Holistic Risk Analysis for IoT
摘要
After having examined the manifold IoT ‘security & privacy’ risks, this chapter focuses on how to assess them. Risk assessment is one of the core elements around which the EU cybersecurity, privacy & data protection legal frameworks are clustered. The first part of the chapter outlines the different rationales of traditional information security risk management models (e.g., ISO framework) and the rights-based model of the GDPR’s data protection impact assessment (DPIA) with a view to identifying misalignments and potential synergies between the two frameworks. Then, the data protection impact assessment (DPIA) model developed by the French Data Protection Authority (CNIL) for IoT devices is critically analysed to investigate whether and to what extent it comprehensively assesses the risks to individuals’ rights and freedoms in the specific context of IoT data processing. The final part presents an ‘holistic’ data protection impact assessment methodology for IoT devices.