
ILT-U-4189
IoT Security Evaluation.GlobalPlatform SESIP – NISTIR 8425 Mapping
DETERMINATION | METHOD |
| NISTIR 8425 asset identification and product configuration | NIST AI1 / AI2 / PC1-PC3 assessed through SESIP identity, attestation, configuration, and secure-default evidence. |
| NISTIR 8425 data protection | NIST DP1-DP3 assessed through SESIP secure communication, cryptographic keystore, data protection, and secure storage evidence. |
| NISTIR 8425 interface access control | NIST IAC1-IAC2 assessed through SESIP authenticated access control, privileged access control, secure debugging, and interface protection. |
| NISTIR 8425 software update | NIST SU1-SU2 assessed through SESIP secure update of platform/application, secure install, integrity, and lifecycle evidence. |
| NISTIR 8425 cybersecurity state awareness | NIST CSA1 assessed through SESIP application/platform state, audit-log generation, secure log storage, and incident-relevant evidence. |
| NISTIR 8425 information reception and dissemination | NIST IQR1 and InD1-InD2 assessed through SESIP vulnerability handling, guidance, security target, and lifecycle support evidence. |
| NISTIR 8425 product education and awareness | NIST PEA1 assessed through SESIP guidance documents, user instructions, secure installation, maintenance, and decommissioning evidence. |
| SESIP assurance and lifecycle evidence | GlobalPlatform GP and ETSI EN references are assessed using the mapping workbook, with relationship type and fulfilled status recorded. |
| Overall SESIP-to-NISTIR 8425 PT performance | Qualitative comparison of PASS / FAIL / PARTIAL / NA-JUSTIFIED / UNASSESSED results with the ILT reference evaluation. |


