Overview - ISO/IEC 10181-5:1996 (Confidentiality framework)
ISO/IEC 10181-5:1996 defines a general framework for confidentiality services within Open Systems Interconnection (OSI). Published as part of the ISO/IEC 10181 series and aligned with ITU‑T Recommendation X.814, this standard describes concepts, classes of mechanisms, required management functions, and the interaction of confidentiality with other security services. It is focused on protecting information from unauthorized disclosure (including traffic‑flow confidentiality) rather than prescribing specific protocols or cryptographic algorithms.
Key topics and technical requirements
- Scope and purpose
- Framework for confidentiality in information retrieval, transfer and management across open systems (e.g., databases, distributed applications, ODP, OSI).
- Core concepts
- Definitions of confidentiality‑protected‑environment, confidentiality‑protected‑data / information, and operations: hide (apply protection) and reveal (remove protection).
- Importance of protecting control information (keys, RCI/HCI/RCI - Hiding/ Revealing Confidentiality Information).
- Classes of confidentiality services
- Protection of data semantics; semantics plus attributes (existence, size, timestamps); and semantics, attributes plus derivable information.
- Threat models
- Distinction between external and internal threats, and implications for service design (e.g., access controls, covert channels).
- Mechanisms and properties
- Generic mechanism classes described (clause references for facilities and classes). The framework is algorithm‑agnostic - it does not standardize cryptographic algorithms but notes some mechanisms depend on algorithm properties.
- Concepts such as overlapped protected environments, commutativity of hide/reveal when moving data between environments for continuous protection.
- Management and interaction
- Identification of management requirements to support confidentiality services and interaction with authentication, access control, integrity and audit frameworks.
Practical applications and users
Who uses ISO/IEC 10181-5:
- Security architects and systems designers defining confidentiality requirements for distributed systems.
- Standards developers and product vendors mapping confidentiality services into protocols or APIs.
- Network and cloud engineers designing data‑in‑transit and data‑at‑rest protections (including traffic‑flow confidentiality planning).
- Compliance officers and risk managers who need a common vocabulary and framework for confidentiality policies.
How it’s applied:
- As a reference framework when specifying confidentiality requirements in system designs or standards.
- To classify required confidentiality services and select appropriate mechanisms (e.g., cryptographic transforms, access controls, physical protections).
- To guide security management planning (key management, overlap of protected environments, threat model selection).
Related standards
- ISO/IEC 10181 series (Parts 1–7), ITU‑T X.814, ITU‑T X.810 (overview), X.812 (access control), X.273/X.274 (network/transport layer security).