Information technology — Open Systems Interconnection — Systems Management: Security audit trail function

Establishes user requirements for the service definition needed to support the security audit trail reporting function, defines the service provided by the security audit trail reporting function, specifies the protocol that is necessary in order to provide the service, defines the relationship between the service and management notifications, defines relationships with other systems management functions, specifies conformance requirements.

Technologies de l'information — Interconnexion de systèmes ouverts — Gestion-système: Fonction de sécurité de l'expertise de l'historique

General Information

Status
Published
Publication Date
16-Jun-1993
Current Stage
9093 - International Standard confirmed
Start Date
29-Jul-2008
Completion Date
14-Feb-2026

Relations

Effective Date
06-Jun-2022
Effective Date
15-Apr-2008

Overview

ISO/IEC 10164-8:1993 - "Information technology - Open Systems Interconnection - Systems Management: Security audit trail function" defines the service and protocol needed to support security audit trail reporting in an OSI systems management environment. Positioned in the application layer, the standard establishes user requirements for recording and reporting security-related events, specifies the service primitives and parameters, defines the required protocol elements (including Abstract Syntax), and sets out conformance requirements and relationships with other systems management functions.

Key topics and requirements

  • Service definition: Formal description of the Security Audit Trail Reporting Service and its primitives (parameters marked mandatory, optional, conditional, or mapped to CMIS).
  • Protocol specification: Elements of procedure, Abstract Syntax (ASN.1 references), and negotiation rules for the security audit trail functional unit.
  • Management information: Defines the management information (MIDS) and managed objects required to represent audit trail data and control log operations.
  • Relationships to other functions: Integration points with alarm reporting, event report management, log control and other ISO/IEC 10164 parts.
  • Conformance: General and dependent conformance classes, PICS (Protocol Implementation Conformance Statement) and related proformas (MCS, MOCS, MIDS, PICS) for testing and compliance.
  • Normative references: Ties to CMIS/CMIP (ISO/IEC 9595), Abstract Syntax Notation One (ASN.1), OSI management framework (ISO/IEC 7498-4), and security architecture (ISO 7498-2 / X.800).

Practical applications

  • Implementing reliable audit logging for security administration in distributed OSI-based systems.
  • Enabling systems to exchange audit records between managed nodes and central management applications or security information stores.
  • Providing a standard basis for conformance testing and interoperability between management agents and managers.
  • Serving as a reference for designing audit-related managed objects, notifications, and protocol mappings in enterprise management solutions.

Who should use this standard

  • System and network vendors implementing OSI-based management agents and managers.
  • Security architects and administrators designing audit trail policies and integration with management systems.
  • Integrators and software developers building interoperable management applications and log control modules.
  • Test labs and standards bodies performing conformance verification (PICS/MOCS/MIDS).

Related standards

  • ISO/IEC 9595 (CMIS), ISO/IEC 8824–8825 (ASN.1/BER), ISO/IEC 10040 (Systems management overview), ISO/IEC 10164 (other parts: alarm reporting, log control, event reports), ISO/IEC 7498-2/4 (Basic Reference Model - security & management).

Keywords: ISO/IEC 10164-8:1993, security audit trail, systems management, OSI, audit log, CMIS, ASN.1, conformance, PICS, managed objects.

Buy Documents

Standard

ISO/IEC 10164-8:1993 - Information technology -- Open Systems Interconnection -- Systems Management: Security audit trail function

English language (26 pages)
sale 15% off
Preview
sale 15% off
Preview

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

NYCE

Mexican standards and certification body.

EMA Mexico Verified

Sponsored listings

Frequently Asked Questions

ISO/IEC 10164-8:1993 is a standard published by the International Organization for Standardization (ISO). Its full title is "Information technology — Open Systems Interconnection — Systems Management: Security audit trail function". This standard covers: Establishes user requirements for the service definition needed to support the security audit trail reporting function, defines the service provided by the security audit trail reporting function, specifies the protocol that is necessary in order to provide the service, defines the relationship between the service and management notifications, defines relationships with other systems management functions, specifies conformance requirements.

