In order to participate in this service package, each physical object should meet or exceed the following security levels.
In order to participate in this service package, each information flow triple should meet or exceed the following security levels.
| Information Flow Security |
| Source |
Destination |
Information Flow |
Confidentiality |
Integrity |
Availability |
| Basis |
Basis |
Basis |
| DMV |
Payment Administration Center |
registration |
Moderate |
Moderate |
Moderate |
| Will contain PII of driver and/or vehicle owner. Not HIGH because this affects a small number of individuals, and because safety of life is not likely a concern for this flow. |
Registration/ownership information needs to be correct, the lack of correctness may lead to false paths which have a nontrivial cost. |
Real-time decisions may be made based on this information. |
| Emissions Management Center |
Payment Administration Center |
low emissions zone coordination |
Moderate |
Moderate |
Low |
| While this information may eventually be public, it may contain details of emissions zone operations that could be used to abuse emissions zone systems. |
Emissions zone information should have its integrity protected to avoid misinformation or confusion that could result from incorrect data dissemination. |
Probably not a huge impact if this information cannot be updated frequently, thus LOW. If the priority of the low emission zone is high (to the jurisdiction in question) this could be MODERATE. |
| Emissions Management Center |
Payment Administration Center |
low emissions zone operations information |
Moderate |
Moderate |
Low |
| While this information may eventually be public, it may contain details of emissions zone operations that could be used to abuse emissions zone systems. |
Emissions zone information should have its integrity protected to avoid misinformation or confusion that could result from incorrect data dissemination. |
Probably not a huge impact if this information cannot be updated frequently, thus LOW. |
| Financial Center |
Payment Administration Center |
payment methods financial institution |
Moderate |
Moderate |
Low |
| Payment methods should be widely disseminated and contain no information that could cause harm if exposed. |
Payment methods need to be correct so payment information can be exchanged. Could be LOW, as this should have redundancies and be able to tolerate significant latency. |
Payment methods need to be correct so payment information can be exchanged. Could be LOW, as this should have redundancies and be able to tolerate significant latency. |
| Financial Center |
Payment Administration Center |
settlement |
Moderate |
Moderate |
Moderate |
| This may include PII and will include status information about a payment that could be used by a criminal for a variety of purposes, including identity theft, financial theft, or location-based activities, as the status is predictivie of what the account holder is doing and where they are doing it. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
| ITS Roadway Payment Equipment |
Light Vehicle OBE |
road use charges |
Moderate |
Moderate |
Moderate |
| Intended for the end user, so does not generally need to be concealed based on its content. However, could reasonably include localized information which if intercepted implies location of the end user, which is personal and should be protected. |
This material is used to support end user routing with an understanding of travel times and costs. Loss, corruption or forgery are likely to implact small numbers of users and have a moderate impact on revenues. |
This material is used to support end user routing with an understanding of travel times and costs. Loss, corruption or forgery are likely to implact small numbers of users and have a moderate impact on revenues. |
| ITS Roadway Payment Equipment |
Payment Administration Center |
authorization request |
Moderate |
Moderate |
Moderate |
| Contains an identifier linked to an individual or specific device, and thus PII by definition. Compromise of one secureID would likely impact only one user, but the nature of this flow requires that the same algorithm be used for every user; algorithm compromise would harm every user, which would have widespread impact. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
| ITS Roadway Payment Equipment |
Payment Administration Center |
payment transactions |
Moderate |
Moderate |
Moderate |
| Contains PII and intended to be used for enforcement. Thus privacy implications that, while they may affect only a single individual at a time, could yield significant negative consequences to that individual. |
Violation information needs to be correct or the commercial vehicle may be improperly penalized, or not when it should be. This is probably not a severe consequence however, so MODERATE. |
More or less important depending on the context. Could even be LOW if areas of minimal import, depending on local policies. |
| ITS Roadway Payment Equipment |
Payment Administration Center |
road use history |
High |
High |
Moderate |
| Contains vehicle identity, location and road use history. This is personal, tracking information that needs the highest levels of protection. |
Used as the basis for charging, any changes will have a direct impact on fees imposed and revenue collected. |
Inability to complete this flow will result in a failure of the road use charging system, which will require alternative mechanisms, or more likely delay payments. Payment delay is probably not a serious problem unless widespread and unable to be resolved. Could be LOW if alternative mechanisms for managing charges exist. |
| Light Vehicle Driver |
Light Vehicle OBE |
light vehicle driver input |
Moderate |
High |
High |
| Data included in this flow may include origin and destination information, which should be protected from other's viewing as it may compromise the driver's privacy. |
