Skip to main content
Guidance

Device security principles for manufacturers

Principles to guide manufacturers in the design of secure, enterprise-connected devices.

Page 4 of 12

3. Protect data at rest and in transit

Data stored on a device and transmitted to and from it is often sensitive in nature. This may include data relating to its users, the enterprise, functionality or other information necessary for the device to operate securely.

It's important that data on the device is appropriately protected so an attacker can’t read or modify it. Data transmitted to and from the device must also be appropriately protected, so it can’t be stolen or tampered with. Throughout this principle, data is considered sensitive if its compromise could directly or indirectly cause financial, reputational or personal harm to its owner or anyone associated with it. Any device that holds such information is therefore also considered sensitive. This also includes security-relevant data and isn’t limited to private keys, passwords and other credentials.








Published

Reviewed

Version

2.1