GB/T 18794.3-2003 in English
VALIDInformation technology—Open Systems Interconnection—Security frameworks for open systems—Part 3:Access control framework
- Issued on:2003-01-01
- Implemented on:2004-08-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$524.00
| Standard No: | GB/T 18794.3-2003 |
| Document status: | VALID |
| Title in English: | Information technology—Open Systems Interconnection—Security frameworks for open systems—Part 3:Access control framework |
| Title in Chinese: | 信息技术 开放系统互连 开放系统安全框架 第3部分:访问控制框架 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2003-01-01 |
| Implemented on: | 2004-08-01 |
| ICS Classification: | 35.100.01-Open systems interconnection in general |
| Chinese Classification: | L79-Opening and system interconnection of computer |
| Professional Classification: | GB-National Standard |
| Related Keywords: | open systems security framework
information technology open systems interconnection security frameworks open systems interconnection open systems access control framework scopethis standard |
| Related Topics: | Access control
Access control Information system access control management GBT18794.3 GB/T 18794.3-2003 |
《GB/T 18794.3-2003信息技术 开放系统互连 开放系统安全框架 第3部分:访问控制框架》由TC28(全国信息技术标准化技术委员会)归口,TC28SC6(全国信息技术标准化技术委员会数据通信分会)执行,主管部门为国家标准化管理委员会。
本部分为GB/T18794的第3部分,等同采用国际标准ISO/IEC10181-3:1996《信息技术开放系统互连开放系统安全框架:访问控制框架》(英文版)。
Scope
This standard for an open systems security framework addresses the application of security services in an open systems environment, where the term "open systems" includes such domains as databases, distributed applications, open distributed processing, and open systems interconnection. A security framework involves defining methods for providing protection to systems and objects within systems, and to the interactions between systems. This security framework does not address methodologies for building systems or mechanisms. A security framework addresses sequences of data elements and operations (rather than protocol elements), both of which can be used to obtain specific security services. These security services apply to the entities the systems are communicating with, the data exchanged between the systems, and the data managed by the systems. As far as access control is concerned, access can be either to a system (that is, to entities that are communicating parts of the system) or to the interior of a system. The information items to be presented to obtain access, as well as the order in which such access is requested and the notification of the result of such access are all considered within the scope of this security framework. However, any information items and operations that only depend on specific applications and are strictly limited to local access within a system are not considered within the scope of this security framework. Many applications require security measures to prevent threats to resources, including information generated by open systems interconnection. In the OSI environment, some well-known threats and the security services and mechanisms that can be used to prevent these threats are described in GB/T 9387.2. The process of deciding what resources are allowed to be used in an open systems environment and, where appropriate, preventing unauthorized access is called access control. This clause defines a general framework for providing access control services. This security framework: a) defines the basic concept of access control; b) demonstrates the method of embodying the basic concept of access control to support some recognized access control services and mechanisms; C) defines these services and corresponding access control mechanisms; d ) identify the functional requirements of the protocols that support these access control services and mechanisms; e) identify the management requirements that support these access control services and mechanisms; f) address the interaction of the access control services and mechanisms with other security services and mechanisms. Like other security services, access control can only be provided within the context of a security policy defined for a particular application. The definition of an access control policy is outside the scope of this section, but some characteristics of an access control policy will be discussed in this section. This International Standard does not specify details of protocol exchanges that may be performed by providing an access control service. This International Standard does not specify specific mechanisms to support these access control services, nor does it specify details of security management services and protocols. Many different types of standards can use this framework, including: 1) standards embodying the concept of access control; 2) standards specifying abstract services that contain access control; 3) standards specifying services using access control; 5) Standards specifying access control mechanisms. These standards can use this framework in the following ways: - standard types 1), 2), 3), 4) and 5) can use the terms of this framework; - standard types 2), 3), 4) and 5) Can use the facilities defined in Clause 7 of this Framework; - standard type 5) can be based on the mechanism categories defined in Clause 8.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 44121-2024 in English
Intelligent manufacturing—Requirements of identification and resolution system
2024-05-28 -

GB/T 9387.2-1995 in English
Information processing systems-Open Systems Interconnection-Basic reference Model-Part 2: Security architecture
1995-06-02 -

GB/T 17965-2000 in English
Information technology--Open Systems Interconnection--Upper layers security model
2000-01-03 -

GB/T 35299-2017 in English
Information technology―Open systems interconnection―Object identifier resolution system
2017-12-29 -

GB/T 16652-1996 in English
Open document architecture(ODA) and inter change format-Document structures
1996-01-02