CAN CSA-ISO IEC 10181-7-2000 Information technology - Open Systems Interconnection - Security frameworks for open systems Security audit and alarms framework.pdf
《CAN CSA-ISO IEC 10181-7-2000 Information technology - Open Systems Interconnection - Security frameworks for open systems Security audit and alarms framework.pdf》由会员分享,可在线阅读,更多相关《CAN CSA-ISO IEC 10181-7-2000 Information technology - Open Systems Interconnection - Security frameworks for open systems Security audit and alarms framework.pdf(28页珍藏版)》请在麦多课文档分享上搜索。
1、CSA I NT E RN AT ION A1 I - National Standard of Canada CAN/CSA-ISO/1EC 101 81-7-00 (I SO/I EC 1 0 1 81 -7: 1 996) International Standard ISO/IEC 10181-7: 1996 (first edition 1996-08-01) has been adopted without modification as CSA Standard CAN/CSA-ISO/IEC 10181-7-00, which has been approved as a Na
2、tional Standard of Canada by the Standards Council of Canada. ISBN I -55324-088-X March 2000 Information technology - Open Systems Interconnection - Security frameworks for open systems: Security audit and alarms framework Technologies de t in formation - lnterconnexiun de s ystPmes ouverts (OS! - C
3、adres pour la s this remains the continuing responsibility of the accredited standards-development organization. Those who have a need to apply standards are encouraged to use National Standards of Canada whenever practicable. These standards are subject to periodic review; therefore, users are caut
4、ioned to obtain the latest edition from the organization preparing the standard. The responsibility for approving National Standards of Canada rests with the Standards Council of Canada 45 OConnor Street, Suite 1200 Ottawa, Ontario, K1 P 6N7 Canada A National Standard of Canada is a standard which C
5、SA INTERNATIONAL c . Les normes nationales du Canada sont publi6es en versions frangaise et anglaise. Although the intended primary application of this Standard is stated in its Scope, it is important to note that it remains the responsibility of the users to judge its suitability for their particul
6、ar purpose. lnformation technology - Open Systems Interconnection - Security frameworks for open systems: Security audit and alarms framework CAN/CSA-/SO/fC 7 0 7 8 7 -7-00 CAN/CSA-ISO/IEC 101 81 -7-00 Infomalion technology - Open Systems Interconnection - Security jkarneworks for open systems: Secu
7、rity audit and alums pamework CSA Preface Standards development within the Information Technology sector is harmonized with international standards development. Through the CSA Technical Committee on Information Technology (TCIT), Canadians serve as the Canadian Advisory Committee (CAC) on ISO/IEC j
8、oint Technical Committee 1 on Information Technology (ISO/IEC JTCl ) for the Standards Council of Canada (SCC), the IS0 member body for Canada and sponsor of the Canadian National Committee of the IEC. Also, as a member of the International Telecommunication Union (ITU), Canada participates in the I
9、nternational Telegraph and Telephone Con su Ita tive Committee (ITU -T). This International Standard was reviewed by the CSA TClT under the jurisdiction of the Strategic Steering Committee on Information Technology and deemed acceptable for use in Canada. (A committee membership list is available on
10、 request from the CSA Project Manager.) From time to time, ISO/tEC may publish addenda, corrigenda, etc. The CSA TClT will review these documents for approval and publication. For a listing, refer to the CSA Information Products catalogue or CSA /do Update or contact a CSA Sales representative. This
11、 Standard has been formally approved, without modification, by these Committees and has been approved as a National Standard of Canada by the Standards Council of Canada. March 2000 0 CSA lnternational- 2000 All rights reserved. No part of this publication may be reproduced in any form whatsoever wi
12、thout the prior permission of the publisher. ISO/lfC material is reprinted with permission. Inquiries regarding this National Standard of Canada should be addressed to CSA International, 7 78 Rexdale Boulevard, Toronto, Ontario, M9 W 7 R3. March 2000 CSA/7 I NTE R N AT1 0 NAL STANDARD BO/ IEC 10181-
13、7 First edition 1 99608-0 1 Information technology - Open Systems Interconnection - Security frameworks for open systems: Security audit and alarms framework Technologies de I information - Interconnexion de syst - helping ensure that actions can be attributed to the entities responsible for those a
14、ctions; contributing to the deveIopment of improved damage control procedures; confirming compliance with established security policy: reporting infomation that may indicate inadequacies in system controls; and identifying possible required changes in controls, policy and procedures. In this framewo
15、rk, a security audit consists of the detection, collection and recording of various security-related events in a security audit trail and analysis of those events. Both audit and accountability require that information be recorded. A security audit ensures that sufficient infomation is recorded abou
16、t both routine and exceptional events so that later investigations can determine if security violations have occurred and, if so, what information or other resources have been compromised. Accountability ensures that relevant information is recorded about actions performed by users, or processes act
17、ing on their behalf, so that the consequences of those actions can later be linked to the user(s) in question, and the user(s) can be held accountable for his or her actions. Provision of a security audit service can contribute to the provision of accountability. A security alarm is a warning issued
18、 to an individual or process to indicate that a situation has arisen that may require timely action. The purposes of a security alarm service include: - to report real or apparent attempts to violate security; to report various security-related events, including “normal” events; and to report events
19、 triggered by threshold limits being reached. 1v ISO/IEC 10181-7 : 1996 (E) INTERNATIONAL STANDARD ITU-T RECOMMENDATION 1 INFORMATION TECHNOLOGY - OPEN SYSTEMS INTERCONNECTION - SECURITY FRAMEWORKS FOR OPEN SYSTEMS: SECURITY AUDIT AND ALARMS FRAMEWORK Scope This Recommendation I International Standa
20、rd addresses the application of security services in an Open Systems environment, where the term “Open Systems” is taken to include areas such as Database, Distributed Applications, Open Distributed Processing and OSI. The Security Frameworks are concerned with defining the means of providing protec
21、tion for systems and objects within systems, and with the interactions between systems. The Security Frameworks are not concerned with the methodology for constructing systems or mechanisms. The Security Frameworks address both data elements and sequences of operations (but not protocol elements) wh
22、ich are used to obtain specific security services. These security services may apply to the communicating entities of systems as well as to data exchanged between systems, and to data managed by systems. The purpose of security audit and alms as described in this Recommendation I International Stand
23、ard is to ensure that open system-security-related events are handled in accordance with the security poky of the applicable security authority . In particular, this framework: a) b) defines the basic concepts of security audit and alarms; provides a general model for security audit and alarms; and
24、c) identifies the relationship of the Security Audit and Alms service with other security services. As with other security services, a security audit can only be provided within the context of a defined security policy. The Security Audit and Alarms model provided in clause 6 supports a variety of g
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- CANCSAISOIEC1018172000INFORMATIONTECHNOLOGYOPENSYSTEMSINTERCONNECTIONSECURITYFRAMEWORKSFOROPENSYSTEMSSECURITYAUDITANDALARMSFRAMEWORKPDF

链接地址:http://www.mydoc123.com/p-590207.html