Establishes user requirements for the service definition needed to support the security audit trail reporting function, defines the service provided by the security audit trail reporting function, specifies the protocol that is necessary in order to provide the service, defines the relationship between the service and management notifications, defines relationships with other systems management functions, specifies conformance requirements.

ISO/IEC 10164-8:1993 is classified under the following ICS (International Classification for Standards) categories: 35.100.70 - Application layer. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/IEC 10164-8:1993 has the following relationships with other standards: It is inter standard links to ISO/IEC 10164-8:1993/Cor 3:1999; is excused to ISO/IEC 10164-8:1993/Cor 3:1999. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

ISO/IEC 10164-8:1993 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


INTERNATIONAL
ISOJIEC
STANDARD
10164-8
First edition
1993-06-15
Information technology - Open Systems
Interconnection - Systems Management:
Security audit trail function
Technologies de I’informa tion - Interconnexion de systemes ouverts -
Ges tion-sys tkme: Fonction de sbcurit6 de I’expertise de I’his torique
Reference number
ISO/IEC 101649kl993 (E)
Contents
Page
1 Scope . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
2 Normative references . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Identical Recommendations I International Standards . . . . . . . . . . . . . . . . . .
2.1
2.2 Paired Recommendations I International Standards equivalent in
technical content . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
2.3 Additional references
3 Definitions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Basic reference model definitions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
3.1
..........................................
3.2 Security architecture definitions
...................................... 3
3.3 Management framework definitions
Systems management overview definitions .
34 .
..........................
35 . Event report management function definitions
...................................... 4
Security alarm reporting definitions
3.6
Log control definitions .
3.7
......................................
38 . OS1 conformance testing definitions
4 Abbreviations .
5 Conventions . .
6 Requirements .
.............................................................................
7 Model
8 Generic definitions .
.......................................................
8.1 Generic notifacations
............................................................
8.2 Managed Object
.............................................. 7
8.3 Imported generic definitions
8.4 Compliance .
0 ISO/IEC 1993
All rights reserved. No patt of this publication may be reproduced or utilized in any form or by any
means, electronie or mechanical, including photocopying and microf’ilm, without permission in writing
from the publisher.
ISO/lEC Copyright Office l Case postale 56 l CH-121 1 Geneve 20 l Switzerland
Printed in Switzerland
ii
1S0/IEC10164=8:1993(E)
................................................................
9 Service definition
9.1 Introduction .
......................................
9.2 Security audit trail reporting Service
..................................................................
10 Functional units
11 Protocol .
...................................................
11.1 Elements of procedure
...........................................................
11.2 Abstract Syntax
........... 9
11.3 Negotiation of security audit trail reporting functional unit
.............................................
12 Relationships with other functions
.....................................................................
13 Conformance
............................... 10
13.1 General conformance class requirements
............................
13.2 Dependent conformance class requirements
.................
13.3 Management information conformance requirements
........................................................
13.4 PICS requirements
Annexes
........................................
A Definition of management information
B MCS proforma .
.................................................................
C MOCS proforma
..................................................
D MIDS (notification) proforma
E PICS proforma .
..............................
Relationship with the security audit framework
F
. . .
ISO/IEClOl64-8:1993(E)
Foreword
ISO (the International Organization for Standardization) and IEC (the Inter-
national Electrotechnical Commission) form the specialized System for world-
wide standardization. National bodies that are members of ISO or IEC participate
in the development of International Standards through technical committees
established by the respective organization to deal with particular fields sf
technical activity. ISO and IEC technical committees collaborate in Felds of
mutual interest. Other international organizations, governmental and non-
governmental, in liaison with ISO and IEC, also take part in the work.
In the field of information technology, ISO and IEC have established a joint
technical committee, ISOAEC JTC 1. Draft International Standards adopted by
the joint technical committee are circulated to national bodies for voting. Publi-
cation as an International Standard requires approval by at least 75% of the
national bodies casting a vote.
International Standard ISO/IEC 10164-8 was prepared by Joint Technical Com-
mittee ISOAEC JTC 1, Informatiort te&&gy, in collaboration with the CCI’IT.
The identical text is published as CCI’IT Recommendation X.740.
ISO/IEC 10164 consists of the following Parts, under the general title Infor-
mation technology - Open Systems lnterconnection - Systems Management :
-
Part 1: Object management function
-
Part 2: Stute management function
-
Part 3: Attributes for representing relationships
-
Part 4: Alarm reporting function
- Part 5: Event report management function
-
Part 6: Log control function
-
Part 7: Security alarm reporting function
- Part 8: Security audit trailfunction
-
Part 9: Objects and attributes for access control
- Part 10: Accounting meterfunction
-
Part 11: Workload monitoring function
- Part 12: Test managementfunction
-
Part 13: Summarization function
- Part 14: Confidence and diagnostic test categories
Annexes A, B, C, D and E form an integral part of this part of ISO/IEC 10164.
Annex F is for information only.

