82_FR_56027 82 FR 55802 - National Cybersecurity Center of Excellence (NCCoE) Securing Property Management Systems for the Hospitality Sector

82 FR 55802 - National Cybersecurity Center of Excellence (NCCoE) Securing Property Management Systems for the Hospitality Sector

DEPARTMENT OF COMMERCE
National Institute of Standards and Technology

Federal Register Volume 82, Issue 225 (November 24, 2017)

Page Range55802-55804
FR Document2017-25427

The National Institute of Standards and Technology (NIST) invites organizations to provide products and technical expertise to support and demonstrate security platforms for Securing Property Management Systems for the Hospitality Sector. This notice is the initial step for the National Cybersecurity Center of Excellence (NCCoE) in collaborating with technology companies to address cybersecurity challenges identified under the Hospitality Sector program. Participation in the use case is open to all interested organizations.

Federal Register, Volume 82 Issue 225 (Friday, November 24, 2017)
[Federal Register Volume 82, Number 225 (Friday, November 24, 2017)]
[Notices]
[Pages 55802-55804]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2017-25427]


-----------------------------------------------------------------------

DEPARTMENT OF COMMERCE

National Institute of Standards and Technology

[Docket No. 171010985-7985-01]


National Cybersecurity Center of Excellence (NCCoE) Securing 
Property Management Systems for the Hospitality Sector

AGENCY: National Institute of Standards and Technology, Department of 
Commerce.

ACTION: Notice.

-----------------------------------------------------------------------

SUMMARY: The National Institute of Standards and Technology (NIST) 
invites organizations to provide products and technical expertise to 
support and demonstrate security platforms for Securing Property 
Management Systems for the Hospitality Sector. This notice is the 
initial step for the National Cybersecurity Center of Excellence 
(NCCoE) in collaborating with technology companies to address 
cybersecurity challenges identified under the Hospitality Sector 
program. Participation in the use case is open to all interested 
organizations.

DATES: Interested parties must contact NIST to request a letter of 
interest template to be completed and submitted to NIST. Letters of 
interest will be accepted on a first come, first served basis. 
Collaborative activities will commence as soon as enough completed and 
signed letters of interest have been returned to address all the 
necessary components and capabilities, but no earlier than December 26, 
2017. When the use case has been completed, NIST will post a notice on 
the NCCoE Hospitality Sector program Web site at https://nccoe.nist.gov/projects/use-cases/securing-property-management-systems 
announcing the completion of the use case and informing the public that 
it will no longer accept letters of interest for this use case.

ADDRESSES: The NCCoE is located at 9700 Great Seneca Highway, 
Rockville, MD 20850. Letters of interest must be submitted to 
[email protected] or via hardcopy to National Institute of 
Standards and Technology, NCCoE; 9700 Great Seneca Highway, Rockville, 
MD 20850. Organizations whose letters of interest are accepted in 
accordance with the process set forth in the SUPPLEMENTARY INFORMATION 
section of this notice will be asked to sign a consortium Cooperative 
Research and Development Agreement (CRADA) with NIST. An NCCoE 
consortium CRADA template can be found at: http://nccoe.nist.gov/node/138.

FOR FURTHER INFORMATION CONTACT: Mr. William Newhouse via email to 
[email protected]; by telephone (301) 975-0232; or by mail to 
National Institute of Standards and Technology, NCCoE; 9700 Great 
Seneca Highway, Rockville, MD 20850. Additional details about the 
Hospitality Sector program are available at https://nccoe.nist.gov/projects/use-cases/securing-property-management-systems.

SUPPLEMENTARY INFORMATION: 
    Background: The NCCoE, part of NIST, is a public-private 
collaboration for accelerating the widespread adoption of integrated 
cybersecurity tools and technologies. The NCCoE brings together experts 
from industry, government, and academia under one roof to develop 
practical, interoperable cybersecurity approaches that address the 
real-world needs of complex Information Technology (IT) systems. By 
accelerating dissemination and use of these integrated tools and 
technologies for protecting IT assets, the NCCoE will enhance trust in 
U.S. IT communications, data, and storage systems; reduce risk for 
companies and individuals using IT systems; and encourage development 
of innovative, job-creating cybersecurity products and services.
    Process: NIST is soliciting responses from all sources of relevant 
security capabilities (see below) to enter into a Cooperative Research 
and Development Agreement (CRADA) to provide products and technical 
expertise to support and demonstrate security platforms for the 
Securing Property Management Systems for the Hospitality Sector. The 
full use case can be viewed at: https://nccoe.nist.gov/projects/use-cases/securing-property-management-systems.
    Interested parties should contact NIST using the information 
provided in the FOR FURTHER INFORMATION CONTACT section of this notice. 
NIST will then provide each interested party with a

