Core Services

187 elementer Udtræk: Maj 2026

Kernetjenester – de generelle, fælles IT-tjenester, der udgør fundamentet.
  • CR-1000 Core Services

    The Core Services provide functions to facilitate other service and data providers on the enterprise network by delivering and managing underlying capabilities for collaboration and information management, for service orchestration and platform integration, and for establishing a versatile and reliable computing infrastructure. Core Services represent a collection of community of interest (COI)-independent technical services at the back-end of communications and information systems (CIS) capabilities, focused on the technical functionality to implement service-based environments using infrastructure, architectural and enabling building blocks. Core services provide these building blocks so that these generic, common capabilities do not have to be implemented by individual applications or other services. In the context of the C3 Taxonomy, COI services are facilitating user applications and COI services and connecting these to communications and networking services in the back-end. The second layer of the associated taxonomy specifies three main categories: • Business Support Services – to provide the means to facilitate other service and data providers on the enterprise network by providing and managing underlying capabilities for collaboration and information management. These services are enablers used by other services and users across the whole network-enabled enterprise, acting as "building blocks" for developing more sophisticated COI services and applications. Therefore, they are COI-independent and they must be available to all enterprise members. • Platform Services – to provide a foundation to implement services in a loosely coupled environment, where flexible and agile service orchestration is a requirement. They offer generic building blocks for implementation (e.g. discovery, message busses, orchestration, information abstraction and access, etc.) and can be used as a capability integration platform in a heterogeneous service-provisioning ecosystem. • Infrastructure Services – to provide the foundation to host infrastructure services in a distributed and/or federated environment in support of NATO operations and exercises. They include computing, storage and high-level networking services that can be used as the basis for data centre or cloud computing implementations. The Infrastructure Services are aligned with "Infrastructure as a Service" (IaaS) concepts that are used and promoted by industry as part of their cloud computing developments.

    • CR-1011 Business Support Services

      The Business Support Services provide functions to facilitate other service and data providers on the enterprise network by providing and managing underlying capabilities for collaboration and information management. These services are enablers used by other services and users across the whole network-enabled enterprise, acting as "building blocks" for developing more sophisticated Community Of Interest (COI) services and applications. Therefore, they are COI independent and they must be available to all enterprise members.

      • CR-1008 Business Support CIS Security Services

        The Business Support CIS Security Services provide functions to implement uniform, consistent, interoperable and effective web service security. These services also implement and enforce CIS Security measures at the enterprise support level.

        • CR-1009 Business Support Guard Services

          The Business Support Guard Services provide functions to connect networks of different information security and management policies and usage areas to control traffic flow in-between the networks following a set of predefined rules.

      • CR-1010 Business Support SMC Services

        The Business Support Service Management and Control (SMC) Services provide functions to implement and enforce SMC policies at the enterprise support level.

        • CR-1003 Application Store Services

          The Application Store Services provide functions to download executable content over a network. These services also provides the means to search and discover applications, including application data, from an application repository, typically through the use of an application provisioning portal.

        • CR-1015 Configuration Management Database Services

          The Configuration Management Database (CMDB) Services provide functions to access a repository that is designed to store many of the components of an information system. A CMDB contains data describing managed resources like computer systems and application software and/or process artefacts like incident, problem and change records, and the relationships among these entities. The CMDB represents the authorized configuration of the significant components of the IT environment. Therefore, an important goal for the CMDB is to help an organization understand the relationships between different components and track their configuration. The CMDB is a fundamental component in configuration management processes and its implementations may integrate with change management, knowledge management and/or authorization.

        • CR-1013 Call Management Services

          The Call Management Services provide functions to design and implement rules and parameters governing the routing of inbound telephone calls through a network. The rules determine how calls are distributed according to the time and/or date of the call as well as the location of the caller (usually defined by the outbound Caller ID). These services also incorporate the use of calling features such as Call Queues, IVR Menus, Hunt Groups and Recorded Announcements to provide a customised experience for the user and to maximize the efficiency of inbound call handling.