ISO/IEC 10164~8:1993 (E)
Introduction
ISO/IEC 10164 is a multipart Standard developed according to ISO 7498 and
ISO/IEC 7498-4. ISO/IEC 10164 is related to the following International Stan-
dards
- ISO/IEC 9595 : 1991, Information technology - Open Systems Interconnec-
tion - Common management information Service definition;
- ISO/IEC 9596 : 1991, Information technology - Open Systems Interconnec-
tion - Common management information protocol;
- ISO/IEC 10040 : 1992, Information technology - Open Systems Interconnec-
tion - Systems management overview;
- ISO/IEC 10165 : 1992, Information technology - Open Systems Interconnec-
tion - Structure of management informution.

This page intentionally left blank

ISO/IEC 10164-8 : 1993 (E)
INTERNATIONAL STANDARD
CCITI’ RECOMMENDATION
OPEN SYSTEMS INTERCONNECTION -
INFORMATION TECHNOLOGY -
SYSTEMS MANAGEMENT: SECURITY AUDIT TRAIL FUNCTION
1 Scope
‘Ibis Recommendation I International Standard defines the security audit trail function. The security audit trail function
is a Systems management function which may be used by an application process in a centralized or decentrahzed
management environment to exchange information and commands for the purpose of Systems management, as defmed
by CCITT Rec. X.700 I ISO 7498-4. This Recommendation I International Standard is positioned in the application
layer of CCI’IT Rec. X.200 I ISO 7498 and is defined according to the model provided by ISO/IEC 9545. The role of
1 .
Rec. X.701 I ISO/IEC 10040.
Systems management functions is described by CCITI
This Recommendation I International Standard
Service defmition needed to support the security audit trail
- establishes user requirements for the
reporting function;
defines the Service provided by the security audit trail reporting function;
-
specifies the protocol that is necessary in Order to provide the Service;
-
defines the relationship between the Service and management notifications;
-
defines relationships with other Systems management functions;
specifies conformance requirements.
This Recommendation I International Standard does not define
-
a security audit, nor how to perform one. A security audit may be used to assist in assessing the
effectiveness of a security policy. The security policy identifies the categories of security-related events
that require auditing, and the location of the security audit trail log in which they are to be recorded;
the nature of any implementation intended to provide the security audit trail function;
- the occasions where the use of the security audit trail function is appropriate;
- the Services necessary for the establishment, normal and abnormal release of a management association;
-
any other notifications defmed by other Recommendations l International Standards which may be of
interest to a security administrator.
2 Normative references
The following CCITI’ Recommendations and International Standards contain provisions which, through reference in
this text, constitute provisions of this Recommendation I International Standard. At the time of publication, the editions
indicated were valid. All Recommendations and Standards are subject to revision, and Parties to agreements based on
this Recommendation I International Standard are encouraged to investigate the possibility of applying the most recent
editions of the Recommendations and Standards listed below. Members of IEC and ISO maintain registers of currently
valid International Standards. The CCITT Secretariat maintains a list of currently valid CCITT Recommendations.
CCITT Rec. X.740 (1992 E)
ISOLCEC 10164-8 : 1993 (E)
21 Identical Recommendations I Internationall Standards
l
- CCITI’ Recommendation X.701 (1992) I ISO/IEC 10040:1992, Information technology - Open Systems
Interconnection - Systems management overview.
- CCITT Recommendation X.721 (1992) I ISO/IEC 101652:1992, Information technology - Open
Systems Interconnection - Structure of management information: Definition of management information.
- CCITI’ Recommendation X.722 (1992) I ISO/IEC 10165-4:1992, Information technology - Open
Systems Interconnection - Structure of management information: Guidelines for the definition of
managed objects.
-
