DICOM PS3.15 2025e - Security and System Management Profiles

A.5.3.9 Network Entry

This message describes the event of a system, such as a mobile device, intentionally entering or leaving the network.

No Participant Objects are needed for this message.

Note

The machine should attempt to send this message prior to detaching. If this is not possible, it should retain the message in a local buffer so that it can be sent later. The mobile machine can then capture audit messages in a local buffer while it is outside the secure domain. When it is reconnected to the secure domain, it can send the detach message (if buffered), followed by the buffered messages, followed by a mobile machine message for rejoining the secure domain. The timestamps on these messages is the time that the event was noticed to have occurred, not the time that the message is sent.

Table A.5.3.9-1. Audit Message for Network Entry

Real-World Entities

Field Name

Opt.

Value

Event: EventIdentification

EventID

M

EV (110108, DCM, "Network Entry")

EventActionCode

M

Shall be:

E

Execute

EventDateTime

M

Not specialized.

EventOutcomeIndicator

M

Not specialized.

EventTypeCode

M

EV (110124, DCM, "Attach") EV (110125, DCM, "Detach")

Active Participant: ActiveParticipant

Node or system entering or leaving the network (1)

UserID

M

Not specialized.

AlternativeUserID

U

Not specialized.

UserName

U

Not specialized.

UserIsRequestor

M

Shall be:

false

RoleIDCode

U

Not specialized.

NetworkAccessPointTypeCode

U

Not specialized.

NetworkAccessPointID

U

Not specialized.


DICOM PS3.15 2025e - Security and System Management Profiles