Device Class 3 Areas
Detailed controls for Class 3 ITSRE, CVRSE and Vehicle OBE
Device Class 3:
- Confidentiality: MODERATE
- Integrity: HIGH
- Availability: MODERATE
Devices of this class must meet controls from NIST 800-53 and ISO/IEC 15408 in the following areas:
- Access Control
- Audit and Accountability
- Configuration Management
- Contingency Planning
- Identification and Authentication
- Incident Response
- Media Protection
- Personal Privacy
- Risk Assessment
- System and Services Acquisition
- System and Communications Protection
- System and Information Integrity
In addition, organizations that develop, operate or maintain devices of this class must meet controls from NIST 800-53 and ISO/IEC 15408 the areas above and the following additional areas:
- Awareness and Training
- [Security] Assessment and Authorization
- Maintenance
- Physical and Environmental Protection
- Planning
- Personnel Security
Compared to Class 2 devices, devices of this class will have additional requirements in the areas of:
- Access Control
- Identification and Authentication
- Media Protection
- System and Services Acquisition
- System and Communications Protection
- System and Information Integrity
For example, ITS Roadway Equipment providing Transit Signal Priority or Emergency Vehicle Preemption.