CCITI’ Recommendation X.724l) I ISO/IEC 10165.611, Information technology - Open Systems
-
Interconnection Structure information: Requirements and guidelines
of management
for
implementation conformance Statement proformas associated with management information.
CCITI’ Recommendation X.733 (1992) I ISO/IEC 10164-4:1992, Information technology - Open
Systems Interconnection - Systems management: Alarm reportingJirnction.
-
CCITT Recommendation X.734 (1992) I ISO/IEC 10164-5:1993, Information technology - Open
Systems Interconnection - Systems management: Event report management function.
-
CCITI’ Recommendation X.735 (1992) I ISO/IEC 10164-6:1993, Information technology - Open
Systems Interconnection - Systems management: Log controljunction.
CCITT Recommendation X.736 (1992) I ISO/IEC 10164-7:1992, Information technology - Open
Systems Interconnection - Systems management: Security alarm reporting finction.
22 l Paired Recommendations 1 International Standards equivalent in technical content
- CCITT Recommendation X.200 (1988), Reference Model of Open Systems Interconnection for CCITT
applications.
ISO 7498: 1984, Information processing systems - Open Systems Interconnection - Basic Reference
Model.
- CCITT Recommendation X.208 (1988), Specification of Abstract Syntax Notation One (ASN.1).
ISOIIEC 8824: 1990, Information technology - Open Systems Interconnection - Specijication of Abstract
Syntax Notation One (ASN.1).
- CCITT Recommendation X.209 (1988), Specification of basic encoding rules for Abstract Syntax
Notation (ASN.1).
ISOIIEC 8825: 1990, Information technology - Open Systems Interconnection - Specification of Basic
Encoding Rules for Abstract Syntax Notation One (ASN. I).
- CCITT Recommendation X.210 (1988), Open Systems Interconnection layer Service definition
conventions.
ISO/TR 8509: 1987, Information processing systems - Open Systems Interconnection - Service
conventions.
- CCITT Recommendation X.290 (1992), OSI conformance testing methodology and fiamework for
protocol Recommendations for CCITT applications - General concepts.
ISO/IEC 9646-1: 1991, Information technology - Open Systems Interconnection - Confomtance testing
methodology andfiamework - Part I: General concepts.
-
CCITT Recommendation X.291 (1992), OSI conformance testing methodology and framework for
protocol Recommendations for CCITT applications - Abstract test Suite specification.
ISOIIEC 9646-2 : 1991, Information technology - Open Systems Interconnection - Conformance testing
methodology andframework - Part 2: Abstract test Suite spect@ation.
CCITT Recommendation X.700 (1992), Management framework definition for Open Systems
Interconnection for CCITT applications.
ISOLIEC 7498-4: 1989, Information processing systems
- Open Systems Interconnection - Basic
Reference Model - Part 4: Managementframework.
0 Presently at the Stage of draft.
2 CCI’IT Rec. X.740 (1992 E)
ISO/IF,C 10164-8 : 1993 (E)
-
CCI’IT Recommendation X.7 10 (199 l), Common management information Service definition for CCITT
.
applications.
ISO/IEC 9595: 199 1, Information technology - Open Systems Interconnection - Common management
information Service definition.
- CCI‘IT Recommendation X.800 (1991), Security architecture for Open Systems Interconnection for
CCITT applications.
Open Systems Interconnection - Basic Reference
ISO 7498-2: 1989, Information processing systems -
Model - Part 2: Security architecture.
Additional references
23 0
-
ISO/IEC 9545: 1989, Information technology - Open Systems Interconnection - Application Layer
structure.
- Open Systems Interconnection - Security frameworks -
- ISO/IEC 10181-71), Information technology
Part 7: Security auditframework.
3 Definitions
For the purposes of this Recommendation I International Standard, the following defmitions apply.
Basic reference model definitions
31 0
This Recommendation I International Standard makes use of the following term defined in CCITI’ Rec. X.200 I
ISO 7498:
open System.
Securi ty archi tec ture defini tions
32 0
This Recommendation I International Standard makes use of the following terms defined in CCITT Rec. X.800 I
ISO 7498-2:
security audit trail;
a)
b) security policy.
33 0 Management framework definitions