[[Page 55803]]

letter of interest template, which the party must complete, certify 
that it is accurate, and submit to NIST. NIST will contact interested 
parties if there are questions regarding the responsiveness of the 
letters of interest to the use case objective or requirements 
identified below. NIST will select participants who have submitted 
complete letters of interest on a first come, first served basis within 
each category of product components or capabilities listed below up to 
the number of participants in each category necessary to carry out this 
use case. However, there may be continuing opportunity to participate 
even after initial activity commences. Selected participants will be 
required to enter into a consortium CRADA with NIST (for reference, see 
ADDRESSES section above). NIST published a notice in the Federal 
Register on October 19, 2012 (77 FR 64314) inviting U.S. companies to 
enter into National Cybersecurity Excellence Partnerships (NCEPs) in 
furtherance of the NCCoE. For this demonstration project, NCEP partners 
will not be given priority for participation.
    Use Case Objective: The objective of this project is to help the 
hospitality industry implement stronger security measures and reduce 
vulnerabilities within and around their Property Management Systems 
(PMS), with a focus on the connection to a point-of-sale (POS) system. 
The project will identify typical hotel IT infrastructures and PMS-POS 
configurations, systems, and components that integrate or interface 
with both applications. The project will also identify interactions 
between PMS operators and authorized third-party service provider (SP) 
systems (e.g., online booking, customer relationship marketing 
partners, etc.). This project will result in a NIST Cybersecurity 
Practice Guide--a publicly available description of the solution and 
practical steps needed to effectively secure property management 
systems. A detailed description of the Securing Property Management 
Systems Use Case is available at: https://nccoe.nist.gov/projects/use-cases/securing-property-management-systems.
    Requirements: Each responding organization's letter of interest 
should identify which security platform component(s) or capability(ies) 
it is offering. Letters of interest should not include company 
proprietary information, and all components and capabilities must be 
commercially available. Components are listed in section 3 of the 
Securing Property Management Systems Project Description for the 
Hospitality Sector (for reference, please see the link in the PROCESS 
section above) and include, but are not limited to:

 PMS and POS system(s)
 Point-to-Point Encryption (P2PE)
 Data tokenization
 Multifactor authentication mechanism
 Access control platform
 User behavior analytics
 Network analytics
 Data logging
 Data storage
 Virtualization

    Each responding organization's letter of interest should identify 
how their products address one or more of the following desired 
solution characteristics in section 3 of the Securing Property 
Management Systems for the Hospitality Sector (for reference, please 
see the link in the PROCESS section above):
    1. Auditing, analytics and response capabilities such as:

 Complete, near real-time auditing and reporting of activity, 
including:
    [cir] User behavior analytics
    [cir] Unauthorized access
    [cir] Unauthorized user behavior
    [cir] Network analytics
    [cir] Access requests and decisions
 Automated detection and/or response to incidents
 Continuous monitoring and retention of information on 
component interactions
 Continuous monitoring and retention of network events

    2. System Protection and Authentication capabilities with 
enforcement such as:

 Access control for internal and third-party users, including:
    [cir] Access control policy creation
    [cir] Determination of access control decisions based on policies
    [cir] Access control policy enforcement
 Multifactor Authentication for remote and third-party access
 Adherence to principles of segmentation and zero-trust, 
including:
    [cir] Multiple trust zones and logical trust boundaries
    [cir] Network segmentation gateways
    [cir] Network virtualization platform and micro-segmentation

    3. Data Protection and Encryption capabilities to prevent damage to 
PCI/PII confidentiality, as well as the confidentiality and integrity 
of system data such as:

 Point-to-point encryption (P2PE)
 Limited/no storing/processing/transmission of payment card 
data
 Secure data tokenization and token management capabilities, 
including:
    [cir] Token generation
    [cir] Token mapping
    [cir] Cryptographic key management
 Utilization of a non-PCI, sensitive consumer secure data vault
 Prevention of damage to PCI/PII confidentiality
 Prevention of damage to PMS functionality and security, and 
improved mitigation of cybersecurity risks
 Secure Payment Terminal
 Payment Information Proxy service

