SESIP: An optimized security evaluation methodology, designed for IoT devices

GlobalPlatform is here to support IoT device makers and certification bodies to adopt the Security Evaluation Standard for IoT Platforms (SESIP) methodology and establish their own IoT device security certification schemes.

SESIP provides a common and optimized approach for evaluating the security of connected products that meets the specific compliance, security, privacy and scalability challenges of the evolving IoT ecosystem.

In parallel, GlobalPlatform will align certification bodies and laboratories, to ensure comparable evaluations across the entire IoT ecosystem. GlobalPlatform welcomes engagement from certification bodies and laboratories.

Why SESIP? The Complexity of Connectivity

75.44 bn IoT devices to be deployed by 2025

Nearly 500 different IoT product requirements frameworks

Only 4% of deployed IoT products have security

The growing number of IoT products and the complexity of these connected things introduces new challenges to the traditional security evaluation process. IoT products are made up of multiple components, which are developed by multiple players, many of which are new to security. A myriad of different regulations and certification frameworks create an added layer of complexity for the IoT vendors, developers and service providers tasked with demonstrating the security capability of their products.

A flexible and efficient security evaluation methodology is needed to address the unique complexities and challenges of the evolving IoT ecosystem and drive consistency across IoT certification schemes to bring greater trust.

Interested in learning more?

Methodology: Security Evaluation Standard for IoT Platforms

GlobalPlatform’s SESIP methodology standardizes security certification and gives device makers and solution vendors the ability to demonstrate alignment with market requirements and use cases.

Download here

Video: How does SESIP provide a standardized methodology for IoT security implementation?

Watch this video to understand how SESIP is providing the IoT ecosystem with a scalable, standardized methodology to meet specific compliance, security, privacy and challenges.

Watch here

Video: Using SESIP to Simplify Security Evaluation and Build Trusted IoT Products

This video explores IoT use cases and explains how the embedded developer community can use the SESIP methodology to simplify security evaluation.

Watch here

Frequently Asked Questions about SESIP

This documents answers common questions about the SESIP methodology. It also explains how device makers can leverage SESIP to evaluate and certify products to meet specific compliance, security, privacy and scalability challenges.

Download here

From Complexity to Consistency: What is SESIP?

IoT products are far more complex than the products traditional security evaluation approaches address. SESIP recognizes this with a common security evaluation methodology that is designed specifically for the IoT platforms and platform parts on which these products are based. It addresses the need for a standardized approach that supports a broad range of regulatory and security frameworks, while at the same time providing a methodology that’s adaptable to the IoT environment and accessible to IoT developers who aren’t security experts.

SESIP:

  • Delivers a flexible and efficient security evaluation methodology dedicated to addressing the complexity of the IoT ecosystem.
  • Drives consistency by providing a common and recognized methodology that can be adopted across certification schemes.
  • Reduces complexity, cost and time-to-market for IoT stakeholders by offering a methodology that’s mappable to other evaluation methodologies, and compliant with standards and regulations.
  • Facilitates device certification, by composition of certified parts, and reuse of certification across different evaluations.
  • Establishes a consistent and flexible way for IoT developers to demonstrate the security capability of their IoT products and service providers to select a product that matches their security needs.
How can I adopt and implement SESIP?

GlobalPlatform has 20 years’ experience in establishing and managing security certification schemes. The organization is now supporting the IoT device security certification ecosystem with the adoption of the SESIP methodology. The objective is to build consistency across IoT certification schemes (regional or vertical) to facilitate product evaluation and certificate recognition.

  • Device makers – can work with GlobalPlatform to enhance the security of their devices, which are built on a SESIP-certified platform part, to ensure readiness to achieve certification in line with any schemes using SESIP.
  • Laboratories – can work with GlobalPlatform to improve the SESIP methodology and associated supporting documents to provide an efficient and swift solution for IoT device certification.
  • Certification Bodies – can work with GlobalPlatform, integrate the SESIP methodology alongside their existing certification schemes and work with other certification bodies to ensure consistency of evaluations. This will bring greater trust to the IoT devices deployed within their country or region
  • Solution vendors – benefit from the establishment of consistent SESIP security certification and the ability to demonstrate alignment with market requirements, use cases and regulations in an optimized way.
  • IoT ecosystem – to answer security regulations, the IoT sector can use the SESIP methodology to efficiently define their security requirements and use SESIP laboratories and a SESIP certification body to establish their own schemes.

Participation Forms

The legal and technical forms applicable to each type of certification are provided below.

GlobalPlatform
Hey There!

It seems you are using an outdated browser, unfortunately this means that our website will not render properly for you. Update your browser to view this website correctly.

GOOGLE CHROME
FIREFOX
MICROSOFT EDGE