This Recommendation I International Standard makes use of the following terqx defined in CCITT Rec. X.700 I
ISO 7498-4:
managed Object.
34 0 Systems management overview definitions
This Recommendation I International Standard makes use of the following terms defined in CCITT Rec. X.701 I
ISO/IEC 10040:
agent role;
a)
b) dependent conformance;
c) general conformance;
management domain;
d)
manager role;
d
notification;
f)
Systems management functional unit.
t9
l) Presently at the Stage of draft.
CCITI’ Rec. X.740 (1992 E)
ISO/IEC 10164-8 : 1993 (E)
35 . Event report management definitions
This Recommendation I International Standard makes use of the following term defined in CCITT Rec. X.734 i
ISO/IEc 10164-5:
discriminator.
l Security alarm reporting definitions
This Recommendation I International Standard makes use of the following term defmed in CCITI’ Rec. X.736 I
ISO/IEiC 10164-7:
security-related event.
37 . Log control definitions
This Recommendation I International Standard makes use of the following terms defined in CCITT Rec. X.735 I
ISO/IEE 10164-6:
;
a) 1%
b) log record.
38 l OS1 conformance testing definitions
This Recommendation I International Standard makes use of the following terms defined in CCITT Rec. X.290 I
ISO/IEC 9646- 1:
a) PICS proforma;
b) protocol implementation conformance Statement (PICS);
System conformance Statement.
C>
4 Abbreviations
ASN. 1 Abstract Syntax Notation One
CMIS Common Management Information Services
Conf Confmation
Ind Indication
MAPDU Management Application Protocol Data Unit
MCS Management conformance summary
MIDS Management information definition Statement
MOCS Managed Object conformance Statement
OS1 Open Systems Interconnection
PICS Protocol implementation conformance Statement
Request
Req
Response
RsP
SMAPM Systems Management Application Protocol Machine
5 Conventions
This Recommendation I International Standard defkes Services for the security audit trail function using the
descriptive conventions defined in CCITI’ Rec. X.210 I ISO/TR 8509. In clause 9, the definition of each Service
includes a table that lists the Parameters of its primitives. For a given primitive, the presence of each Parameter is
described by one of the following values:
M the Parameter is mandatory;
(=) the value of the Parameter is equal to the value of the Parameter in the column to the left;
U the use of the Parameter is a service-user Option;
4 CCITT Rec. X.740 (1992 E)
ISO/IEC 10164-8 : 1993 (E)
- the Parameter is not present in the interaction described by the primitive concemed;
C the Parameter is conditional. The condition(s) are defined by the text which describes the Parameter;
P subject to the constraints imposed on the Parameter by CCITT Rec. X.710 I ISO/IEC 9595.
NOTE - The Parameters that are marked “P” in Table 1 are mapped directly onto the corresponding parameters of the
CMIS Service primitive, without changing the semantics or Syntax of the Parameters. The remaining Parameters are used to
construct an MAPDU.
Requirements
The security management user requires the ability to record in a security audit trail log, security-related events that
occur in the management domain. The security policy of an open System may require that particular security-related
events be sent to a security audit trail log in the Same or in a different open System.
The types of security-related event that may be subject to security auditing include, but are not limited to
-
connections;
-
disconnections;
-
security mechanism utilization;
management operations; and
-
usage accounting.
The security management user also requires the ability to control the Operation of the security audit trail function.
This Recommendation I International Standard describes the use of Services and techniques to satisfy these
requirements.
7 Model
This Recommendation I International Standard requires that the security-related events shall be logged according to the
procedures defmed in CCITT Rec. X.735 I ISO/IEC 10164-6. The discriminator construct within the security audit trail
log shall be specified so as to permit the Capture of incoming events that the security policy requires to be logged. If
the event reports are to be sent to a different destination, then event forwarding discriminators as defined in CCITI’