    Responding organizations need to understand and, in their letters 
of interest, commit to provide:
    1. Access for all participants' project teams to component 
interfaces and the organization's experts necessary to make functional 
connections among security platform components.
    2. Support for development and demonstration of the Securing 
Property Management Systems for the Hospitality Sector in NCCoE 
facilities, which will be conducted in a manner consistent with the 
following standards and guidance: FIPS 140-2, FIPS 200, FIPS 201, SP 
800-53, SP 800-63-3, and Payment Card Industry Data Security Standard 
(PCI-DSS).
    Additional details about the Securing Property Management Systems 
for the Hospitality Sector use case are available at: https://nccoe.nist.gov/projects/use-cases/securing-property-management-systems.
    NIST cannot guarantee that all of the products proposed by 
respondents will be used in the demonstration. Each prospective 
participant will be expected to work collaboratively with NIST staff 
and other project participants under the terms of the consortium CRADA 
in the development of the Securing Property Management Systems for the 
Hospitality Sector capability. Prospective participants' contribution 
to the collaborative effort will include assistance in establishing the 
necessary interface functionality, connection and set-up capabilities 
and procedures, demonstration harnesses, environmental and safety 
conditions for use, integrated platform user instructions, and 
demonstration plans and scripts necessary to demonstrate the desired 
capabilities. Each participant will train NIST personnel, as necessary, 
to operate its product in capability demonstrations to the Hospitality 
community. Following successful demonstrations, NIST will publish a 
description of the security platform and its performance 
characteristics sufficient to permit other organizations to develop and 
deploy security platforms that meet the security objectives of the 
Securing Property Management Systems for the Hospitality

[[Page 55804]]

Sector use case. These descriptions will be public information.
    Under the terms of the consortium CRADA, NIST will support 
development of interfaces among participants' products by providing IT 
infrastructure, laboratory facilities, office facilities, collaboration 
facilities, and staff support to component composition, security 
platform documentation, and demonstration activities.
    The dates of the demonstration of the Securing Property Management 
Systems for the Hospitality Sector capability will be announced on the 
NCCoE Web site at least two weeks in advance at http://nccoe.nist.gov/. 
The expected outcome of the demonstration is to improve Securing 
Property Management Systems across an entire Hospitality Sector 
enterprise. Participating organizations will gain from the knowledge 
that their products are interoperable with other participants' 
offerings.
    For additional information on the NCCoE governance, business 
processes, and NCCoE operational structure, visit the NCCoE Web site 
http://nccoe.nist.gov/.

Kevin Kimball,
NIST Chief of Staff.
[FR Doc. 2017-25427 Filed 11-22-17; 8:45 am]
 BILLING CODE 3510-13-P



