Generative AI Image: IoT Use Surges, Security Certification Urged

The number of IoT-enabled devices such as robot vacuum cleaners and IP cameras is growing rapidly, but it has been revealed that South Korea lacks even the minimum mandatory security standards.

Despite the 2020 legislation imposing information protection obligations on manufacturers and importers, the government has failed to establish clear criteria for six years. Procedures such as improvement orders or post-management are also not stipulated, making it impossible for the government to conduct independent inspections.

Photo Image
AI-Generated Image

According to data submitted by the Ministry of Science and ICT to the National Assembly Legislative Research Service in May, the number of IoT security certifications over the past five years averaged only 90 cases annually. Among approximately 450 IoT certifications conducted through voluntary certification, only 10 cases were in the home appliance sector over five years. The telecommunications sector also saw a mere seven certifications. This is largely due to the absence of sanctions or penalties for failing to obtain certification.

Recently, the home appliance market has seen a rapid increase in IoT devices alongside the expansion of smart home platforms. According to Samsung Electronics, the number of domestic SmartThings-registered devices exceeded 20 million as of the end of last year, a roughly 30% increase from the previous year. The trend shows that devices registered to specific platforms have grown by millions within a single year.

However, South Korea currently lacks even minimal security measures. In 2020, the National Assembly amended the Information and Communications Network Act to provide a legal basis for the government to recommend specific protective measures to IoT device manufacturers and importers. Yet, six years after the amendment, the government has yet to incorporate concrete standards into its guidelines. While leaving security certification to industry self-regulation without separate guidelines, the results have been underwhelming, with only 10 certifications over five years.

There is also no system in place to inspect products already in the market. Last year's security inspection of robotic vacuum cleaners was the first such check conducted. Even this was carried out through the Korea Consumer Agency because the government failed to establish a proper basis for direct inspections.

In contrast, overseas trends mandate minimum security requirements from the initial market entry of IoT products. The UK has required consumer IoT products to prohibit universal default passwords, disclose manufacturer contact information for reporting security vulnerabilities, and publicly state the duration of security updates since 2024. The European Union (EU) is also set to implement related regulations starting late next year.

The National Assembly Legislative Research Service argues that minimum security standards applicable to all IoT devices should be established first.

Kang Eun-soo, a legislative researcher at the Legislative Research Service, stated, “High-risk IoT devices with significant impacts on public safety should gradually have security certification mandated. Expanding this step-by-step based on risk levels and societal impact could be a practical solution to alleviate the burden on small and medium-sized manufacturers while improving actual security levels.”]

Photo Image
Major IoT Hacking Incidents and Security Vulnerability Cases - Source: Reprocessed by the National Assembly Research Service

· This article was translated using AI and was published after final review by the reporter.