        • CR-1062 VTC Management Services

          The Video Teleconference (VTC) Management Services provide functions to manage and maintain a video conferencing network and the scheduling of video meetings. These services provide diagnostic tools for system-by-system and conference-by-conference records, diagnostics for rapid support response, management of on-site and remote video systems, and scheduling of video, audio, web and data conferences.

        • CR-1057 Software Factory Services

          The Software Factory Services, also known as "DevSecOps Platform Services," offer standardized tooling and engineering functions for Application Lifecycle Management (ALM) and Build Factory activities such as continuous integration, source code management, artifact repositories, testing, and release management—facilitating collaboration across teams, ARTs, and solution trains and enabling easy movement of personnel between them. These services aim to streamline development processes and improve cross-team cooperation through shared tools and practices. Beyond tools and pipelines, these services include a self-service or ticket-based service catalog, service assurance with monitoring, configuration management, and data protection, and infrastructure on demand (IoD) for dynamic resource allocation and scalability. Additionally, they support integrated collaboration tools, process automation, and usage/cost tracking via analytics, along with a lean portfolio management tool that offers portfolio-level insights, enabling effective coordination and orchestration of development value streams.

          • CR-1157 Continuous Intergration/Continuous Deployment Services

            The Continuous Integration (CI) and Continuous Deployment (CD) Services provide functions to automate the process of integrating code changes from multiple contributors into a shared repository, allowing for early detection of integration issues and for automating the deployment of software changes to different environments (e.g., development, testing, production).

          • CR-1156 Issue Tracking Services

            The Issue Tracking Services provide functions to manage and track issues, tasks, bugs, enhancements, and other work items related to software development projects. The primary goal of an Issue Tracking service is to provide a centralized platform for teams to collaboratively monitor, prioritize, and address various aspects of the software development lifecycle.

          • CR-1158 Testing and Quality Assurance Services

            The Testing and Quality Assurance (TQA) Services provide functions to ensure the reliability, functionality, and overall quality of software products. These services encompass a range of activities, methodologies, and tools designed to identify and address issues throughout the software development lifecycle

          • CR-1155 Version Control Services

            The Version Control Services provide functions to manage changes to source code over time, enabling multiple contributors to work on a project collaboratively. The services tracks changes to files, maintains a historical record of modifications, and allows users to revert to previous versions if needed. They can be used to automatically run CI/CD Services and TQA Services.

      • CR-1014 Communication and Collaboration Services

        The Communication and Collaboration Services provide functions to support a range of interoperable collaboration capabilities, based on open, and commercial available, standards that are secure and fulfil alliance's and coalition's operational requirements. These services enable real-time situational updates to time-critical planning activities between coalition and mission participants, communities of interest, and agencies. Levels of collaboration include awareness, shared information, coordination and joint product development.

        • CR-1026 Formal Messaging Services

          The Formal Messaging Services provide functions to store and forward messages for both users and applications in support of organizational messaging (messaging between organizations and organizational units). These services (also known as Military Messaging Services) support a range of capabilities including access management, alternate recipients, conversion prohibition, deferred delivery, delivery notification, distribution list expansion, latest delivery, and message security labelling. They also support different qualities of service for different message priorities to honour the precedence of the military messages.

        • CR-1037 Informal Messaging Services

          The Informal Messaging Services provide functions to exchange digital messages (electronic mail or email) from a provider to one or more recipients using a store-and-forward model. They provide the ability to accept, forward, deliver and store messages. Messages can be relayed from one domain to another. The messages consist of three main components: the message envelope, the message header, and the message body. The message header contains control information, including an originator's email address and one or more recipient addresses, as well as the subject header field and a message submission date/time stamp.

        • CR-1024 Fax Services

          The Fax Services provide functions to send and receive bitmaps of electronic material (both text and images) using an analogue signal over a telephone network, normally to a telephone number connected to a printer or other output device. The telephone number of a receiving device is normally required to deliver the fax message across a telephone network. Alternatively, services using FoIP to deliver faxes across IP networks can extend fax delivery to multiple IP and email addressees.