Rec. X.734 I ISOLEC 10164-5 shall be created and the destination address shall be set to send the event to the System
where the selected security audit trail log is located. The security audit trail log is a log as defined in CCITT
Rec. X.735 I ISO/IEC 10164-6.
The model for conveying event reports to the System where the security audit trail log is situated is defined in CCITT
Rec. X.734 I ISOLEC 10164-5. The model for the creation and retrieval of entries in the security audit trail log is
defined in CCITT Rec. X.735 1 ISO/IEC 10164-6.
8 Generic definitions
81 l Generic notifications
This Recommendation I International Standard defines a set of generic security audit trail notifications and their
applicable Parameters and semantics.
The set of generic notifications, Parameters and semantics defined by this Recommendation I International Standard
provide the detail for the following Parameters of the M-EVENT-REPORT Service as defined by CCITT Rec. X.710 l
ISO/IEC 9595:
-
event type;
-
event information;
event reply.
All notifications are potential entries in a Systems management log. CCI’IT Rec. X.721 I ISO/IEC 10165-2 defines a
generic event log record Object class from which all entries are derived, the additional information being specified by
the event information and event reply Parameters.
CCITI’ Rec. X.740 (1992 E) 5
ISO/IEC 10164-8 : 1993 (E)
Event type
8.1.1
are defmed
This Parameter defines the type of the security audit trail report. The following event in this
tYPes
Recommendation I International Standard
- Service report: an indication of an even t appertaining to the Provision, denial or recovery of a Service.
Specific Causes for the generation of the event are described in 8.1.2;
- Usage report: an indication of a record which contains information of a statistical nature, relevant to
security.
Other notifications defined in other Recommendations I International Standards (for example, CCITI’ Rec. X.736 I
ISO/IEC 10164-7) may be recorded in the security audit trail log. The notification types (analagous to security audit
trail report types) and their associated Parameters are defined in the appropriate Recommendations I International
Standard.
8.1.2 Event information
The Service report Cause Parameter consitutes the notifkation specific event information.
This Parameter shall be supplied when the event type specifies a Service report, and defines further qualification as to
the probable Cause of the Service report. The value of this Parameter in combination with the value of event type,
determines which Parameters constitute the balance of the Service report, and what the possible values of those
Parameters may be.
Service report Cause values for notifications shall be indicated in the behaviour clause of the Object class definition.
This Recommendation l International Standard defines, for use within the Systems management application context
defined in CCITT Rec. X.701 I ISO/IEC 10040, Service report Causes that have wide applicability across managed
Object classes. These values are registered in Annex A of this Recommendation I International Standard. The syntax of
Service report Causes shall be the ASN.l type Object identifier. Additional Service report Causes, for use within the
Systems management application context defined in CCITT Rec. X.701 l ISO/IEC 10040, may be added to this
Recommendation I International Standard and registered using the registration procedures defined for ASN.1 Object
identifier values in CCITI’ Rec. X.208 I ISO/IEC 8824.
Other Service report Causes, for use within the Systems management application context defmed in CCITT Rec. X.701 I
ISO/lEC 10040, may be defined outside of this Recommendation I International Standard and registered using the
registration procedures defined for ASN.1 Object identifier values in CCITT Rec. X.208 I ISO/IEC 8824.
The following Service report Cause values are defined
-
Request for Service: this value specifies that the notification has been generated because of a request for
the Provision of a Service;
- Denial of Service: this value specifies that the notification has been generated because a request for
Service has been denied;
-
