Overview
ISO 7498-2:1989 - Information processing systems - OSI Basic Reference Model - Part 2: Security Architecture defines a concise, architecture-level description of security services and mechanisms within the Open Systems Interconnection (OSI) Reference Model. It extends ISO 7498 to cover secure communications between open systems by identifying basic security services, related mechanisms, and the positions (layers) in the OSI model where they may be provided. The standard is conceptual - not an implementation specification and not intended as a conformance test.
Key Topics
- Security services: Core services described include authentication, access control/authorization, confidentiality, data integrity, availability, and non-repudiation (digital signatures, audit).
- Security mechanisms: Specifies mechanisms such as encipherment (encryption), digital signatures, cryptographic checkvalues, credentials, security labels, capabilities, and audit trails.
- Encipherment models: Distinguishes end-to-end encipherment (encrypt at source, decrypt at destination) vs link-by-link encipherment (encrypt per link), and discusses implications for relay entities.
- Layer placement: Details recommended placements of services/mechanisms across OSI layers - Physical, Data Link, Network, Transport, Session, Presentation, Application - and explains layering principles and invocation models.
- Security management: Covers security management functions, security management information base (SMIB) concepts, and lifecycle activities such as key management, audit management, and policy enforcement.
- Threat model & terminology: Defines passive/active threats, masquerade, denial of service, manipulation detection, and related vocabulary to unify architecture discussions.
Applications and Who Uses It
ISO 7498-2 is targeted at architects and professionals designing secure communication protocols and standards, including:
- Standards developers and protocol designers who need an architectural framework for specifying security features.
- Network and cybersecurity architects building layered security solutions aligned with OSI principles.
- Security engineers evaluating where to place encryption, authentication, and audit functions.
- Governance, risk, and compliance teams using the terminology and service taxonomy for security policy design.
- Educators and researchers teaching foundational network-security architecture concepts.
Practical uses include guiding protocol specification, informing design decisions about end-to-end vs link-level protection, and defining management requirements for keys and audit data - all without prescribing implementation details.
Related Standards
- ISO 7498 - OSI Basic Reference Model (foundation)
- ISO 7498-4 - OSI Management Framework (MIB concepts)
- ISO 8648 - Internal organization of the Network Layer
- ISO 7498/Add.1 - Connectionless-mode Transmission
Keywords: ISO 7498-2, OSI Security Architecture, Open Systems Interconnection, security services, encipherment, key management, authentication, access control, security management.