Please Rewrite

profileiken305
PolicyDraftingExerciseInternetofThingsIoT.docx.docx

Running head: POLICY DRAFTING ECERCISE 2

POLICY DRAFTING ECERCISE 2

Policy Drafting Exercise: Internet of Things (IoT)

Student’s Name

Institutional Affiliation

Policy Drafting Exercise: Internet of Things (IoT)

The internet of things (IoT) is a system of interlinked networks through which sensors or objects are connected using information infrastructure, exchanging data without the need for human-to-machine interaction (Alaa et al. 2017). Examples of IoT include smart home devices, smart factories, internet of medical items, and intelligent city infrastructures. The primary aim of the internet of things is to enhance connectivity to all physical objects. Presently, vast research on IoT has been tailored to facilitate and enable the anticipated efficient and ubiquitous communications especially to things with minimal human interventions. Different scholars have implied that in the near future, businesses and societies will shift from being interested in IoT to being heavily reliant on it. An IoT enabled home (Smart-home) is an excellent example of this technology that shows the benefits as well as the issues that may arise from using IoT.

Homes utilizing IoT are referred to as connected or smart home. Other scholars define the IoT enabled homes as eHomes. A connected home is a living area that utilizes high-tech automated systems. These homes can also be defined to be “intelligent” because all the activities conducted in that home are monitored using computer systems. A connected home comprises of various technologies through home networking that works together to improve the quality of the users’ lives. Some of the characteristics of an eHome include having an advanced automatic system for monitoring and controlling home appliances, temperature and lighting, security systems, as well as multi-media equipment, among other functions (Alaa et al. 2017). The IoT performs a significant part in establishing a smart home. It is via IoT that all objects used in performing daily human activities can be integrated into the internet. IoT makes it possible to monitor and regulate all linked devices irrespective of the location and time.

A connected home system comprises of applications that are built using the IoT technology. The leading roles of eHome appliances include sending alerts. The eHome should be able to sense its environment and channel signals to the homeowner using a trusted device or account accordingly. The alert offers a message that aligns with the environmental information including the level of the various gases in the home, light intensity, temperature, and humidity (Malche & Maheshwary, 2017). Alerts can be channeled to the homeowner using text messages, tweets, email, or any appropriate social media channel. Another function of a connected home is to monitor its environment using camera feeds and sensors. Monitoring is a vital task as it helps in keeping trace all the undertakings in the eHome, which acts as a ground on which any further decision can be made, or further action is taken (Alaa et al. 2017). A good example is when the room temperature is monitored and an alert sent to the homeowner to turn on an air-conditioner if the temperature is beyond the optimum level. A smart home enables the user to take charge of different activities. The user can control various actions, including turning on and off air-conditioners, lights, and other home appliances, open or close windows and doors and many others. An IoT enabled home permits the homeowner to regulate activities from the same location or remote place (Feng et al. 2017). The control function can enable the owner to program various operations such as switching on or off the air-conditioner depending on the level of room temperature.

Another essential function of a smart home is home intelligence, which incorporates every dynamic behavior of the connected-home environment. This purpose is in line with the automatic decision making as well as the occurrence of other events. Home intelligence relies on the artificial intelligence mechanism that is found in the connected home environment (Malche & Maheshwary, 2017). The intelligence function gives the brain to the connected home as well as contributes to the security perspective in a home. Home intelligence enhances an interlinked environment in the connected residence whereby the artificial intelligence system identifies and appropriately responds in the line of the changing events or conditions.

Various smart home applications make use of the internet of things. These applications include the smart lighting which is achieved by aligning the lighting system to the required conditions by dimming off or switching on and off lights to match the needs of the user. This application is essential for energy-saving thus lowering the unnecessary waste of energy. Some of the conventional methods of implementing smart lighting systems include using IP-powered bulbs, which can be controlled using the internet (Feng et al. 2017). Smart lighting systems function by detecting the level of LUX, temperature in the environment as well as the occupancy. Another type of smart home application is smart appliances, which are significant for collecting the status information of different tools thus controlling the devices from either the same place or remotely. Smart appliances can also be used to schedule activities at a specific time as well as runtime coordination.

