Overview
ISO/IEC 30147:2021 - "Information technology - Internet of things - Methodology for trustworthiness of IoT system/service" - provides system life‑cycle processes to implement and maintain IoT trustworthiness by applying and supplementing ISO/IEC/IEEE 15288:2015. It targets IoT systems and services across a wide range of application areas and addresses the unique characteristics of IoT (long operational lifetimes, constrained devices, unexpected interconnections, broad impact of threats).
Key topics and technical focus
ISO/IEC 30147 integrates trustworthiness activities into established systems‑engineering processes. Key technical topics and process areas include:
- System life‑cycle processes aligned with ISO/IEC/IEEE 15288 (agreement, organizational, technical management, and technical processes).
- Risk management for IoT‑specific risks (security, safety, privacy, reliability, resilience) and interactions between trustworthiness factors (see Annex A: risk examples).
- Acquisition and supply processes to embed trustworthiness into procurement and supplier contracts.
- Architecture, design and implementation guidance to consider constraints of IoT devices and unexpected interconnections.
- Verification, validation, operation, maintenance and disposal activities tailored to long lifetimes and hard‑to‑manage devices.
- Project enabling processes such as quality management, configuration, information and knowledge management.
- Technical management processes including project planning, assessment, decision and measurement to oversee trustworthiness objectives.
- Privacy and continuity considerations referenced through related ISO/IEC guidance (privacy impact assessments, business continuity readiness).
Practical applications and who should use it
ISO/IEC 30147 is practical for organizations that design, procure, integrate, operate or regulate IoT systems and services, including:
- Systems engineers and IoT architects who must integrate trustworthiness into system engineering workflows.
- Program and project managers who need lifecycle‑level requirements for security, safety, privacy and resilience.
- Security, safety and privacy engineers conducting risk assessments, verification/validation and mitigation planning.
- Procurement teams and suppliers who need to specify trustworthiness requirements in contracts.
- Operators and maintainers planning long‑term maintenance, incident readiness and secure disposal.
Use cases include embedding trustworthiness in IoT product development, supplier selection and contract clauses, lifecycle risk assessments, verification/validation plans, and operational readiness for IoT deployments.
Related standards (normative references)
ISO/IEC 30147:2021 is SEO‑relevant for queries like "IoT trustworthiness standard", "ISO/IEC 30147", "IoT lifecycle security", "integrating trustworthiness into 15288", and "IoT risk management guidance".