What does ETSI EN 303 645 say about telemetry?
EN 303 645 defines telemetry as data from a device that can help the manufacturer identify issues or information related to device usage. Provision 5.10-1 is conditional: if telemetry data is collected from consumer IoT devices and services, such as usage and measurement data, it should be examined for security anomalies.
The standard gives practical examples of the kind of security signal it expects teams to look for: deviations from normal device behaviour, such as an abnormal increase in failed login attempts, or telemetry across multiple devices showing that updates are failing because software update authenticity checks are invalid.
- Start by listing the telemetry actually collected by the device and associated services, not by writing a generic monitoring statement.
- For each telemetry category, document whether it is used for security anomaly examination or only for another purpose such as performance or stability analysis.
- Keep the claim conditional: EN 303 645 does not require every product to collect telemetry, but collected telemetry should be examined for security anomalies.
Primary ETSI source for provision 5.10-1 on examining collected telemetry for security anomalies.
Assessment source for checking that at least one security examination is provided in IXIT 24-TelData and that the telemetry description fits the examination.