Overview
ISO/IEC 11586-6:1997 specifies the Protocol Implementation Conformance Statement (PICS) proforma for the Protecting Transfer Syntax used in Open Systems Interconnection (OSI) generic upper‑layer security. Published jointly with ITU‑T (identical to ITU‑T Rec. X.835), this part of the ISO/IEC 11586 series provides the standardized template and completion instructions that implementers, test laboratories and procurers must use to declare and assess conformance to the protecting transfer syntax defined in ISO/IEC 11586‑4 / ITU‑T X.833 and related security transformations in ISO/IEC 11586‑1 (Annex D) / ITU‑T X.830.
Key topics and requirements
- PICS proforma template (Annex A): A self‑contained proforma designed for testing and procurement that implementers must complete to claim conformance.
- Completion rules and identification: Guidance on required entries such as supplier/implementation identification, date of statement, contact information, and relationship to system conformance statements.
- Notation and response model: Standardized Status values (M, O, n/a, conditional, qualified optional) and Support entries (Y/N/–) for consistent interpretation and automated processing.
- Unique numbering scheme: Row and subitem numbering conventions for unambiguous referencing of PICS responses during testing and certification.
- Protocol details captured: Items to report include supported PDV (Presentation Data Value) structures (First PDV explicit/external, Subsequent PDV), fields such as Transformation Id, static/dynamic unprotected parameters, Xformed Data, and establishment of encoding/decoding rules.
- Security transformations catalog: Reporting support for named transformations (Directory Encrypted, Directory Signed, Directory Signature, GULS Signed/Signature) as defined in Part 1 Annex D.
- Conformance framework alignment: Conformance and proforma structure follow ITU‑T Rec. X.291 and ISO/IEC 9646‑2 guidance for conformance testing.
Applications and who uses it
- Protocol implementers and vendors: Complete the PICS to declare which protecting transfer syntax features and security transformations are implemented.
- Conformance/testing laboratories: Use the proforma to verify implementation claims and perform OSI conformance testing against ISO/IEC 11586‑4 requirements.
- Procurement and system integrators: Require completed PICS proformas to ensure interoperability and to specify security capabilities in procurement contracts.
- Certification bodies and auditors: Validate completeness and accuracy of conformance evidence for product certification and compliance audits.
Related standards
- ISO/IEC 11586‑1 (ITU‑T X.830) - Overview, models and notation (Annex D transformations)
- ISO/IEC 11586‑4 (ITU‑T X.833) - Protecting transfer syntax specification (protocol to be declared)
- ISO/IEC 9646‑2 and ITU‑T X.291 - Abstract test suite / PICS guidance and conformance testing methodology
- ITU‑T X.210 / ISO/IEC 10731 - OSI service conventions referenced for descriptive conventions
Keywords: ISO/IEC 11586-6:1997, PICS proforma, Protecting transfer syntax, Open Systems Interconnection, ITU‑T X.833, conformance testing, security transformations, Protocol Implementation Conformance Statement.