                                                55802                       Federal Register / Vol. 82, No. 225 / Friday, November 24, 2017 / Notices

                                                radiators; sound mufflers for vehicle                   21013, U.S. Department of Commerce,                   ADDRESSES:    The NCCoE is located at
                                                engines; clutch assemblies; bearing                     1401 Constitution Avenue NW.,                         9700 Great Seneca Highway, Rockville,
                                                holders; transmissions; transmission                    Washington, DC 20230–0002, and in the                 MD 20850. Letters of interest must be
                                                sub-assemblies; brakes; axle covers;                    ‘‘Reading Room’’ section of the Board’s               submitted to hospitality-nccoe@nist.gov
                                                brackets; stays; rods; muffler pipe; rod                Web site, which is accessible via                     or via hardcopy to National Institute of
                                                assemblies; flanges; supports; knobs;                   www.trade.gov/ftz.                                    Standards and Technology, NCCoE;
                                                levers; wiper blades; control wire;                        For further information, contact                   9700 Great Seneca Highway, Rockville,
                                                control cable; shock absorbers; universal               Christopher Wedderburn at                             MD 20850. Organizations whose letters
                                                joints; bevel gears; spiral gears; pinion               Chris.Wedderburn@trade.gov or (202)                   of interest are accepted in accordance
                                                gears; guards; lenses; plates; planetary                482–1963.                                             with the process set forth in the
                                                gears; splines; drive shafts; clutch rod                  Dated: November 17, 2017.                           SUPPLEMENTARY INFORMATION section of
                                                shafts; u-joints; shaft assemblies; collars;                                                                  this notice will be asked to sign a
                                                                                                        Andrew McGilvray,
                                                differential cases; transmission cases;                                                                       consortium Cooperative Research and
                                                ball joints; axle cases; gear cases; gear               Executive Secretary.
                                                                                                                                                              Development Agreement (CRADA) with
                                                shafts; pins; shims; bushings; drive shaft              [FR Doc. 2017–25399 Filed 11–22–17; 8:45 am]
                                                                                                                                                              NIST. An NCCoE consortium CRADA
                                                caps; shaft couplings; steering shafts;                 BILLING CODE 3510–DS–P
                                                                                                                                                              template can be found at: http://
                                                shaft yokes; thrust collars; synchronizer                                                                     nccoe.nist.gov/node/138.
                                                rings; dust covers; heater assemblies; tie                                                                    FOR FURTHER INFORMATION CONTACT: Mr.
                                                rods; brackets; battery retainers; control              DEPARTMENT OF COMMERCE
                                                                                                                                                              William Newhouse via email to
                                                pedals; fuel tanks; hand rails; radiator                                                                      hospitality-nccoe@nist.gov; by
                                                                                                        National Institute of Standards and
                                                grilles; bonnet dampers; steering                                                                             telephone (301) 975–0232; or by mail to
                                                                                                        Technology
                                                linkages; suspension linkages; muffler                                                                        National Institute of Standards and
                                                stays; struts for agricultural tractors and             [Docket No. 171010985–7985–01]
                                                                                                                                                              Technology, NCCoE; 9700 Great Seneca
                                                other off-road vehicles; unmounted                                                                            Highway, Rockville, MD 20850.
                                                glass lenses for vehicle signals and                    National Cybersecurity Center of
                                                                                                        Excellence (NCCoE) Securing Property                  Additional details about the Hospitality
                                                controls; glass lenses for vehicle signals                                                                    Sector program are available at https://
                                                and controls; thermometers; sensors;                    Management Systems for the
                                                                                                        Hospitality Sector                                    nccoe.nist.gov/projects/use-cases/
                                                gauges; oil switches; electrical sensors                                                                      securing-property-management-systems.
                                                and liquid and gas sensors; odometers;                  AGENCY: National Institute of Standards               SUPPLEMENTARY INFORMATION:
                                                other panel meters for use in vehicle                   and Technology, Department of
                                                control; counters for use in vehicles and                                                                        Background: The NCCoE, part of
                                                                                                        Commerce.                                             NIST, is a public-private collaboration
                                                farm implements; volt meters for vehicle
                                                and farm implement controls; other                      ACTION: Notice.                                       for accelerating the widespread
                                                instruments for vehicle and farm                                                                              adoption of integrated cybersecurity
                                                                                                        SUMMARY:    The National Institute of                 tools and technologies. The NCCoE
                                                implement controls; test benches for                    Standards and Technology (NIST)
                                                vehicle and implement repair;                                                                                 brings together experts from industry,
                                                                                                        invites organizations to provide                      government, and academia under one
                                                measuring equipment for vehicle                         products and technical expertise to
                                                control and repair; thermostats;                                                                              roof to develop practical, interoperable
                                                                                                        support and demonstrate security                      cybersecurity approaches that address
                                                temperature controllers; speed sensors                  platforms for Securing Property
                                                for vehicle control; regulators; rotary                                                                       the real-world needs of complex
                                                                                                        Management Systems for the Hospitality                Information Technology (IT) systems.
                                                switches; seats and seat assemblies;                    Sector. This notice is the initial step for
                                                slide rollers for seats; work lamps; toy                                                                      By accelerating dissemination and use
                                                                                                        the National Cybersecurity Center of                  of these integrated tools and
                                                tractors; brushes for vehicle repair; and,              Excellence (NCCoE) in collaborating
                                                electric lighter covers for agricultural                                                                      technologies for protecting IT assets, the
                                                                                                        with technology companies to address                  NCCoE will enhance trust in U.S. IT
                                                tractors and other off-road vehicles
                                                                                                        cybersecurity challenges identified                   communications, data, and storage
                                                (duty rate ranges from duty-free to
                                                                                                        under the Hospitality Sector program.                 systems; reduce risk for companies and
                                                12%). The request indicates that
                                                                                                        Participation in the use case is open to              individuals using IT systems; and
                                                bearings are subject to antidumping/
                                                                                                        all interested organizations.                         encourage development of innovative,
                                                countervailing duty (AD/CVD) orders
                                                when imported from certain countries.                   DATES: Interested parties must contact                job-creating cybersecurity products and
                                                The FTZ Board’s regulations (15 CFR                     NIST to request a letter of interest                  services.
                                                400.14(e)) require that merchandise                     template to be completed and submitted                   Process: NIST is soliciting responses
                                                subject to AD/CVD orders, or items                      to NIST. Letters of interest will be                  from all sources of relevant security
                                                which would be otherwise subject to                     accepted on a first come, first served                capabilities (see below) to enter into a
                                                suspension of liquidation under AD/                     basis. Collaborative activities will                  Cooperative Research and Development
                                                CVD procedures if they entered U.S.                     commence as soon as enough completed                  Agreement (CRADA) to provide
                                                customs territory, be admitted to the                   and signed letters of interest have been              products and technical expertise to
                                                zone in privileged foreign status (19                   returned to address all the necessary                 support and demonstrate security
                                                CFR 146.41).                                            components and capabilities, but no                   platforms for the Securing Property
                                                   Public comment is invited from                       earlier than December 26, 2017. When                  Management Systems for the Hospitality
                                                interested parties. Submissions shall be                the use case has been completed, NIST                 Sector. The full use case can be viewed
                                                                                                        will post a notice on the NCCoE
sradovich on DSK3GMQ082PROD with NOTICES




