Device Class 5 Areas
Detailed controls for Class 5 ITSRE, CVRSE and Vehicle OBE
Device Class 5:
- Confidentiality: HIGH
- Integrity: HIGH
- Availability: HIGH
Devices of this class must meet controls from NIST 800-53 and ISO/IEC 15408 in the following areas:
- Access Control
- Audit and Accountability
- Configuration Management
- Contingency Planning
- Identification and Authentication
- Incident Response
- Media Protection
- Personal Privacy
- Risk Assessment
- System and Services Acquisition
- System and Communications Protection
- System and Information Integrity
In addition, organizations that develop, operate or maintain devices of this class must meet controls from NIST 800-53 and ISO/IEC 15408 the areas above and the following additional areas:
- Awareness and Training
- [Security] Assessment and Authorization
- Maintenance
- Physical and Environmental Protection
- Planning
- Personnel Security
For example, a Fleet and Freight Management Center providing hazmat information to the Emergency Management Center.