Another type of smart home application is detecting intruders through text message or email. This device works by sending explicit reports accompanied with videos or images to the homeowner. The app has a stored database of the suspected attackers which are channeled to the homeowners. This system is crucial as it monitors suspicious purposes in the connected home and alerts the owner to respond appropriately for safety purposes (Stojkoska & Trivodaliev,2017). At that point of attack, the intruder detection service can implement different automatic activities such as locking down particular servers or lock down all the internet links. The system also launches back evidence and tries to locate the attackers and come up with enough proof of the disreputable actions. The smart home also applies to the detection of smoke in the house. The smoke detector is used for ionization, air sampling, and optical detection (Malche & Maheshwary, 2017). The system raises alert to the nearest fire service when a situation arises. It also sends a message to the home user via email informing, and if the user is inside the house, the alarms are so loud and piercing hence can wake the user up when asleep.

Some of the benefits of using IoT at home include saving on costs. Smart home appliances utilize minimal energy while cutting overheads on utility costs. Besides, connected homes increase in value over time making it easier to sell thus yielding higher returns. IoT enabled households enhance safety by protecting the people living in the house (Roshan & Ray, 2016). This is possible through the monitoring and control systems on daily activities as well as sending alerts in case of a dangerous situation. Another benefit of a connected home is that it prevents damage. The user or homeowners can monitor their homes even when they are away remotely. This enhances security in that even if the oven is left on or any other dangerous condition the user will be alerted and control the situation. Having IoT in homes helps in enhancing convenience. Smart home offers customized living space and ease living (Alaa et al. 2017). For instance, a connected home can remind users when they are running low on household goods, and the security systems and smart doors offer a sense of confidence to the homeowner. Smart homes are efficient, and they save on time. The machine-to-machine interaction enhances efficiency which brings about accurate results in a little time. Smart homes save on valuable time in that users do not need to repeat similar tasks every day, which creates an opportunity for individuals to focus on other creative jobs.

Some of the challenges associated with IoT at home include internet availability. Smart homes heavily rely on internet connections whose reliability and availability are still a challenge to many countries (Roshan & Ray, 2016). For IoT consumer adoption or smart homeowner, this may pose a significant problem. Another demerit is the high costs incurred when installing the IoT systems in homes as well as the connected home appliances. As the popularity of the IoT homes is increasing, the price of these systems and devices is skyrocketing locking most individuals from acquiring it. Lack of uniform standards and interoperability is another issue that needs to be addressed for efficient smart homes. Standards are crucial when establishing markets for emerging technologies. Therefore, if appliances from different manufacturers fail to agree on the rules to comply with, which makes interoperability difficult, thus calling for more gateways to translate from one standard to the other (Stojkoska & Trivodaliev,2017). Besides, when the data standards are dissimilar, there is a high probability of locking out the consumers into one family of products. This may result in the users losing all the benefits of data that they may have accumulated over time as a result of replacing their devices with those from different manufacturers.

Another challenge is the security issues that may arise when IoT connects many devices, thus providing more entry points for malware. In most cases, the less expensive devices are more subject to tampering. Trust and privacy issues may arise because of the enormous IoT data being transmitted which increases the risk of losing privacy (Stojkoska & Trivodaliev,2017). Hackers may use third-party vendors’ stolen credentials to access the security system and other essential data. Compatibility and complexity issues may arise in smart homes because devices from various manufacturers are interlinked thus bringing about the challenge of compatibility in monitoring and tagging crops up. The IoT is a complex and diverse network; hence, any bugs or failure in the hardware or software results in adverse consequences (Malche & Maheshwary, 2017). For instance, power failure may cause a lot of damage and inconvenience.

