
ILT-U-4170
Cybersecurity for Consumer IoT. (CSA CLS Level 4)
DETERMINATION | METHOD |
| Default password check | ETSI TS 103 701 TSO 5.1 / SP-151-5 Section 2.8 |
| No hardcoded credentials | ETSI TS 103 701 TSO 5.1 |
| Vulnerability disclosure mechanism | ETSI TS 103 701 TSO 5.2 |
| Software update mechanism | ETSI TS 103 701 TSO 5.3 |
| Update integrity verification | ETSI TS 103 701 TSO 5.3 |
| Secure credential storage | ETSI TS 103 701 TSO 5.4 |
| Secure communication | ETSI TS 103 701 TSO 5.5 |
| Deprecated protocol check | ETSI TS 103 701 TSO 5.5 – SSL/TLS/WEP |
| Attack surface minimization | ETSI TS 103 701 TSO 5.6 |
| Debug interface disabled | ETSI TS 103 701 TSO 5.6 |
| Software integrity | ETSI TS 103 701 TSO 5.7 |
| Personal data security | ETSI TS 103 701 TSO 5.8 |
| System resilience | ETSI TS 103 701 TSO 5.9 |
| Telemetry data examination | ETSI TS 103 701 TSO 5.10 |
| User data deletion | ETSI TS 103 701 TSO 5.11 |
| Input data validation | ETSI TS 103 701 TSO 5.13 |
| WPS brute-force resistance | SP-151-5 Section 2.10 Test 1 |
| WPS disabled by default | SP-151-5 Section 2.10 Test 1 |
| HNAP disabled | SP-151-5 Section 2.10 Test 2 |
| Remote admin disabled | SP-151-5 Section 2.10 Test 2 |
| UPnP disabled or secured | SP-151-5 Section 2.10 Test 2 |
| NAT-PMP disabled | SP-151-5 Section 2.10 Test 2 |
| Admin password policy | SP-151-5 Section 2.10 Test 3 |
| Configuration portal security | SP-151-5 Section 2.6 |
| Network services testing | SP-151-5 Section 2.7 |
| Firmware extraction & analysis | SP-151-5 Section 2.9 |
| Wireless security testing | SP-151-5 Section 2.10 |
| Telemetry monitoring | SP-151-5 Section 2.5 |
| Authentication testing | SP-151-5 Section 2.8 |
| Freeform penetration testing | SP-151-2 Section 6.3 Task 5 – minimum 4 days |
| Overall conformity with CSA CLS Level 4 | Qualitative assessment based on PASS / FAIL / NA verdicts per test case |