Response from Service: this value specifies that the notification has been generated because a request for
Service has been satisfied;
- Service failure: this value specifies that the notification has been generated because an abnormal
condition that caused the Service to fail, has been detected during the Provision of a Service;
-
Service recovery: this value specifies that the notification has been generated because a Service has
recovered from an abnormal condition;
- Other reason: this value specifies that the notifkation has been generated for reasons other than those
listed above. The actual Cause and other relevant information is specified in the other Parameters of the
report.
8.1.3 Event reply
This Recommendation I International Standard does not specify management information to be used in the event reply
Parameter.
l Managed Object
A security audit trail record is a managed Object class derived from the event log record Object class defined in CCITI’
Rec. X.721 I ISO/IEC 10165-2. The security audit trail record Object class represents information stored in logs
resulting from security audit trail notifications.
6 CCITI’ Rec. X.740 (1992 E)
ISO/IEC 10164-8 : 1993 (E)
Imported generic definitions
83 l
.
The following Parameters are also utilized. These Parameters are defined by CCITI’ Rec. X.733 1 ISO/IEC 10164-4.
- Additional information;
-
Additional text;
- Correlated notifications;
-
Notification identifier.
l Compliance
Managed Object class definitions support the functions defined in this Recommendation I International Standard by
incorporating the specification of the notifications through reference to the notification templates defined in Annex A.
The reference mechanism is defined in CCITI’ Rec. X.722 I ISO/IEC 101654.
A managed Object class definition importing one or more of the security audit trail notifications defmed in this
Recommendation I International Standard is required for each instance of a security audit trail report to select the
security audit trail report type that most closely reflects the real event that leads to the managed Object issuing the
notification. The definition of the managed Object class shall, for each imported notification, specify in the behaviour
clause which of the optional and conditional Parameters are to be utilized, the conditions for their use, and their values.
It is permissible to state that the use of a Parameter remains optional.
9 Service definition
91 l Introduction
Security audit trail notifications provide the ability to report security-related events detected by a managed Object. The
Parameters convey the information relevant to the security audit trail.
92 . Security audit trail reporting Service
The security audit trail reporting Service uses the Parameters defined in clause 8 in addition to the general M EVENT-
REPORT Service Parameters defrned in CCITT Rec. X.710 I ISO/IEC 9595. Table 1 lists the Parameters for the
security audit trail reporting service.
Table 1 - Security audit trail reporting Parameters
Parameter name Reqhd RspKonf
Invoke identifier P P
Mode P
Managed Object class P P
Managed Object instance P P
Event type M
C(=)
Event time P
Event information
Service report Cause C
Notification identifier U
Correlated notifications
U
Additional text U
Additional information U
I
Cumnt time P
Event reply
Errors P
rt
The Event time, Correlated notifkations, and Notification identifier Parameters may be assigned by the managed
Object that emits the notification or by the managed System.
CCITT Rec. X.740 (1992 E)
ISO/IEC 10164-8 : 1993 (E)
10 Functional units
The security audit trail function constitutes a Single Systems management functional unit.
11 Protocoll
11.1 Elements of procedure
11.1.1 Agent role
11.1.1.1 Invocation
The security audit trail reporting procedures are initiated by the security audit trail reporting request primitive. On
receipt of a security audit trail reporting request primitive, the SMAPM shall construct an MAPDU and issue a CMIS
M-EVENT-REPORT request Service primitive with Parameters derived from the security audit trail reporting request
primitive. In the non-confirmed mode, the procedure in 11.1.1.2 does not apply.
11.1.1.2 Receipt of response