IoT has led to a new level of risk, and the primary concern of the consumers is privacy and information security of the information collected by the smart objects. As defined by the CASAGRAS, IoT is a global network of infrastructure linking both virtual and physical objects to communication capabilities and exploitation of data collected in the process. This technology will offer different utilities, among them, object connection and identification capabilities, as the basis for developing applications and comparative services. This technology is expected to involve mass participation in critical services such as energy transportation and democratic stability. But the omnipresent nature of the device’s users has started to get concerned as the objects can exchange information without the user even noticing. This, in turn, leads to a new level of security risk concerning the information collected by the objects, and the severity of each risk is dependent on the environment in which the IoT application was deployed.

Therefore, the four main areas that provide the basis for IoT are the ones that are targeted by security and privacy policies. These key areas include pervasive identification, sensing, processing, and networking. The first part of the policy focuses on ensuring that there are availability and continuity in the provision of IoT. This is one of the common risks that lead to information security issues. This directly relates to the architecture of the IoT facilities. The very basic models used in the building the objects should use a high-level inscription and update system. To avoid attackers from accessing the objects remotely, the model should include high-level firewalls and also an automatic update system, thus giving the system the ability to adapt to the continually growing technology and even the levels of threats the technologies come with (Andrea, Chrysostomou, & Hadjichristofi, 2015). For example, consider a power grid in which the system can be reprogrammed remotely by attackers. This could lead to significant security problems, and it may be challenging for the power to be restored and this means that the data collected in the homes connected to the grid will be vulnerable. Even for those whose identity is not known, their addresses and very confidential information may be exposed to the attackers.

Related to the architecture of the objects and smart devices, the design also matters significantly in the enhancement of data protection and information security. Most companies add this feature after they have adopted a design and even built the smart devices, but in the real sense, this should be done at the design stage. Adding security features while the intended functionality is already running makes the security upgrade not effective thus reducing the efficiency of the entire system less efficient. The IoT objects also lack the computing capabilities to implement all the security upgrades that are added up later thus making the heterogeneity of the objects challenging. The policies should also be heterogeneous (Bertino & Islam, 2017). The more an individual is involved in the process, the more IoT has to consider security and privacy of the information generated and also the policies that apply in that context. Therefore, in coming up with policies, one must consider the purpose of the object and also the context. For example, in smart energy and smart homes, one has to consider all the variables to ensure that all the principles data security and protection are observed. This will lead to data minimization and also provide users with the ability to survive in an automated and open environment. Another issue that has become evident with the use of IoT is profiling and unlawful processing. There is increased collection of data a factor that may lead to problems of authenticity and trust. The information collected also leads to people being easily identified and also better known.

With the increased use of IoT, there is also a significant increase in data collection. But most often, data collected for one purpose ends up being used for another purpose, and the existing challenge, in this case, is that the information can be used for purposes it was not intended for. For example, the data collected by smart homes or other objects ion the IoT network can be used by government authorities to spy on their subjects. This is a direct violation of people’s rights, and this may affect the broader social and public acceptance (Lin et al., 2017). Therefore, the policy should give the users, and the IoT objects the ability to exercise their data protection rights. This will include permissions and data controllership. This also includes the establishment of optimum frequency of data collection to avoid accumulation of data that is not significant for the current purpose.

There has been an increase in the cases of violation of individual data protection in virtually all aspects of life. For instance, the banking industry is the most common where attackers are able to use the IoT environments to collect information from users as they navigate through the system. The information collected through the IoT sensors and identifiers have the ability to reveal the identity and other information about an individual. This information is, most of the time very private information such as their habits, locations, interests among other information that is stored in the system for ease of access. When this information is combined with data collected from other environments or data mining, the attacker can build up knowledge regarding the individual thus increasing the concern about using IoT technology. This way, attackers can drain users' accounts or even shop using their credit card information. The policy proposal in this paper is meant to prevent something like identity theft and access to user information from happening. The last and most crucial part of the policy is the identification of malicious activity or attacks in the system (Granjal, Monteiro, & Silva, 2015). Most of the time the IoT system is compromised due to limited security protocols in place. The challenge is in the identification of these controls appropriate for IoT and how they evolve. This also needs to be defined for every object in the system and it is dependent on the system architecture.