Commands from from the driver to the vehicle must be correct or the vehicle may behave in an unpredictable and possibly unsafe manner |
Commands must always be able to be given or the driver has no control. |
| Light Vehicle OBE |
ITS Roadway Payment Equipment |
actuate secure payment |
Moderate |
Moderate |
High |
| Contains an identifier linked to an individual or specific device, and thus PII by definition. Compromise of one secureID would likely impact only one user, but the nature of this flow requires that the same algorithm be used for every user; algorithm compromise would harm every user, which would have widespread impact. |
Payment related information needs to be correct or the user may be inconvenienced or defrauded. |
Contact/proximity payment mechanisms need to be very reliable or large numbers of users will be inconvenienced and the systems that use these interfaces (transit, parking etc.) will be hamstrung by interface failures. |
| Light Vehicle OBE |
ITS Roadway Payment Equipment |
road use history |
High |
High |
Moderate |
| Contains vehicle identity, location and road use history. This is personal, tracking information that needs the highest levels of protection. |
Used as the basis for charging, any changes will have a direct impact on fees imposed and revenue collected. |
Inability to complete this flow will result in a failure of the road use charging system, which will require alternative mechanisms, or more likely delay payments. Payment delay is probably not a serious problem unless widespread and unable to be resolved. Could be LOW if alternative mechanisms for managing charges exist. |
| Light Vehicle OBE |
Light Vehicle Driver |
light vehicle driver updates |
Not Applicable |
Moderate |
Moderate |
| This data is informing the driver about the safety of a nearby area. It should not contain anything sensitive, and does not matter if another person can observe it. |
This is the information that is presented to the driver. If they receive incorrect information, they may act in an unsafe manner. However, there are other indicators that would alert them to any hazards, such as an oncoming vehicle or crossing safety lights. |
If this information is not made available to the driver, then the system has not operated correctly. |
| Light Vehicle OBE |
Payment Administration Center |
actuate secure payment |
Moderate |
Moderate |
High |
| Contains an identifier linked to an individual or specific device, and thus PII by definition. Compromise of one secureID would likely impact only one user, but the nature of this flow requires that the same algorithm be used for every user; algorithm compromise would harm every user, which would have widespread impact. |
Payment related information needs to be correct or the user may be inconvenienced or defrauded. |
Contact/proximity payment mechanisms need to be very reliable or large numbers of users will be inconvenienced and the systems that use these interfaces (transit, parking etc.) will be hamstrung by interface failures. |
| Light Vehicle OBE |
Payment Administration Center |
road use history |
High |
High |
Moderate |
| Contains vehicle identity, location and road use history. This is personal, tracking information that needs the highest levels of protection. |
Used as the basis for charging, any changes will have a direct impact on fees imposed and revenue collected. |
Inability to complete this flow will result in a failure of the road use charging system, which will require alternative mechanisms, or more likely delay payments. Payment delay is probably not a serious problem unless widespread and unable to be resolved. Could be LOW if alternative mechanisms for managing charges exist. |
| Light Vehicle OBE |
Payment Administration Center |
user account setup |
High |
High |
Moderate |
| Contains user identification and transaction history, which if compromised could lead to identity or financial theft. |
Payment setup information, if corrupted, could lead the user to not properly pay for his trips or perhaps pay for others. If intercepted by a malicious actor, this could be manipulated to trick the user into taking action not in his own best interest. |
These exchanges can be delayed but eventually have to go through or accounts will not be properly updated, mostly impacting revenue collection. |
| Light Vehicle OBE |
Payment Administration Center |
vehicle payment information |
High |
High |
Moderate |
| Contains personal information, potentially including identity, payment information such as account numbers, location, and in some cases fraud detection data. All of this information is personal in nature and acceptable only for the intended destination to receive, as any 3rd party observation could lead to identity theft/compromise and/or payment method theft/compromise. |
This is information is used to process payment and/or detect fraud. Any losses, corruption or forgery has a direct impact on revenue collection, charges assessed and potentially legal action. |
This is information is used to process payment and/or detect fraud. Any losses, corruption or forgery has a direct impact on revenue collection, charges assessed and potentially legal action. Availability constrained to MODERATE the fact that alternative mechanisms and compromises exist to ameliorate not completing the flow. |
| Light Vehicle OBE |
Payment Device |
request for payment |
Moderate |
Moderate |
High |
| Contains charges and possibly balance or personal information. Charge information may or may not be public, and balance and personal information is not, though it may be displayed visually. Could be LOW if no personal or balance information and no identifier is not included in the flow. |
Payment related information needs to be correct or the user may be inconvenienced or defrauded. |
Contact/proximity payment mechanisms need to be very reliable or large numbers of users will be inconvenienced and the systems that use these interfaces (transit, parking etc.) will be hamstrung by interface failures. |