                                                addressed to the Board’s Executive                                                                            at: https://nccoe.nist.gov/projects/use-
                                                Secretary at the address below. The                     Hospitality Sector program Web site at                cases/securing-property-management-
                                                closing period for their receipt is                     https://nccoe.nist.gov/projects/use-                  systems.
                                                January 3, 2018.                                        cases/securing-property-management-                      Interested parties should contact NIST
                                                   A copy of the notification will be                   systems announcing the completion of                  using the information provided in the
                                                available for public inspection at the                  the use case and informing the public                 FOR FURTHER INFORMATION CONTACT
                                                Office of the Executive Secretary,                      that it will no longer accept letters of              section of this notice. NIST will then
                                                Foreign-Trade Zones Board, Room                         interest for this use case.                           provide each interested party with a


                                           VerDate Sep<11>2014   18:19 Nov 22, 2017   Jkt 244001   PO 00000   Frm 00004   Fmt 4703   Sfmt 4703   E:\FR\FM\24NON1.SGM   24NON1


                                                                            Federal Register / Vol. 82, No. 225 / Friday, November 24, 2017 / Notices                                           55803

                                                letter of interest template, which the                  PROCESS section above) and include,                      Æ Token mapping
                                                party must complete, certify that it is                 but are not limited to:                                  Æ Cryptographic key management
                                                accurate, and submit to NIST. NIST will                 • PMS and POS system(s)                               • Utilization of a non-PCI, sensitive
                                                contact interested parties if there are                 • Point-to-Point Encryption (P2PE)                       consumer secure data vault
                                                questions regarding the responsiveness                  • Data tokenization                                   • Prevention of damage to PCI/PII
                                                of the letters of interest to the use case              • Multifactor authentication mechanism                   confidentiality
                                                objective or requirements identified                    • Access control platform                             • Prevention of damage to PMS
                                                below. NIST will select participants                    • User behavior analytics                                functionality and security, and
                                                who have submitted complete letters of                  • Network analytics                                      improved mitigation of cybersecurity
                                                interest on a first come, first served                  • Data logging                                           risks
                                                basis within each category of product                   • Data storage                                        • Secure Payment Terminal
                                                components or capabilities listed below                 • Virtualization                                      • Payment Information Proxy service
                                                up to the number of participants in each                  Each responding organization’s letter                  Responding organizations need to
                                                category necessary to carry out this use                of interest should identify how their                 understand and, in their letters of
                                                case. However, there may be continuing                  products address one or more of the                   interest, commit to provide:
                                                opportunity to participate even after                   following desired solution                               1. Access for all participants’ project
                                                initial activity commences. Selected                    characteristics in section 3 of the                   teams to component interfaces and the
                                                participants will be required to enter                                                                        organization’s experts necessary to make
                                                                                                        Securing Property Management Systems
                                                into a consortium CRADA with NIST                                                                             functional connections among security
                                                                                                        for the Hospitality Sector (for reference,
                                                (for reference, see ADDRESSES section                                                                         platform components.
                                                                                                        please see the link in the PROCESS
                                                above). NIST published a notice in the                                                                           2. Support for development and
                                                                                                        section above):
                                                Federal Register on October 19, 2012                                                                          demonstration of the Securing Property
                                                                                                          1. Auditing, analytics and response
                                                (77 FR 64314) inviting U.S. companies                                                                         Management Systems for the Hospitality
                                                                                                        capabilities such as:
                                                to enter into National Cybersecurity                                                                          Sector in NCCoE facilities, which will
                                                Excellence Partnerships (NCEPs) in                      • Complete, near real-time auditing and
                                                                                                          reporting of activity, including:                   be conducted in a manner consistent
                                                furtherance of the NCCoE. For this                                                                            with the following standards and
                                                demonstration project, NCEP partners                      Æ User behavior analytics