        • CR-1012 Calendaring and Scheduling Services

          The Calendaring and Scheduling Services provide functions to manage calendars, the timing of tasks and task assignments for users. These include event definitions and actions in the form of notifications or alerts.

        • CR-1063 Video-based Communication Services

          The Video-based Communication Services provide functions to establish a two-way video transmission between different parties on the network, including call set-up, call coordination, full motion display of events and participants in a bi-directional manner, support for the management of directing the cameras, ranging from fixed position, to sender directed, to receiver directed, to automated sound pickup. These services also provide simultaneous videoconferencing among two or more remote points by means of a Multipoint Control Unit (MCU). This is a bridge that interconnects calls from several sources (in a similar way to the audio conference call). All parties call the MCU unit, or the MCU unit can also call the parties which are going to participate, in sequence. There are MCU bridges for IP and ISDN-based videoconferencing. There are MCUs which are pure software, and others which are a combination of hardware and software. An MCU is characterized according to the number of simultaneous calls it can handle, its ability to conduct transposing of data rates and protocols (translating and transcoding), and features such as Continuous Presence, in which multiple parties can be seen onscreen at once.

        • CR-1005 Audio-based Communication Services

          The Audio-based Communication Services provide functions for two-way audio transmission between different parties on the network, including call set-up and call co-ordination in a bi-directional manner. These services also support simultaneous audio conferencing among two or more remote points by means of a Multipoint Control Unit (MCU). This is a bridge that interconnects calls from several sources (in a similar way to the video conference call). All parties call the MCU unit, or the MCU unit can also call the parties which are going to participate, in sequence. There are MCU bridges for IP and ISDN-based videoconferencing. There are MCUs which are pure software, and others which are a combination of hardware and software. An MCU is characterized according to the number of simultaneous calls it can handle, its ability to conduct transposing of data rates and protocols (transrating and transcoding), and features such as Continuous Presence, in which multiple parties can be seen onscreen at once.

        • CR-1060 Text-based Communication Services

          The Text-based Communication Services enable the exchange of short, near real-time text messages between network addressable entities, supporting a variety of communication scenarios. They facilitate one-to-one messaging, allowing direct communication between two entities, as well as multi-party messaging for conversations involving multiple entities, which is essential for coordinated operations and information sharing across teams. Additionally, these services support alerting and notification messages to quickly disseminate critical updates and structured request and response interactions for formal information exchanges. They also enable cross-domain sharing of information, ensuring that relevant data can be efficiently transmitted and received across different operational domains, enhancing overall communication effectiveness and situational awareness.

        • CR-1064 Whiteboarding Services

          The Whiteboarding Services provide functions to mirrors the experience of collaborating on a whiteboard in a conference room. The services allow for the capture of freeform ideas by bringing together a group of people's thoughts, all in one place. The services also provide a virtual whiteboarding capability for shares, images or files and lets multiple participants work and annotate on these images or files concurrently, with real-time updates being shared between all participants.

        • CR-1052 Presence Services

          The Presence Services provide functions to advertize the network availability of other entities hence providing the knowledge of whether those entities are online and available for communication. The services manage a subscription model, in effect a simple publish-subscribe method, whereby entities that have subscribed to another entity's presence receive updated presence information when that entity comes online and goes offline.

        • CR-1002 Application Sharing Services

          The Application Sharing Services provide functions to share an application's user interface over the network infrastructure. All participating actors can view and use the shared application simultaneously.

      • CR-1023 Enterprise Resource Planning Services

        The Enterprise Resource Planning (ERP) Services provide functions to cross-functional support for enterprise internal business processes by providing a real-time view of financial resource management, human resource management, supply chain management, customer relationship management, project management and process management activities.

