National Academies Press: OpenBook
« Previous: APPENDIX E: Sample Nondisclosure Agreements
Page 75
Suggested Citation:"APPENDIX F: Examples of SSI and Non-SSI." National Academies of Sciences, Engineering, and Medicine. 2010. Reconciling Security, Disclosure, and Record-Retention Requirements in Transit Procurements. Washington, DC: The National Academies Press. doi: 10.17226/14404.
×
Page 75

Below is the uncorrected machine-read text of this chapter, intended to provide our own search engines and external engines with highly rich, chapter-representative searchable text of each book. Because it is UNCORRECTED material, please consider the following text as a useful but insufficient proxy for the authoritative book pages.

75 APPENDIX F: Examples of SSI and Non-SSI The following table is reproduced from FTA’s March 2009 Sensitive Security Information (SSI): Designation, Markings, and Control, Resource Document for Transit Agencies, page 9, http://transit- safety.volpe.dot.gov/Publications/order/singledoc.asp?docid=968. Table 1. Examples of SSI and Non-SSI Might Be SSI Usually Not SSI System Design and Operational Information Transit system design configurations, including architectural drawings and engineering schematics; critical assets and network topology maps; exposed, unattended, or unprotected assets; critical infrastructure layouts; energy sources; and communications assets and procedures Environmental, safety, or health information Installation and design-related operational information concern- ing critical equipment or components that, if sabotaged, could pre- vent operation or safe shutdown Information needed to comply with laws and regulations Security System Design and Equipment Information Records of vulnerabilities or security deficiencies at specified fa- cilities or locations, or within the transit agency in general Information discernable by casual observa- tion Records of specific locations and design or operational details of internal security devices, such as sensors, detectors, alarms, and barriers Budgeting and cost information Information about the capabilities and limitations of security sys- tems, and methods and times to defeat or degrade equipment, op- erations, or mitigations General information about equipment Security procedures and operations that are of a non-routine na- ture Routine administrative data Information about physical security vulnerabilities and deficien- cies, especially if they have not been corrected Records of past facility and equipment evaluations that do not reveal security-related deficiencies or that reveal deficiencies that have been corrected Information about intrusion detection, alarm, or assessment equipment, including physical and cybersecurity plans and perform- ance of installed equipment Installation records for intrusion detection, alarm, or assessment systems Information about security system design or integration, includ- ing heightened-risk operating procedures Commercial vendor information about secu- rity equipment and systems Data on security personnel assigned to specific transit facilities, including times and locations, where information can not be deter- mined by casual observation Total number of security personnel assigned to transit system facilities, or the fact that per- sonnel numbers are being increased or de- creased Emergency and Emergency Communications Information Some emergency procedures, including heightened-risk operating procedures, contingency plans, and business continuity plans Fire response and evacuation plans that must be shared with all employees Records of assessments, drills, or exercises that reveal system or security vulnerabilities Records of communications equipment used by transit authorities, including emergency management Ridership Data Information about the number of passengers on individual trains or buses or at a particular time of day

Next: APPENDIX G: Checklist for Assessing Adequacy of Management of Security Information »
Reconciling Security, Disclosure, and Record-Retention Requirements in Transit Procurements Get This Book
×
 Reconciling Security, Disclosure, and Record-Retention Requirements in Transit Procurements
MyNAP members save 10% online.
Login or Register to save!
Download Free PDF

TRB‘s Transit Cooperative Research Program (TCRP) Legal Research Digest 32: Reconciling Security, Disclosure, and Record-Retention Requirements in Transit Procurements highlights the legal requirements that are relevant to the transit procurement process of balancing the competing needs of open government and public security. The report explores federal and state requirements concerning record retention and disclosure, as well as practices transit agencies have adopted to meet their responsibilities in balancing these competing public policy interests.

READ FREE ONLINE

  1. ×

    Welcome to OpenBook!

    You're looking at OpenBook, NAP.edu's online reading room since 1999. Based on feedback from you, our users, we've made some improvements that make it easier than ever to read thousands of publications on our website.

    Do you want to take a quick tour of the OpenBook's features?

    No Thanks Take a Tour »
  2. ×

    Show this book's table of contents, where you can jump to any chapter by name.

    « Back Next »
  3. ×

    ...or use these buttons to go back to the previous chapter or skip to the next one.

    « Back Next »
  4. ×

    Jump up to the previous page or down to the next one. Also, you can type in a page number and press Enter to go directly to that page in the book.

    « Back Next »
  5. ×

    To search the entire text of this book, type in your search term here and press Enter.

    « Back Next »
  6. ×

    Share a link to this book page on your preferred social network or via email.

    « Back Next »
  7. ×

    View our suggested citation for this chapter.

    « Back Next »
  8. ×

    Ready to take your reading offline? Click here to buy this book in print or download it as a free PDF, if available.

    « Back Next »
Stay Connected!