                                                                                                          Æ Unauthorized access                               guidance: FIPS 140–2, FIPS 200, FIPS
                                                will not be given priority for
                                                                                                          Æ Unauthorized user behavior                        201, SP 800–53, SP 800–63–3, and
                                                participation.
                                                   Use Case Objective: The objective of                   Æ Network analytics                                 Payment Card Industry Data Security
                                                this project is to help the hospitality                   Æ Access requests and decisions                     Standard (PCI–DSS).
                                                industry implement stronger security                    • Automated detection and/or response                    Additional details about the Securing
                                                measures and reduce vulnerabilities                       to incidents                                        Property Management Systems for the
                                                within and around their Property                        • Continuous monitoring and retention                 Hospitality Sector use case are available
                                                Management Systems (PMS), with a                          of information on component                         at: https://nccoe.nist.gov/projects/use-
                                                focus on the connection to a point-of-                    interactions                                        cases/securing-property-management-
                                                sale (POS) system. The project will                     • Continuous monitoring and retention                 systems.
                                                identify typical hotel IT infrastructures                 of network events                                      NIST cannot guarantee that all of the
                                                and PMS–POS configurations, systems,                      2. System Protection and                            products proposed by respondents will
                                                and components that integrate or                        Authentication capabilities with                      be used in the demonstration. Each
                                                interface with both applications. The                   enforcement such as:                                  prospective participant will be expected
                                                project will also identify interactions                                                                       to work collaboratively with NIST staff
                                                                                                        • Access control for internal and third-              and other project participants under the
                                                between PMS operators and authorized                      party users, including:
                                                third-party service provider (SP)                                                                             terms of the consortium CRADA in the
                                                                                                          Æ Access control policy creation                    development of the Securing Property
                                                systems (e.g., online booking, customer                   Æ Determination of access control
                                                relationship marketing partners, etc.).                                                                       Management Systems for the Hospitality
                                                                                                             decisions based on policies                      Sector capability. Prospective
                                                This project will result in a NIST                        Æ Access control policy enforcement
                                                Cybersecurity Practice Guide—a                                                                                participants’ contribution to the
                                                                                                        • Multifactor Authentication for remote               collaborative effort will include
                                                publicly available description of the                     and third-party access
                                                solution and practical steps needed to                                                                        assistance in establishing the necessary
                                                                                                        • Adherence to principles of                          interface functionality, connection and
                                                effectively secure property management                    segmentation and zero-trust,
                                                systems. A detailed description of the                                                                        set-up capabilities and procedures,
                                                                                                          including:                                          demonstration harnesses, environmental
                                                Securing Property Management Systems                      Æ Multiple trust zones and logical
                                                Use Case is available at: https://                                                                            and safety conditions for use, integrated
                                                                                                             trust boundaries                                 platform user instructions, and
                                                nccoe.nist.gov/projects/use-cases/                        Æ Network segmentation gateways
                                                securing-property-management-systems.                                                                         demonstration plans and scripts
                                                                                                          Æ Network virtualization platform                   necessary to demonstrate the desired
                                                   Requirements: Each responding
                                                                                                             and micro-segmentation                           capabilities. Each participant will train
                                                organization’s letter of interest should
                                                identify which security platform                          3. Data Protection and Encryption                   NIST personnel, as necessary, to operate
                                                component(s) or capability(ies) it is                   capabilities to prevent damage to PCI/                its product in capability demonstrations
                                                offering. Letters of interest should not                PII confidentiality, as well as the                   to the Hospitality community.
                                                                                                        confidentiality and integrity of system               Following successful demonstrations,
sradovich on DSK3GMQ082PROD with NOTICES




