Bridging the Gap: Automated Transformation of IoT Data Streams for ISO 27001-Compliant Logging in Ambient Assisted Living Environments
Kunal Gawande, Vladimir StantchevA control that cannot be audited is a control that does not yet exist operationally. Commercial off-the-shelf (COTS) Internet of Things (IoT) devices in Ambient Assisted Living (AAL) environments expose this problem sharply: they export raw behavioural telemetry rather than the security-auditable event records required by the logging and monitoring controls of ISO/IEC 27001:2022. This study formalises that deficit as the Admissibility Gap, a weighted, field-level measure of the mismatch between native device output and the evidentiary requirements of Annex A. An audit of four publicly available AAL datasets (CASAS, SPHERE, UCI HAR, OPPORTUNITY) confirms that identity attribution, integrity, firmware version, and privacy-minimisation governance fields are universally absent, establishing that the gap is systemic. To close it, this study proposes the Compliance Transformation Layer, an edge middleware applying three rules: LDAP-based identity attribution, keyed HMAC-SHA256 integrity sealing with firmware baseline injection, and privacy-preserving GPS truncation. An experimental campaign on 10,000 synthetic records reduced the weighted Admissibility Gap deficit from 57.0% to 4.7% (an illustrative figure under the authors’ weight vector; because the transformation rules apply deterministically, this is a demonstration of sufficiency rather than an independent validation, and its direction is robust to the weighting), with outputs mapped to the Microsoft Sentinel Common Event Format schema and the BSI IT-Grundschutz OPS.1.1.5 logging requirements. Benchmarking on Raspberry Pi 4 hardware yielded a mean per-record latency of 1.574 ms at idle, demonstrating that audit-ready logging is achievable from the edge gateway inward on commodity hardware without hardware or firmware modification. The integrity and identity guarantees are enforced from the point of gateway ingestion; the device-to-gateway segment is treated as a declared trust boundary.