Core contents of the standard: First, full-level security architecture specification, a four-layer security architecture of "terminal layer - network layer - platform layer - application layer" for elevator IoT is constructed, clarifying the security protection requirements, technical indicators, and test methods of each layer, forming a full-link security protection system; Second, terminal security requirements, clarifying the identity authentication, access control, firmware security, intrusion detection, and security upgrade requirements of elevator IoT terminal devices. Terminal devices must adopt a unique hardware identity, and firmware must be encrypted and signed to prevent illegal tampering and malicious intrusion; Third, network and platform security specifications, standardizing the encryption requirements for elevator IoT data transmission, must adopt TLS1.3 and above encryption protocols. The platform must have firewall, intrusion prevention, virus protection, and vulnerability scanning functions, with platform availability ≥99.9%, and data backup and recovery time ≤4 hours; Fourth, data security requirements, clarifying the classification and hierarchical management requirements of elevator operation data, maintenance data, and personal information data. Personal information processing must comply with the requirements of the Personal Information Protection Law. The whole process of data storage, transmission, use, and destruction is traceable, and illegal collection, leakage, and tampering of elevator operation data are prohibited; Fifth, security test and operation and maintenance specifications, unifying the security test methods, acceptance standards, and regular security assessment requirements of the elevator IoT system. A comprehensive network security test and risk assessment must be carried out every year, and the emergency disposal process and requirements for security incidents are clarified.