                                                include company proprietary
                                                information, and all components and                     data such as:                                         NIST will publish a description of the
                                                capabilities must be commercially                       • Point-to-point encryption (P2PE)                    security platform and its performance
                                                available. Components are listed in                     • Limited/no storing/processing/                      characteristics sufficient to permit other
                                                section 3 of the Securing Property                        transmission of payment card data                   organizations to develop and deploy
                                                Management Systems Project                              • Secure data tokenization and token                  security platforms that meet the security
                                                Description for the Hospitality Sector                    management capabilities, including:                 objectives of the Securing Property
                                                (for reference, please see the link in the                Æ Token generation                                  Management Systems for the Hospitality


                                           VerDate Sep<11>2014   18:19 Nov 22, 2017   Jkt 244001   PO 00000   Frm 00005   Fmt 4703   Sfmt 4703   E:\FR\FM\24NON1.SGM   24NON1


                                                55804                       Federal Register / Vol. 82, No. 225 / Friday, November 24, 2017 / Notices

                                                Sector use case. These descriptions will                   Meeting address: The meeting will be               DEPARTMENT OF COMMERCE
                                                be public information.                                  held via webinar and are open to
                                                   Under the terms of the consortium                    members of the public. Webinar                        National Oceanic and Atmospheric
                                                CRADA, NIST will support                                registration is required and registration             Administration
                                                development of interfaces among                         links will be posted to the Citizen
                                                participants’ products by providing IT                                                                        Marine Mammals and Endangered
                                                                                                        Science program page of the Council’s
                                                infrastructure, laboratory facilities,                                                                        Species
                                                                                                        Web site at www.safmc.net.
                                                office facilities, collaboration facilities,                                                                  AGENCY:  National Marine Fisheries
                                                and staff support to component                             Council address: South Atlantic
                                                                                                        Fishery Management Council, 4055                      Service (NMFS), National Oceanic and
                                                composition, security platform                                                                                Atmospheric Administration (NOAA),
                                                documentation, and demonstration                        Faber Place Drive, Suite 201, N.
                                                                                                                                                              Commerce.
                                                activities.                                             Charleston, SC 29405.
                                                                                                                                                              ACTION: Notice; receipt of applications
                                                   The dates of the demonstration of the                FOR FURTHER INFORMATION CONTACT:                      for permit amendments.
                                                Securing Property Management Systems                    Amber Von Harten, Citizen Science
                                                for the Hospitality Sector capability will              Program Manager, SAFMC; phone: (843)                  SUMMARY:   Notice is hereby given that
                                                be announced on the NCCoE Web site                      302–8433 or toll free (866) SAFMC–10;                 the permit holders listed below have
                                                at least two weeks in advance at http://                fax: (843) 769–4520; email:                           applied for an amendment to their
                                                nccoe.nist.gov/. The expected outcome                   amber.vonharten@safmc.net.                            Scientific Research Permits.
                                                of the demonstration is to improve                                                                            DATES: Written, telefaxed, or email
                                                Securing Property Management Systems                    SUPPLEMENTARY INFORMATION:    The                     comments must be received on or before
                                                across an entire Hospitality Sector                     Council created a Citizen Science                     December 26, 2017.
                                                enterprise. Participating organizations                 Advisory Panel Pool in June 2017. The                 ADDRESSES: The application and related
                                                will gain from the knowledge that their                 Council appointed members of the                      documents are available for review by
                                                products are interoperable with other                   Citizen Science Advisory Panel Pool to                selecting ‘‘Records Open for Public
                                                participants’ offerings.                                five Action Teams in the areas of                     Comment’’ from the ‘‘Features’’ box on
                                                   For additional information on the                    Volunteers, Data Management, Projects/                the Applications and Permits for
                                                NCCoE governance, business processes,                   Topics Management, Finance, and                       Protected Species home page, https://
                                                and NCCoE operational structure, visit                  Communication/Outreach/Education to                   apps.nmfs.noaa.gov, and then selecting
                                                the NCCoE Web site http://                              develop program policies and                          the File No. from the list of available
                                                nccoe.nist.gov/.                                        operations for the Council’s Citizen                  applications.
                                                Kevin Kimball,                                          Science Program.                                         These documents are also available
                                                                                                                                                              upon written request or by appointment
                                                NIST Chief of Staff.                                       The Action Team will meet to                       in the Permits and Conservation
                                                [FR Doc. 2017–25427 Filed 11–22–17; 8:45 am]            continue work on developing                           Division, Office of Protected Resources,
                                                BILLING CODE 3510–13–P                                  recommendations on program policies                   NMFS, 1315 East-West Highway, Room
                                                                                                        and operations to be reviewed by the                  13705, Silver Spring, MD 20910; phone
                                                                                                        Council’s Citizen Science Committee.                  (301) 427–8401; fax (301) 713–0376.
                                                DEPARTMENT OF COMMERCE                                  Public comment will be accepted at the                   Written comments on this application
                                                                                                        beginning of the meeting.                             should be submitted to the Chief,
                                                National Oceanic and Atmospheric
                                                Administration                                             Items to be addressed during these                 Permits and Conservation Division, at
                                                                                                        meetings:                                             the address listed above. Comments may
                                                RIN 0648–XF849                                                                                                also be submitted by facsimile to (301)
                                                                                                        1. Discuss work on tasks in the Terms                 713–0376, or by email to
                                                Fisheries of the South Atlantic; South                       of Reference                                     NMFS.Pr1Comments@noaa.gov. Please
                                                Atlantic Fishery Management Council;                    2. Other Business                                     include the File No. in the subject line
                                                Public Meetings                                                                                               of the email comment.
                                                                                                        Special Accommodations                                   Those individuals requesting a public
                                                AGENCY:  National Marine Fisheries                                                                            hearing should submit a written request
                                                Service (NMFS), National Oceanic and                      These meetings are physically
                                                                                                                                                              to the Chief, Permits and Conservation
                                                Atmospheric Administration (NOAA),                      accessible to people with disabilities.               Division at the address listed above. The
                                                Commerce.                                               Requests for auxiliary aids should be                 request should set forth the specific
                                                ACTION: Notice of public meetings.                      directed to the council office (see                   reasons why a hearing on the
                                                                                                        ADDRESSES) 3 days prior to the meeting.               application(s) would be appropriate.
                                                SUMMARY:  The South Atlantic Fishery                      Note: The times and sequence specified in           FOR FURTHER INFORMATION CONTACT:
                                                Management Council (Council) will                       this agenda are subject to change.                    Shasta McClenahan or Amy Hapeman,
                                                hold a meeting of its Citizen Science
                                                                                                                                                              (301) 427–8401.
                                                Advisory Panel Projects/Topics                            Authority: 16 U.S.C. 1801 et seq.
                                                                                                                                                              SUPPLEMENTARY INFORMATION: The
                                                Management Action Team via webinar.
                                                                                                          Dated: November 17, 2017.                           subject amendments to the permits
                                                DATES: The Projects/Topics Management
                                                                                                        Tracey L. Thompson,                                   listed below are requested under the
                                                Action Team meeting will be held on                                                                           authority of the Marine Mammal
                                                Monday, December 11, 2017 at 3 p.m.                     Acting Deputy Director, Office of Sustainable
                                                                                                                                                              Protection Act of 1972, as amended (16
sradovich on DSK3GMQ082PROD with NOTICES