        • CR-1025 Financial Resource Management Services

          The Financial Resource Management Services provide functions to manage budgeting, cost management, general ledger, payables, receivables, cash management, financial consolidation and financial auditing processes.

        • CR-1036 Human Resource Management Services

          The Human Resource Management Services provide functions to manage recruiting, in-processing, separation, training, skill-set management, payroll, job description management and organizational structure management processes.

        • CR-1059 Supply Chain Management Services

          The Supply Chain Management Services provide functions to manage and locate objects or materials including capacity, stock levels, re-order levels, historical demand records and specialized storage capacity (e.g. environmentally controlled).

        • CR-1054 Project Management Services

          The Project Management Services provide functions to execute project planning, resource assignment, project accounting, project collaboration and project tracking, integrating information for other supporting services and systems like workforce management systems and accounting systems. Web-based project management applications and tools typically model and enforce best practices that facilitate reliable and consistent project planning, launch and delivery.

      • CR-1030 Geospatial Web Services

        The Geospatial Web Services provide functions to deliver network-based access to quality raster, vector and terrain data, available in varying degrees of format and complexity. These services form a distinct class of information services through their unique requirements for collecting, converting, storing, retrieving, processing, analysing, creating, and displaying geographic data. The generic nature of the services - "organizing information by location" - is interdisciplinary and not specific to any Community of Interest (COI) or application. Nonetheless, specialized services are also required, based on specific needs such as transformation of geographic coordinates and querying of catalogues.

        • CR-1027 Geospatial Catalog Services

          The Geospatial Catalog Services provide functions to discover, browse, and query metadata about geospatial data, services, and other potential resources.

        • CR-1034 Geospatial Web Map Services

          The Geospatial Web Map Services (WMS) provide functions to request geo-registered map images from one or more distributed geospatial databases. A WMS request defines the geographic layer(s) and area of interest to be processed. The response to the request is one or more geo-registered map images. Typical image formats for the map result are PNG, JPEG, GIF or SVG. There are open source WMS Servers such as UMN Mapserver and Mapnik. Commercial alternatives exist from most commercial GIS vendors, such as ESRI ArcIMS, ArcGIS Server, GeoClip, Intergraph Geomedia WebMap, and others.

        • CR-1033 Geospatial Web Feature Services

          The Geospatial Web Feature Services provide functions to describe data manipulation operations (e.g. create, delete, update, get or query) on geospatial features which are primarily based on vector data.

        • CR-1032 Geospatial Web Coverage Services

          The Geospatial Web Coverage Services provide functions to support the requests for geographical coverages across the web using platform-independent calls. The coverages are objects (or images) in a geographical area, whereas the Web Map Services (WMS) interface or online mapping portals return only an image, which end-users cannot edit or spatially analyze.

        • CR-1035 Geospatial Web Map Tile Services

          The Geospatial Web Map Tile Services provide functions to access to cartographic maps using predefined image tiles. Geospatial Web Map Tile Services provide a complementary approach to the Geospatial Web Map Services for tiling maps. The services focus on rendering custom maps and is an ideal solution for dynamic data or custom styled maps. They trade the flexibility of custom map rendering for the scalability possible by serving of static data (base maps) where the bounding box and scales have been constrained to discrete tiles which enables the use of standard network mechanisms for scalability such as distributed cache systems to cache images between the client and the server, reducing latency and bandwidth use. The service advertises the tiles it has available through a standardized declaration in the ServiceMetadata document common to all geospatial web services. This declaration defines the tiles available in each layer (i.e. each type of content), in each graphical representation style, in each format, in each coordinate reference system, at each scale, and over each geographic fragment of the total covered area. The ServiceMetadata document also declares the communication protocols and encodings through which clients can interact with the server. Clients can interpret the Service Metadata document to request specific tiles.

        • CR-1028 Geospatial Coordinate Services

          The Geospatial Coordinate Services provide functions to translate geospatial coordinates between spatial reference systems. A spatial reference system (SRS) is a coordinate-based local, regional or global system used to locate geographical entities. This reference system defines a specific map projection, as well as transformations between different spatial reference systems.

