Overview
ISO/IEC 10181-3:1996 - Access control framework defines a general framework for providing access control in Open Systems Interconnection (OSI) and other open systems. Part of the ISO/IEC 10181 security frameworks (identical to ITU‑T X.812), this standard describes the goals, components, information items and architectural options needed to protect systems and objects from unauthorized operations such as unauthorized use, disclosure, modification, destruction and denial of service.
Key topics and technical elements
- Goals and threat model: purpose of access control to counter unauthorized operations and the threat classes addressed.
- Access control policies: expression categories, groups and roles, security labels, multiple-initiator policies, granularity, inheritance, precedence and default rules; policy management types (fixed, administratively imposed, user-selected) and cross‑domain policy mapping.
- Access control information (ACI): types and bindings including initiator ACI, target ACI, access request ACI, operand ACI, contextual information, and initiator-/target-/request‑bound ACIs.
- Protection of ACI: use of access control certificates and access control tokens to convey authorization data.
- Classification of mechanisms: principal schemes described are ACL (access control list), capability schemes, label‑based schemes and context‑based schemes - with their ACIs and supporting mechanisms and variations.
- Distribution and architecture: incoming, outgoing and interposed control; distribution of components across multiple security domains; forwarding of access control certificates.
- Interactions with other security services: integration with authentication, data integrity, confidentiality, audit and other access‑related services.
- Annexes: practical guidance on certificate exchange, OSI layer use, non‑unique identities, component distribution, rule‑based vs identity‑based policies, and example mechanisms.
Practical applications and users
ISO/IEC 10181-3 is targeted to:
- Security architects, system designers and network engineers who design access control services for distributed and OSI-based systems.
- Standards implementers and vendors building access control mechanisms, tokens and certificate formats.
- Enterprise security teams and auditors defining policy management, policy mapping across domains and compliance requirements.
- Researchers and educators studying canonical access control architectures and interactions with authentication, audit and confidentiality services.
Typical uses include designing interoperable access control services for distributed applications, defining policy expression and mapping for multi‑domain environments, and selecting appropriate mechanisms (ACL, capability, label or context based) for system requirements.
Related standards
- ISO/IEC 10181 family (Parts 1–7) - security frameworks for open systems
- ITU‑T Recommendation X.812 (identical text)
Keywords: ISO/IEC 10181-3, access control framework, Open Systems Interconnection, access control policies, ACL, capability, label-based, access control certificate, ACI, authentication, audit.