This document specifies the minimum governance procedure requirements for ITS data management and access using secure interfaces (and, particularly, secure vehicle interfaces) in order to meet objectives in accordance with the principles of ISO/TC 204 policy documents concerning ITS data governance policy. NOTE 1 Where an ITS data management and access paradigm is already in existence, this document proposes only to provide a suitable checklist for any assessment of its competency. This document does not propose that existing arrangements that are acceptably competent be changed. NOTE 2 This document does not affect proprietary original equipment manufacturer (OEM) communications using ExVe (see ISO 20077-1), but does provide means for its complementary coexistence.
Systèmes de transport intelligents — Gouvernance à l'aide d'interfaces sécurisées — Exigences minimales et procédures de gouvernance
This document provides specifications for the minimum requirements for a governance process for using
"ITS Trusted Devices" for ITS data management and access via secure interfaces.
The paradigm presented in this document can be used for any ITS interface, but it is particularly focused on
meeting some of the unique characteristics of the interface between a vehicle and external entities, such as
roadside units and other vehicles.
While many technical specifications and standards have already been developed on the use of ITS devices
for ITS data management and access (and on which this document relies), combinations of such documents
need to be used consistently and the whole system needs to be consistently governed. This document
concerns the adoption and use of combinations of existing approved technical specifications or standards in
combination with governance processes. It does not introduce new technical specifications. While it enables
government policies to be consistently supported, it does not specify those policies.
For the purposes of this document, the term "governance" encompasses the use and combination of systems
that direct and control ITS data entities, including the structure and processes for decision making,
accountability, control and behaviour. ITS data governance influences how an organization’s objectives
are set and achieved, and how risk is monitored and addressed in terms of the acquisition, use, retention,
sharing and elimination of ITS data. ITS data governance also prescribes a system and a process, rather than
a single activity; successful implementation of a good governance strategy therefore requires a systematic
approach that incorporates strategic planning, risk management and performance management.
The purpose of this document is to specify the use and combination of (largely already existent) standards
and specifications for the governance of data across ITS secure interfaces, and to present organizational
concepts to support such governance measures in accordance with the principles of ISO/TC 204 policy
documents concerning ITS data governance policy. This involves the components of a so called "trust model"
[e.g. PKI (public key infrastructure) services] as well as the entities running them, i.e. the trusted third
parties for the trust and privacy management on which operational entities rely, and which allow them to be
run in a secure and reliable way.
Governance in an international context and covering a wide range of use-case paradigms with different
needs necessitates a multi-layer governance model, with general governance and specification of high-level
options that are useable by all and maintain consistency. Regional requirements can be introduced to this
level to meet the needs of regional government.
These operational aspects need be overt and clear to all and provide the principal policy requirements
and options to maintain cybersecure interoperability. They can be found in accordance with the
principles of ISO/TC 204 policy documents concerning ITS data governance policy and form the principle
recommendations and minimum requirements for governance of ITS data management and access. However,
