Device Class 1 Areas
Detailed controls for Class 1 ITSRE, CVRSE and Vehicle OBE
Device Class 1:
- Confidentiality: LOW
- Integrity: MODERATE
- Availability: MODERATE
Devices of this class must meet controls from NIST 800-53 and ISO/IEC 15408 in the following areas:
- Access Control
- Audit and Accountability
- Configuration Management
- Contingency Planning
- Identification and Authentication
- Incident Response
- Media Protection
- Personal Privacy
- Risk Assessment
- System and Services Acquisition
- System and Communications Protection
- System and Information Integrity
In addition, organizations that develop, operate or maintain devices of this class must meet controls from NIST 800-53 and ISO/IEC 15408 the areas above and the following additional areas:
- Awareness and Training
- [Security] Assessment and Authorization
- Maintenance
- Physical and Environmental Protection
- Planning
- Personnel Security
For example, an aftermarket safety device (Vehicle OBE) providing vehicle location and motion.