From the context explained above, the main objective of the policy should be data protection using legal principles as well as effective data security, and this includes confidentiality, availability, and integrity. Secondly, the policy should be in line with global data protection policies relevant to IoT environments. There must be harmonization of data protection laws. There are two policy options that can help in achieving the objectives discussed above.

· IoT shall observe all the virtues of human rights for example not violating the human identity and also the privacy of ones’ public liberties.

· Individuals shall be in control of their information that is collected during the use of IoT objects except where the information conflicts with the first policy.

According to these two principles, there are different options that can be taken to achieve the objectives. The first option is data privacy and information security risk management. This entails that the companies responsible for the manufacture of the different objects that are connected to the IoT network are fitted with high-end technological safeguards to protect user information. This should be accompanied by an effective and efficient data protection mechanism to achieve widespread implementation of the policy (Sicari et al., 2015). The strategy will ensure that the information protection principles are incorporated at the design level of the IoT systems, and best practices such as identifiers, audit loggings, among others, are used to identify the risks. Other aspects of the policy that will enhance protection of user information include improved password structure. The best structure that will ensure security of user information will be at least 14 characters that are case sensitive with numbers and symbols. All factory set IDs shall be changed during initial configuration, and the password age should be set to 60 days. To insulate the security of user data, accounts will be disabled if a user exceeds three attempts to log in unto the system. Finally, maintaining a security record for every log will ease investigation of any security breach.

Conclusively, IoT has proofed to be the future of global communication. The world has seen significant advancements in technology, with everything becoming connected to the internet. But this increased connection to the internet has raised security issues and privacy violations. Attackers are using the data collected by the IoT systems to undertake crimes. But with relevant policies in place, the security of the information will be ensured and thus preventing unauthorized access to confidential information. Additionally, individuals will feel safe on the internet thus making their experience better than it is today. Harmonization of universal laws regarding the use of IoT will ensure that everybody is safe on the internet, and all the manufacturing companies follow the policies from the design stage to configuration stage.

References

Alaa, M., Zaidan, A. A., Zaidan, B. B., Talal, M., & Kiah, M. L. M. (2017). A review of smart home applications based on Internet of Things. Journal of Network and Computer Applications97, 48-65.

Andrea, I., Chrysostomou, C., & Hadjichristofi, G. (2015, July). Internet of Things: Security vulnerabilities and challenges. In 2015 IEEE Symposium on Computers and Communication (ISCC) (pp. 180-187). IEEE.

Bertino, E., & Islam, N. (2017). Botnets and internet of things security. Computer, (2), 76-79.

Feng, S., Setoodeh, P., & Haykin, S. (2017). Smart home: Cognitive interactive people-centric Internet of Things. IEEE Communications Magazine55(2), 34-39.

Granjal, J., Monteiro, E., & Silva, J. S. (2015). Security for the internet of things: a survey of existing protocols and open research issues. IEEE Communications Surveys & Tutorials17(3), 1294-1312.

Lin, J., Yu, W., Zhang, N., Yang, X., Zhang, H., & Zhao, W. (2017). A survey on internet of things: Architecture, enabling technologies, security and privacy, and applications. IEEE Internet of Things Journal4(5), 1125-1142.

Malche, T., & Maheshwary, P. (2017, February). Internet of Things (IoT) for building smart home system. In 2017 International Conference on I-SMAC (IoT in Social, Mobile, Analytics and Cloud)(I-SMAC) (pp. 65-70). IEEE.

Roshan, R., & Ray, A. K. (2016). Challenges and risk to implement IoT in smart homes: an Indian perspective. Int J Comput Appl153, 16-19.

Sicari, S., Rizzardi, A., Grieco, L. A., & Coen-Porisini, A. (2015). Security, privacy and trust in Internet of Things: The road ahead. Computer networks76, 146-164.

Stojkoska, B. L. R., & Trivodaliev, K. V. (2017). A review of Internet of Things for smart home: Challenges and solutions. Journal of Cleaner Production140, 1454-1464.