| Other Payment Administration Centers |
Payment Administration Center |
payment coordination |
Moderate |
High |
Moderate |
| Contains pricing and reconciliation information shared between agencies. If it includes road use charging information this is MODERATE, as road use charging data is vehicle and owner-specific and can be considered personal. A 3rd party observing this information might learn behavrioral patterns of the individual and use that information in the commission of a crime. If no road use charging information is included, this can be reduced to LOW. |
Backoffice operations flows should generally be correct and available as these are the primary interface between operators and system. |
A delay in reporting this may cause a delay in payment processing, but this is not time critical. |
| Payment Administration Center |
DMV |
license request |
High |
Moderate |
Low |
| Contains PII and an indication that the person(s) identified in this flow has violated a toll. Release of this information would compromise the personal privacy of those involved. |
Inaccurate or corrupted information in this flow could lead to a mistaken understanding of the toll violator's identity. |
Real-time response may be required to deal with tolling and similar violations. The number of people affected is probably quite small, but if the load becomes great the availability may need to be raised to MODERATE. |
| Payment Administration Center |
Emissions Management Center |
low emissions zone coordination |
Moderate |
Moderate |
Low |
| While this information may eventually be public, it may contain details of emissions zone operations that could be used to abuse emissions zone systems. |
Configuration functions should have their integrity protected to avoid misconfiguration which could result in revenue or operational losses. |
Probably not a huge impact if this information cannot be updated frequently, thus LOW. If the priority of the low emission zone is high (to the jurisdiction in question) this could be MODERATE. |
| Payment Administration Center |
Enforcement Center |
payment violation notification |
Moderate |
Moderate |
Moderate |
| Contains PII and intended to be used for enforcement. Thus privacy implications that, while they may affect only a single individual at a time, could yield significant negative consequences to that individual. |
Violation information needs to be correct or the commercial vehicle may be improperly penalized, or not when it should be. This is probably not a severe consequence however, so MODERATE. |
More or less important depending on the context. Could even be LOW if areas of minimal import, depending on local policies. |
| Payment Administration Center |
Financial Center |
payment request |
Moderate |
Moderate |
Moderate |
| Contains account and related information that is personal and if compromised could financially impact the owner of the account. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
| Payment Administration Center |
ITS Roadway Payment Equipment |
authorization response |
Moderate |
Moderate |
Moderate |
| While this may not contain any PII, it does expose behavior. While an observer in place may assume payment activity, there is no sound reason to not conceal this information. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
| Payment Administration Center |
ITS Roadway Payment Equipment |
payment instructions |
Moderate |
Moderate |
Moderate |
| This includes control information that can be considered sensitive and competitive, so it should be protected from viewing for competitive reasons. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
| Payment Administration Center |
ITS Roadway Payment Equipment |
road use charges |
Moderate |
Moderate |
Moderate |
| Intended for the end user, so does not generally need to be concealed based on its content. However, could reasonably include localized information which if intercepted implies location of the end user, which is personal and should be protected. |
This material is used to support end user routing with an understanding of travel times and costs. Loss, corruption or forgery are likely to implact small numbers of users and have a moderate impact on revenues. |
This material is used to support end user routing with an understanding of travel times and costs. Loss, corruption or forgery are likely to implact small numbers of users and have a moderate impact on revenues. |
| Payment Administration Center |
Light Vehicle OBE |
access violation notification |
Moderate |
High |
Moderate |
| May contain PII of a black listed user account, and/or vehicle identification. |
Given the potential for PII to be involved, this needs to be correct and unalterable to avoid confusion or malfeasance. |
Availability is at least MODERATE since the information has potential legal (or at least traffic law) implications that would otherwise involve a far less prompt and possibly manpower intensive interaction. |
| Payment Administration Center |
Light Vehicle OBE |
road use charges |
Moderate |
Moderate |
Moderate |
| Intended for the end user, so does not generally need to be concealed based on its content. However, could reasonably include localized information which if intercepted implies location of the end user, which is personal and should be protected. |
This material is used to support end user routing with an understanding of travel times and costs. Loss, corruption or forgery are likely to implact small numbers of users and have a moderate impact on revenues. |
This material is used to support end user routing with an understanding of travel times and costs. Loss, corruption or forgery are likely to implact small numbers of users and have a moderate impact on revenues. |
| Payment Administration Center |
Other Payment Administration Centers |
payment coordination |
Moderate |
High |
Moderate |
