Overview
ISO/IEC 10164-8:1993 - "Information technology - Open Systems Interconnection - Systems Management: Security audit trail function" defines the service and protocol needed to support security audit trail reporting in an OSI systems management environment. Positioned in the application layer, the standard establishes user requirements for recording and reporting security-related events, specifies the service primitives and parameters, defines the required protocol elements (including Abstract Syntax), and sets out conformance requirements and relationships with other systems management functions.
Key topics and requirements
- Service definition: Formal description of the Security Audit Trail Reporting Service and its primitives (parameters marked mandatory, optional, conditional, or mapped to CMIS).
- Protocol specification: Elements of procedure, Abstract Syntax (ASN.1 references), and negotiation rules for the security audit trail functional unit.
- Management information: Defines the management information (MIDS) and managed objects required to represent audit trail data and control log operations.
- Relationships to other functions: Integration points with alarm reporting, event report management, log control and other ISO/IEC 10164 parts.
- Conformance: General and dependent conformance classes, PICS (Protocol Implementation Conformance Statement) and related proformas (MCS, MOCS, MIDS, PICS) for testing and compliance.
- Normative references: Ties to CMIS/CMIP (ISO/IEC 9595), Abstract Syntax Notation One (ASN.1), OSI management framework (ISO/IEC 7498-4), and security architecture (ISO 7498-2 / X.800).
Practical applications
- Implementing reliable audit logging for security administration in distributed OSI-based systems.
- Enabling systems to exchange audit records between managed nodes and central management applications or security information stores.
- Providing a standard basis for conformance testing and interoperability between management agents and managers.
- Serving as a reference for designing audit-related managed objects, notifications, and protocol mappings in enterprise management solutions.
Who should use this standard
- System and network vendors implementing OSI-based management agents and managers.
- Security architects and administrators designing audit trail policies and integration with management systems.
- Integrators and software developers building interoperable management applications and log control modules.
- Test labs and standards bodies performing conformance verification (PICS/MOCS/MIDS).
Related standards
- ISO/IEC 9595 (CMIS), ISO/IEC 8824–8825 (ASN.1/BER), ISO/IEC 10040 (Systems management overview), ISO/IEC 10164 (other parts: alarm reporting, log control, event reports), ISO/IEC 7498-2/4 (Basic Reference Model - security & management).
Keywords: ISO/IEC 10164-8:1993, security audit trail, systems management, OSI, audit log, CMIS, ASN.1, conformance, PICS, managed objects.