Cybersecurity and data protection
For Topic 26-OS1, are there specific cybersecurity or data protection expectations for Phase I Trusted Intermediary architectures using proprietary carrier, telematics, maintenance, or transportation operations data, such as NIST SP 800-171, FISMA, FedRAMP, CMMC, encryption, access control, or audit-log expectations?
2
votes
-
Phase I is intended to demonstrate a feasibility concept and we expect the proposal to comply with the privacy framework necessary to protect any data being used during the feasibility concept demonstration. The proposal should have a plan to come into compliance with all USDOT requirements prior to a potential deployment.