| Contains pricing and reconciliation information shared between agencies. If it includes road use charging information this is MODERATE, as road use charging data is vehicle and owner-specific and can be considered personal. A 3rd party observing this information might learn behavrioral patterns of the individual and use that information in the commission of a crime. If no road use charging information is included, this can be reduced to LOW. |
Backoffice operations flows should generally be correct and available as these are the primary interface between operators and system. |
A delay in reporting this may cause a delay in payment processing, but this is not time critical. |
| Payment Administration Center |
Payment Administrator |
payment information presentation |
Moderate |
High |
High |
| Individual payment change requests are unlikely to have any significant systematic impact, but may contain PII and should thus be eyes-only for the operator. |
Backoffice operations flows should generally be correct and available as these are the primary interface between operators and system. |
Backoffice operations flows should generally be correct and available as these are the primary interface between operators and system. |
| Payment Administration Center |
Personal Information Device |
access violation notification |
Moderate |
High |
Moderate |
| May contain PII of a black listed user account, and/or vehicle identification. |
Given the potential for PII to be involved, this needs to be correct and unalterable to avoid confusion or malfeasance. |
Availability is at least MODERATE since the information has potential legal (or at least traffic law) implications that would otherwise involve a far less prompt and possibly manpower intensive interaction. |
| Payment Administration Center |
Personal Information Device |
traveler payment request |
Moderate |
Moderate |
Moderate |
| While this may not contain any PII, it does expose behavior. While an observer in place may assume payment activity, there is no sound reason to not conceal this information. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
Payment flows must all have some integrity protection and consistent availability to prohibit forgery and instill confidence in the payment process. Repurcussions of roadway payment are individually fairly small, collectiviely significant but probably never catastrophic. Thus MODERATE for both integrity and availability. |
| Payment Administration Center |
Personal Information Device |
user account reports |
High |
High |
Moderate |
| Contains user identification and transaction history, which if compromised could lead to identity or financial theft. |
Payment history information, if corrupted, could lead the user to take action he or she should not take. If intercepted by a malicious actor, this could be manipulated to trick the user into taking action not in his own best interest. |
There should be other mechanisms to retrieve this information, but if the flow has low reliability users will lose confidence and not use it. MODERATE for that reason only. |
| Payment Administrator |
Payment Administration Center |
payment administration requests |
Moderate |
High |
High |
| Individual payment change requests are unlikely to have any significant systematic impact, but may contain PII and should thus be eyes-only for the operator. |
Backoffice operations flows should generally be correct and available as these are the primary interface between operators and system. |
Backoffice operations flows should generally be correct and available as these are the primary interface between operators and system. |
| Payment Device |
Light Vehicle OBE |
actuate secure payment |
Moderate |
Moderate |
High |
| Contains an identifier linked to an individual or specific device, and thus PII by definition. Compromise of one secureID would likely impact only one user, but the nature of this flow requires that the same algorithm be used for every user; algorithm compromise would harm every user, which would have widespread impact. |
Payment related information needs to be correct or the user may be inconvenienced or defrauded. |
Contact/proximity payment mechanisms need to be very reliable or large numbers of users will be inconvenienced and the systems that use these interfaces (transit, parking etc.) will be hamstrung by interface failures. |
| Personal Information Device |
Payment Administration Center |
traveler payment information |
High |
High |
Moderate |
| Contains personal information, potentially including identity, payment information such as account numbers and location. All of this information is personal in nature and acceptable only for the intended destination to receive, as any 3rd party observation could lead to identity theft/compromise and/or payment method theft/compromise. |
This is information is used to process payment and/or detect fraud. Any losses, corruption or forgery has a direct impact on revenue collection, charges assessed and potentially legal action. |
This is information is used to process payment . Any losses, corruption or forgery has a direct impact on revenue collection, charges assessed and potentially legal action. Availability constrained to MODERATE the fact that alternative mechanisms and compromises exist to ameliorate not completing the flow. |
| Personal Information Device |
Payment Administration Center |
user account setup |
High |
High |
Moderate |
| Contains user identification and matching vehicle information, which if compromised could lead to identity theft or remote tracking. |
Payment setup information, if corrupted, could lead the user to not properly pay for his trips or perhaps pay for others. If intercepted by a malicious actor, this could be manipulated to trick the user into taking action not in his own best interest. |
There should be other mechanisms to provide this information, but if the flow has low reliability users will lose confidence and not use it. MODERATE for that reason only. |