Overview
ISO/IEC 10181-6:1996 - Information technology - Open Systems Interconnection - Security frameworks for open systems: Integrity framework - defines a general integrity framework for open systems (OSI). It formalizes the concept of data integrity (the constancy of a data value), describes how integrity services apply to data and sequences of operations, and specifies high-level provisions for delivering integrity services across databases, distributed applications, open distributed processing and OSI environments.
Key topics and technical scope
This part of ISO/IEC 10181 provides a structured treatment of integrity considerations rather than implementation recipes. Major topics include:
- Definitions and scope: formal definitions (integrity-protected channel/environment, shield/unshield, validate) and the intended application domains.
- Types of integrity services and mechanisms: taxonomy of integrity approaches (cryptographic techniques such as digital signatures, seals and encipherment of redundant data; context-based methods such as replication and pre-agreed context; detection/acknowledgement and prevention methods).
- Integrity information and facilities (Clause 7): classes of integrity information (Shield Integrity Information, Modification Detection Integrity Information, Unshield Integrity Information) and operational/management facilities needed to support integrity.
- Integrity policies (Clause 6): policy expression, data and entity characterization, identity-based and rule-based policies.
- Threats and attacks: analysis of threats to integrity and typical integrity attack classes.
- Interactions with other security services: how integrity mechanisms relate to access control, data origin authentication, confidentiality, audit and non‑repudiation.
- Classification and management: classification of mechanisms (clause 8), and management/operational requirements to support integrity provision.
The framework is algorithm‑agnostic - it does not mandate specific cryptographic algorithms (ISO maintains algorithm registration via ISO/IEC 9979).
Practical applications and who uses it
ISO/IEC 10181-6 is useful for:
- Security architects and systems engineers designing integrity controls for distributed systems, databases and network services.
- Standards developers aligning protocol- and service-level integrity definitions with OSI security frameworks.
- Implementers and vendors that need to map product features (digital signatures, message authentication, replication controls) to a recognized integrity taxonomy.
- Auditors and compliance teams assessing whether integrity policies, facilities and management processes meet accepted framework expectations.
Typical applications include protecting configuration data, transaction logs, messages exchanged between systems, and any data whose unauthorized modification would undermine authentication, access control, confidentiality, audit or non-repudiation.
Related standards
- ISO/IEC 10181 series (Parts 1–7): Overview, Authentication, Access Control, Non‑repudiation, Confidentiality, Integrity, Security Audit.
- ISO/IEC 7498-2 / ITU-T X.800 (security architecture)
- ITU-T X.815 (identical text)
- ISO/IEC 9979 (cryptographic algorithm registration)
Keywords: ISO/IEC 10181-6, integrity framework, data integrity, OSI security, integrity services, integrity mechanisms, integrity policies.