Overview
ISO/IEC 11586-5:1997 specifies a Protocol Implementation Conformance Statement (PICS) proforma for the Security Exchange Service Element (SESE) protocol used in generic upper‑layer security for Open Systems Interconnection (OSI). Part 5 of the ISO/IEC 11586 series provides the standardised template, instructions and notation that implementers, test laboratories and procurement bodies use to declare and verify conformance of a protocol implementation to ITU‑T Rec. X.832 / ISO/IEC 11586‑3. The text is published identically as ITU‑T Recommendation X.834.
Key topics and requirements
- PICS proforma structure: A self‑contained annex (Annex A) defines the PICS layout including numbered rows for unique referencing, a two‑column multi‑layout with Status (mandatory/optional/conditional) and Support (Y/N/-) entries, and guidance for completion.
- Conformance rules: A conforming PICS must preserve numbering and ordering, describe an implementation that meets ITU‑T X.832 / ISO/IEC 11586‑3, and include supplier and implementation identification.
- Completion guidance: Instructions cover required fields such as date of statement, implementation details (supplier, implementation name, OS/hardware, contact), and relationships to system conformance statements.
- Detailed content items: The proforma requests protocol details, implemented technical corrigenda, global statement of conformance, supported APDUs and parameters, abstract syntax, application contexts, and supported security exchanges (including directory authentication and negotiation exchanges).
- Testing alignment: The proforma is compliant with conformance testing guidance from ITU‑T X.291 and ISO/IEC 9646‑2 (abstract test suite specification) and references PIXIT concepts for extra test information.
Applications
- Vendors and implementers use the PICS proforma to formally declare which SESE protocol features and options their products implement.
- Test laboratories and certification bodies use completed PICS documents to plan and execute conformance testing and to uniquely reference implementation capabilities.
- Procurement, compliance and security architects use PICS responses to compare products, verify mandatory feature support, and determine interoperability readiness.
Who should use this standard
- Protocol implementers and software/hardware vendors of OSI upper‑layer security mechanisms
- Conformance test laboratories and certification agencies
- Systems integrators and security architects responsible for secure OSI deployments
- Procurement teams requiring standardized evidence of protocol conformance
Related standards
- ISO/IEC 11586 series (Parts 1–6)
- ITU‑T Rec. X.832 (SESE protocol specification)
- ITU‑T Rec. X.830 (overview, models and notation)
- ITU‑T X.291 and ISO/IEC 9646‑2 (conformance testing guidance)
Keywords: ISO/IEC 11586-5:1997, SESE, PICS proforma, Protocol Implementation Conformance Statement, ITU‑T X.832, conformance testing, OSI security.