
ILT-U-4137
Cybersecurity for Consumer IoT. (CSA CLS Level 3)
DETERMINATION | METHOD |
| Firmware extraction & hash verification | SP-151-2 Section 5 – Binary Analysis methodology |
| Firmware filesystem analysis | SP-151-2 Section 5 – Component identification |
| Kernel identification | SP-151-2 Section 5 – Binary analysis |
| User-space binary identification | SP-151-2 Section 5 – Binary analysis |
| Library identification | SP-151-2 Section 5 – Binary analysis |
| Configuration file analysis | SP-151-2 Section 5 – Credential/secret detection |
| SBOM generation | SP-151-2 Section 5 – Software Bill of Materials |
| SBOM completeness verification | SP-151-2 Section 5 – Cross-reference validation |
| Automated vulnerability scanning | SP-151-2 Section 5 – CVE-bin-tool, Grype, Semgrep |
| CVE correlation | SP-151-2 Section 5 – NVD/CVE database mapping |
| CVSS severity classification | SP-151-2 Section 5 – CVSS v3.1 scoring |
| Hardcoded credential detection | ETSI TS 103 701 TSO 5.1 / SP-151-5 Section 2.7 |
| Debug interface detection | ETSI TS 103 701 TSO 5.6 / SP-151-5 Section 2.9 |
| Malware/backdoor check | SP-151-2 Section 5 – Signature scanning |
| Software integrity verification | ETSI TS 103 701 TSO 5.7 – Firmware signing |
| Update mechanism analysis | ETSI TS 103 701 TSO 5.3 – OTA integrity |
| Secret storage analysis | ETSI TS 103 701 TSO 5.4 – Credential protection |
| Communication security analysis | ETSI TS 103 701 TSO 5.5 – Crypto libraries |
| Input validation analysis | ETSI TS 103 701 TSO 5.13 – Web server binaries |
| Overall conformity with CSA CLS Level 3 | Qualitative assessment based on PASS / FAIL / NA verdicts per test case |


