid is a cloud services and technology company that provides Oracle enterprise workload consulting and managed services across Oracle, Azure, Amazon, Google, and private cloud.

MLSecOps Community

MLSecOps Community

The MLSecOps Community is a collaborative space for machine learning security experts and industry leaders to connect and shape the future of AI/ML security.

Sinergi Digital

Sinergi Digital

Sinergi Digital is a business unit of the Metrodata Group with a focus on providing ICT solution to help accelerating digital transformation.