                                                The meeting is scheduled to last                        Fisheries, National Marine Fisheries Service.
                                                                                                        [FR Doc. 2017–25367 Filed 11–22–17; 8:45 am]          U.S.C. 1361 et seq.), the regulations
                                                approximately 90 minutes. Additional                                                                          governing the taking and importing of
                                                Action Team webinar and plenary                         BILLING CODE 3510–22–P
                                                                                                                                                              marine mammals (50 CFR part 216), the
                                                webinar dates and times will publish in                                                                       Endangered Species Act of 1973, as
                                                a subsequent issue in the Federal                                                                             amended (16 U.S.C. 1531 et seq.), and
                                                Register.                                                                                                     the regulations governing the taking,
                                                ADDRESSES:                                                                                                    importing, and exporting of endangered


                                           VerDate Sep<11>2014   18:19 Nov 22, 2017   Jkt 244001   PO 00000   Frm 00006   Fmt 4703   Sfmt 4703   E:\FR\FM\24NON1.SGM   24NON1



Document Created: 2017-11-22 23:34:11
Document Modified: 2017-11-22 23:34:11
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice.
DatesInterested parties must contact NIST to request a letter of interest template to be completed and submitted to NIST. Letters of interest will be accepted on a first come, first served basis. Collaborative activities will commence as soon as enough completed and
ContactMr. William Newhouse via email to [email protected]; by telephone (301) 975-0232; or by mail to National Institute of Standards and Technology, NCCoE; 9700 Great Seneca Highway, Rockville, MD 20850. Additional details about the Hospitality Sector program are available at https://nccoe.nist.gov/ projects/use-cases/securing-property-management-systems.
FR Citation82 FR 55802 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR