In order to participate in this service package, each physical object should meet or exceed the following security levels.
In order to participate in this service package, each information flow triple should meet or exceed the following security levels.
Information Flow Security |
Source |
Destination |
Information Flow |
Confidentiality |
Integrity |
Availability |
Basis |
Basis |
Basis |
Alternate Mode Transportation Center |
Transportation Information Center |
alternate mode information |
Low |
Moderate |
Low |
Generally, center-originating flows destined for a TIC don't contain any personal or confidential information, and are eventually intended for some kind of public consumption. |
Generally transportation coordination information should be correct between source and destination, or inappropriate actions may be taken. |
While useful, there is little impact if this flow is not available. |
Maint and Constr Management Center |
Transportation Information Center |
maint and constr work plans |
Low |
High |
High |
This data is eventually intended for public dissemination, and is also shared with many centers. |
If incorrect or unavailable this could result in a vehicle being somewhere it should not be due to work zone impacts, which could have an impact on the infrastruture and the vehicle, including potential incidents (consider a large vehicle with narrow or height-restricted roadway). |
If incorrect or unavailable this could result in a vehicle being somewhere it should not be due to work zone impacts, which could have an impact on the infrastruture and the vehicle, including potential incidents (consider a large vehicle with narrow or height-restricted roadway). |
Maint and Constr Management Center |
Transportation Information Center |
roadway maintenance status |
Low |
Moderate |
Moderate |
Roadway maintenance status data is distributed to a host of places including travelers, so there is no justification for obfuscation. |
Road maintenance data is generally distributed to travelers through a TIC, so this needs to be accurate and available so that travelers can make appropriate decisions. Inappropriate decisions may significantly affect traffic and individual travel experiences. |
Road maintenance data is generally distributed to travelers through a TIC, so this needs to be accurate and available so that travelers can make appropriate decisions. Inappropriate decisions may significantly affect traffic and individual travel experiences. |
Maint and Constr Management Center |
Transportation Information Center |
work zone information |
Low |
Moderate |
Moderate |
Eventually intended for public distribution, so no need to obfuscate. |
Information needs to be timely and correct so that appropriate actions are taken on the part of the receiver. Trip plans, corresponding maintenance actions, transit and emergency vehicle routes, etc.; DISC: WYO believes this to be HIGH. |
Information needs to be timely and correct so that appropriate actions are taken on the part of the receiver. Trip plans, corresponding maintenance actions, transit and emergency vehicle routes, etc. |
Other Transportation Information Centers |
Transportation Information Center |
alternate mode information |
Low |
Moderate |
Low |
Generally, center-originating flows destined for a TIC don't contain any personal or confidential information, and are eventually intended for some kind of public consumption. |
Generally transportation coordination information should be correct between source and destination, or inappropriate actions may be taken. |
While useful, there is little impact if this flow is not available. |
Other Transportation Information Centers |
Transportation Information Center |
incident information for public |
Low |
Moderate |
Moderate |
Generally, center-originating flows destined for a TIC don't contain any personal or confidential information, and are eventually intended for some kind of public consumption. |
Publicly shared data about planned incidents should be accurate and delivered in timely fashion so as to enable end users to react appropriately; otherwise, signficant mobility challenges may result. |
Publicly shared data about planned incidents should be accurate and delivered in timely fashion so as to enable end users to react appropriately; otherwise, signficant mobility challenges may result. |
Other Transportation Information Centers |
Transportation Information Center |
parking information |
Moderate |
Moderate |
Moderate |
Does not include PII, but does include usage information for a managed facility that implies a number of vehicles. While this is observable information, it could be considered competitive, and regardless is accessible without being physically present, which is its own barrier. |
Generally transportation coordination information should be correct between source and destination, or inappropriate actions may be taken. |
Most likely not a frequently updated flow. Typically MODERATE for applications with a high degree of commercial vehicle parking, but could be LOW otherwise. |
Other Transportation Information Centers |
Transportation Information Center |
road network conditions |
Low |
Moderate |
Moderate |
No harm should come from seeing this data, as it is eventually intended for public consumption. |
While accuracy of this data is important for decision making purposes, applications should be able to corroborate the data in many instances. Thus MODERATE generally. |
Depends on the application; if mobility decisions that affect large numbers of travelers are made based on this data, then it is MODERATE. In more modest circumstances, it may be LOW. |
Other Transportation Information Centers |
Transportation Information Center |
transit service information |
Low |
Moderate |
Low |
Generally, center-originating flows destined for a TIC don't contain any personal or confidential information, and are eventually intended for some kind of public consumption. |
Generally transportation coordination information should be correct between source and destination, or inappropriate actions may be taken. |
While useful, there is no signficant impact if this flow is not available. |
Pathway Communications Unit |
Personal Information Device |
communications signature |
Not Applicable |
Moderate |
Low |
Byproduct flow, does contain PII (Bluetooth MAC addresses for example) but already existant and not required. |
While the flow here is a byproduct of existing transmissions, if the data contained within is not reliable then the application using this data will generate erroneous results. Integrity is set MODERATE to emphasize to the application developer that they should verify the flows' integrity, or develop methods to minimize integrity's importance, in which case this could be LOW. |
This is a by-product flow; taking advantage of existing wireless emissions to measure travel times for example. If this flow is not present then the application might not function, however, the application is not deploying this flow, it already exists. |
Pathway Communications Unit |
Transportation Information Center |
communications signature |
Not Applicable |
Moderate |
Low |
Byproduct flow, does contain PII (Bluetooth MAC addresses for example) but already existant and not required. |
While the flow here is a byproduct of existing transmissions, if the data contained within is not reliable then the application using this data will generate erroneous results. Integrity is set MODERATE to emphasize to the application developer that they should verify the flows' integrity, or develop methods to minimize integrity's importance, in which case this could be LOW. |
This is a by-product flow; taking advantage of existing wireless emissions to measure travel times for example. If this flow is not present then the application might not function, however, the application is not deploying this flow, it already exists. |
Pathway Equipment |
Personal Information Device |
pathway equipment state |
Low |
Moderate |
Moderate |
Probably no obfuscation is needed as most of the information in this flow should be otherwise observable. |
Information should be correct and available or wayfinding will not function well. A re-levelling of integrity measures may consider this LOW, depending on the importance of wayfinding. |
Information should be correct and available or wayfinding will not function well. Might be LOW depending on the importance attached to VRU wayfinding. |
Pathway Equipment |
Personal Information Device |
pathway equipment status |
Not Applicable |
Moderate |
Moderate |
This information should be observable. |
Information should be correct and available or wayfinding will not function well. A re-levelling of integrity measures may consider this LOW, depending on the importance of wayfinding. |
Information should be correct and available or wayfinding will not function well. Might be LOW depending on the importance attached to VRU wayfinding. |
Pathway Equipment |
Personal Information Device |
pathway signage information |
Low |
Moderate |
Moderate |
Probably no obfuscation is needed as most of the information in this flow should be otherwise observable. |
Information should be correct and available or wayfinding will not function well. A re-levelling of integrity measures may consider this LOW, depending on the importance of wayfinding. |
Information should be correct and available or wayfinding will not function well. A re-levelling of integrity measures may consider this LOW, depending on the importance of wayfinding. |
Pathway Equipment |
Personal Safety Device |
pathway equipment state |
Low |
Moderate |
Moderate |
Probably no obfuscation is needed as most of the information in this flow should be otherwise observable. |
Information should be correct and available or wayfinding will not function well. A re-levelling of integrity measures may consider this LOW, depending on the importance of wayfinding. |
Information should be correct and available or wayfinding will not function well. Might be LOW depending on the importance attached to VRU wayfinding. |
Pathway Equipment |
Transportation Information Center |
pathway equipment state |
Low |
Moderate |
Moderate |
Probably no obfuscation is needed as most of the information in this flow should be otherwise observable. |
Information should be correct and available or wayfinding will not function well. A re-levelling of integrity measures may consider this LOW, depending on the importance of wayfinding. |
Information should be correct and available or wayfinding will not function well. Might be LOW depending on the importance attached to VRU wayfinding. |
Pathway Equipment |
Transportation Information Center |
pathway equipment status |
Not Applicable |
Moderate |
Moderate |
This information should be observable. |
Information should be correct and available or wayfinding will not function well. A re-levelling of integrity measures may consider this LOW, depending on the importance of wayfinding. |
Information should be correct and available or wayfinding will not function well. Might be LOW depending on the importance attached to VRU wayfinding. |
Pathway Equipment |
Traveler |
traveler pathway updates |
Low |
Moderate |
Moderate |
Probably no obfuscation is needed as most of the information in this flow should be otherwise observable. |
Information should be correct and available or wayfinding will not function well. A re-levelling of integrity measures may consider this LOW, depending on the importance of wayfinding. |
Information should be correct and available or wayfinding will not function well. A re-levelling of integrity measures may consider this LOW, depending on the importance of wayfinding. |
Personal Information Device |
Pathway Communications Unit |
communications signature |
Not Applicable |
Moderate |
Low |
Byproduct flow, does contain PII (Bluetooth MAC addresses for example) but already existant and not required. |
While the flow here is a byproduct of existing transmissions, if the data contained within is not reliable then the application using this data will generate erroneous results. Integrity is set MODERATE to emphasize to the application developer that they should verify the flows' integrity, or develop methods to minimize integrity's importance, in which case this could be LOW. |
This is a by-product flow; taking advantage of existing wireless emissions to measure travel times for example. If this flow is not present then the application might not function, however, the application is not deploying this flow, it already exists. |
Personal Information Device |
Personal Safety Device |
safety device control |
Low |
Moderate |
Moderate |
Unlikely to have any PII and so little harm could come from observation; if any PII were included, should be MODERATE. |
This flow will directly impact a vulnerable road user's trip, and should be correct and timely to protect them and their journey. |
This flow will directly impact a vulnerable road user's trip, and should be correct and timely to protect them and their journey. |
Personal Information Device |
Transportation Information Center |
user profile |
Moderate |
Moderate |
Low |
Personal preferences and similar information will be associated with a user id of some kind, which should be protected to avoid identity and related thefts. |
User configuration information needs to be correct the user is subject to third party manipulation or poor quality of service. |
Probably many opportunities to exchange this data, and will not need to be done often. |
Personal Information Device |
Transportation Information Center |
wayfinding feedback |
Moderate |
Moderate |
Moderate |
Likely to include some PII and could compromise privacy if observed. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Personal Information Device |
Transportation Information Center |
wayfinding request |
Moderate |
Moderate |
Moderate |
Likely to include some PII and could compromise privacy if observed. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Personal Information Device |
Traveler |
traveler interface updates |
Not Applicable |
Moderate |
Moderate |
Personalized data that includes directions and guidance for an individual, but eventually evident anyway. |
Should be accurate as the Traveler will be relying on this information for routing and related choices. Lack of accuracy will result in lack of confidence from the traveler as well as an unsatisfactory trip, leading to a negative feedback spiral. |
Users expect their devices to work. If information is not presented to the operator, the relevant applications simply won't be used. |
Personal Safety Device |
Personal Information Device |
safety device inputs |
Low |
Moderate |
Moderate |
Unlikely to have any PII and so little harm could come from observation; if any PII were included, should be MODERATE. |
This flow will directly impact a vulnerable road user's trip, and should be correct and timely to protect them and their journey. |
This flow will directly impact a vulnerable road user's trip, and should be correct and timely to protect them and their journey. |
TIC Operator |
Transportation Information Center |
TIC operator input |
Moderate |
High |
High |
Backoffice operations flows should have minimal protection from casual viewing, as otherwise imposters could gain illicit control or information that should not be generally available. |
Backoffice operations flows should generally be correct and available as these are the primary interface between operators and system. |
Backoffice operations flows should generally be correct and available as these are the primary interface between operators and system. |
Transit Management Center |
Transportation Information Center |
transit and fare schedules |
Low |
Moderate |
Moderate |
Generally, center-originating flows destined for a TIC don't contain any personal or confidential information, and are eventually intended for some kind of public consumption. |
While accuracy of this data is important for decision making purposes, the greatest impact if manipulated or incorrect data would be financial and likely limited in scope. For example, making all options appear less expensive than an attacker's route of fiduciary interest, driving revenue to his route. This is undesireable and significant, but not catastrophic. Thus MODERATE generally. |
While accuracy of this data is important for decision making purposes, applications should be able to function without frequent updates. Thus MODERATE generally, though it could be LOW depending on the level of projected updates. |
Transit Management Center |
Transportation Information Center |
transit schedule adherence information |
Low |
Moderate |
Moderate |
Eventually intended for public consumption, so no need to obfuscate. |
While accuracy of this data is important for decision making purposes, applications should be able to function without it. Thus MODERATE generally. |
While accuracy of this data is important for decision making purposes, applications should be able to cfunction without it. Thus MODERATE generally. |
Transportation Information Center |
Other Transportation Information Centers |
alternate mode information |
Low |
Moderate |
Low |
Generally, center-originating flows destined for a TIC don't contain any personal or confidential information, and are eventually intended for some kind of public consumption. |
Generally transportation coordination information should be correct between source and destination, or inappropriate actions may be taken. |
While useful, there is little impact if this flow is not available. |
Transportation Information Center |
Other Transportation Information Centers |
incident information for public |
Low |
Moderate |
Moderate |
Generally, center-originating flows destined for a TIC don't contain any personal or confidential information, and are eventually intended for some kind of public consumption. |
Publicly shared data about planned incidents should be accurate and delivered in timely fashion so as to enable end users to react appropriately; otherwise, signficant mobility challenges may result. |
