D-Link to implement comprehensive software security program to settle FTC complaint

0
816

As part of the agreement, the company will take specific steps to make sure that its Internet-connected cameras and routers are secure. It will implement the following:

  1. security planning
  2. threat modeling,
  3. sting for vulnerabilities before releasing products
  4. ongoing monitoring to address security flaws
  5. automatic firmware updates
  6. accepting vulnerability reports from security researchers

Additionally, D-Link agreed obtain biennial, independent, third-party assessments of its software security program for ten years.

Furthermore, under the settlement agreement,  FTC has the authority to approve the third-party assessor selected by D-Link.

On the company has the option to have the assessor certify its compliance with the secure product development standard set by the International Electrotechnical Commission, an international standard setting organization.