On receipt of a CMIS M-EVENT-REPORT confinn Service primitive containing an MAPDU responding to a security
audit trail reporting notification, the SMAPM shall issue a security audit trail reporting confirmation primitive to the
security audit trail reporting Service user with Parameters derived from the CMIS M-EVENT-REPORT tonfirm
Service primitive, thus completing the security audit trail reporting procedure.
NOTE - The SMAPM shall ignore all errors in the received MAPDU. The security audit trail reporting Service user may
ignore such errors, or abort the association as a consequence of such errors.
11.1.2 Manager role
11.1.2.1 Receipt of request
On receipt of a CMIS M-EVENT-REPORT indication Service primitive containing an MAPDU requesting the security
audit trail reporting Service, the SMAPM shall, if the MAPDU is well formed, issue a security audit trail reporting
indication primitive to the security audit trail reporting Service user with Parameters derived from the CMIS
M-EVENT-REPORT indication Service primitive. Otherwise, the SMAPM shall in the confrnned mode construct an
appropriate MAPDU containing notification of the error, and shall issue a CMIS M-EVENT-REPORT response
Service primitive with an error Parameter present. In the non-confmed mode, the procedure in 11.1.2.2 does not
aPPlY*
lL1.2.2 Response
In the confirmed mode, the SMAPM shall accept a security audit trail reporting response primitive and shall construct
an MAPDU confrrming the notification and issue a CMIS M-EVENT-REPORT response Service primitive with the
Parameters derived from the security audit trail reporting response primitive.
11.2 Abstract Syntax
11.2.1 Managed objects
This Recommendation I International Standard defines the following support Object, the abstract syntax of which is
specified in Annex A.
securityAuditTra.ilRecord.
11.2.2 Attributes
Table 2 identif’ies the relationship between the Parameter defined in 8.1.2 and attribute type specification defined in
Annex A.
Table 2 - Attributes
v ,
Parameter Attribute name
Service report Cause serviceReportCause
8 CCITT Rec. X.740 (1992 E)
1s0/IEc 10164-8 : 1993 (E)
11.2.3 Attribute groups
There are no attribute groups defmed by this Systems management function.
11.2.4 Actions
There arc no specific actions defined by this Systems management function.
11.2.5 Notifications
Table 3 identifies the relationship between the notifications defined in 8.1.1 and the notification type specifications
defined in Annex A.
Table 3 - Notifications
Security audit traii type Notification type
serviceReport
Service report
usageReport
Usage report
The abstract syntax referenced by the notification type specifications is carried in the MAPDU.
11.2.6 Service report Causes
Table 4 identifies the relationship between the Service report Causes defined in 8.1.2 and the ASN.l value references
defined in Annex A.
Table 4 - Service report causes
Service report cause ASN.l value reference
I serviceReauest l
Denial of senke serviceDenial
I- I I
IR esDome fkom Service I serviceResponse I
Service failure serviceFahre
I I I
Service recovery serviceRecovery
t er reason otherReason
1 Oh I I
11.3 Negotiation of security audit trail reporting functional unit
This Recommendation 1 International Standard assigns the Object identifier
uoint-iso-ccitt 1x49) function(2) part8(8) functionalUnitPackage(1))
as a value of the ASN.l type FunctionalUnitPackageId defined in CCI’IT Rec. X.701 I ISO/IEC 10040 to use for
negotiating the following functional unit
0 security audit trail reporting functional unit
where the number identifies the bit Position assigned to the functional unit, and the name references the functional unit
as defined in clause 10.
Within the Systems management application context, the mechanism for negotiating the security audit trail reporting
functional unit is described by CCITI’ Rec. X.701 I ISO/IEC 10040.
NOTE - The requirement to negotiate functional units is specified by the application context.
CCITT Rec. X.740 (1992 E) 9
ISO/IEC 10164-8 : 1993 (E)
12 Relationships with other functions
Control of the security audit trail reporting Service is provided by mechanisms specified i
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.

Loading comments...