Publicly shared data about planned incidents should be accurate and delivered in timely fashion so as to enable end users to react appropriately; otherwise, signficant mobility challenges may result. |
Transportation Information Center |
Other Transportation Information Centers |
parking information |
Moderate |
Moderate |
Moderate |
Does not include PII, but does include usage information for a managed facility that implies a number of vehicles. While this is observable information, it could be considered competitive, and regardless is accessible without being physically present, which is its own barrier. |
Generally transportation coordination information should be correct between source and destination, or inappropriate actions may be taken. |
While useful, there is no signficant impact if this flow is not available. |
Transportation Information Center |
Other Transportation Information Centers |
road network conditions |
Low |
Moderate |
Moderate |
No harm should come from seeing this data, as it is eventually intended for public consumption. |
While accuracy of this data is important for decision making purposes, applications should be able to corroborate the data in many instances. Thus MODERATE generally. |
condition info should be timely and readily available so that TMCs are aware of current traffic info, conditions, restrictions, etc. but should not have severe/catastrophic consequences if not |
Transportation Information Center |
Other Transportation Information Centers |
transit service information |
Low |
Moderate |
Low |
Generally, center-originating flows destined for a TIC don't contain any personal or confidential information, and are eventually intended for some kind of public consumption. |
Generally transportation coordination information should be correct between source and destination, or inappropriate actions may be taken. |
While useful, there is no signficant impact if this flow is not available. |
Transportation Information Center |
Pathway Equipment |
pathway equipment application info |
Moderate |
Moderate |
Moderate |
Field equipment control so should be protected from observation and potential abuse. |
Information must be correct and timely so as to ensure control of field infrastructure. |
Information must be correct and timely so as to ensure control of field infrastructure. |
Transportation Information Center |
Personal Information Device |
wayfinding information |
Moderate |
Moderate |
Moderate |
Likely to include some PII and could compromise privacy if observed. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Transportation Information Center |
Personal Information Device |
wayfinding plan |
Moderate |
Moderate |
Moderate |
Likely to include some PII and could compromise privacy if observed. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Transportation Information Center |
TIC Operator |
TIC operations information presentation |
Moderate |
High |
High |
Backoffice operations flows should have minimal protection from casual viewing, as otherwise imposters could gain illicit control or information that should not be generally available. |
Backoffice operations flows should generally be correct and available as these are the primary interface between operators and system. |
Backoffice operations flows should generally be correct and available as these are the primary interface between operators and system. |
Transportation Information Center |
Traveler Support Equipment |
wayfinding information |
Moderate |
Moderate |
Moderate |
Likely to include some PII and could compromise privacy if observed. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Transportation Information Center |
Traveler Support Equipment |
wayfinding plan |
Moderate |
Moderate |
Moderate |
Likely to include some PII and could compromise privacy if observed. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Traveler |
Personal Information Device |
traveler input |
Not Applicable |
Moderate |
Low |
This data is informing the vehicle of operational information that is relevant to the operation of the vehicle. It should not contain anything sensitive, and does not matter if another person can observe it. |
While public, information must be correct or travelers may make incorrect decisions with regard to their travel plans. |
Information is available through other means, though depending on the location this might not always be the case, in which case this would be MODERATE. |
Traveler |
Traveler Support Equipment |
traveler input |
Not Applicable |
Moderate |
Low |
Publicly available information, while not directly observable, is intended for widespread distribution |
While public, information must be correct or travelers may make incorrect decisions with regard to their travel plans. |
Information is available through other means, though depending on the location this might not always be the case, in which case this would be MODERATE. |
Traveler Support Equipment |
Transportation Information Center |
wayfinding request |
Moderate |
Moderate |
Moderate |
Likely to include some PII and could compromise privacy if observed. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Impact feels minimal if incorrect or not timely, likely affecting a very small number of travelers, though in high crime areas could put them in jeopardy. Additionally however, travelers in unfamiliar areas would depend on the contents for safe and efficient personal navigation. |
Traveler Support Equipment |
Traveler |
traveler interface updates |
Not Applicable |
Moderate |
Moderate |
Publicly available information, while not directly observable, is intended for widespread distribution |
Should be accurate as the Traveler will be relying on this information for routing and related choices. Lack of accuracy will result in lack of confidence from the traveler as well as an unsatisfactory trip, leading to a negative feedback spiral. |
Users expect their devices to work. If information is not presented to the operator, the relevant applications simply won't be used. |