        • CR-1031 Geospatial Terrain Analysis Services

          The Geospatial Terrain Analysis Services provide functions to support planning and predictive decision tools by providing information and knowledge products that capture integrated terrain and weather effects. Terrain and weather effects represent a fundamental, enabling piece of battlefield information supporting situation awareness and the decision-making processes within Command, Control, Communications, Computer, Intelligence, Surveillance and Reconnaissance (C4ISR). These effects can both enhance or constrain force tactics and behaviours, platform performance (ground and air), system performance (e.g. sensors) and humans.

      • CR-1038 Information Management Services

        The Information Management Services provide functions to direct and support the handling of information throughout its life-cycle ensuring it becomes the right information in the right form and of adequate quality to satisfy the demands of an organization. These services support capabilities to organize, store and retrieve information (in any format, structured or unstructured) through services and managed processes, governed by policies, directives, standards, profiles and guidelines.

        • CR-1016 Content Management Services

          The Content Management Services provide functions to manage the development and lifecycle of information (from creation to destruction, structured or unstructured, static or dynamic, transitory or operational record) such as images, audio, video, web content, messaging and email, office documents, PDFs, XML, etc.

        • CR-1061 Unit Conversion Services

          The Unit Conversion Services provide functions to convert a given value in a selected unit to another selected unit. The units include distance (nautical mile, statute mile, data mile, yard, feet, meter, kilometre), wind speed and force (e.g. Beaufort to km/h), speed (knots, data mile per hour, km/h, m/s, mph), weight/mass, length, area, volume, temperature, density/pressure.

        • CR-1065 Workflow Services

          The Workflow Services provide functions to support business activities (manual, semi-automated or automated) and coordination of information, people and services involved. This includes supporting services for the management of business processes, their creation, execution and monitoring.

        • CR-1056 Search Services

          The Search Services provide functions to search and discover information (structured, semi-structured and unstructured, in any format, transitory or operational record) to and from integrated and federated services and data sources, and in compliance with relevant governance.

        • CR-1049 Language Support Services

          The Language Support Services provide functions to exploit enterprise linguistic support for multiple human languages in the form of typographic and grammatical verification and auto-correction, thesaurus and natural language translation capabilities.

        • CR-1004 Archiving Services

          The Archiving Services provide functions to archive an organization's electronic data and to manage archives. In general, archives of any individual or organization consist of records which have been especially selected for permanent or long-term preservation, due to their enduring value. Archival records are normally unpublished and almost always unique, unlike books or magazines, in which many identical copies exist.

        • CR-1198 Records Management Services

          The Records Management Services provide functions to support the processes and full active lifecycle of records as authoritative evidence, ensuring accuracy, accountability, authenticity, reliability, completeness, accessibility and compliance of records.

      • CR-1020 Data Science Services

        The Data Science Services provide functions to support data-driven decision making, and leverage data as a strategic resource. The Data Science Services enable transformation of raw data into insights through visualization and reporting, advanced analytics and Artificial Intelligence (AI) technologies, such as machine learning (ML), Deep Learning (DL), natural language processing (NLP), use of large language models (LLMs), and generative artificial intelligence (GenAI).

        • CR-1050 Machine Learning Services

          The Machine Learning (ML) Services provide functions to simplify and accelerate the building, training, and deployment of machine learning models. Machine learning facilitates the continuous advancement of computing through exposure to new scenarios, testing and adaptation, while employing pattern and trend detection for improved decisions. The services support multiple statistical methods that address categorization (binary and multi-class), clustering, anomaly detection, regression, recommendation, and cognitive analysis such as: • Vision – image-processing algorithms to smartly identify, caption, index, and moderate pictures and videos. • Knowledge – mapping complex information and data in order to conduct semantic searches. • Language – processing natural language and evaluating sentiment. • Speech – converting spoken audio into text. Recognizing voices of individual speakers.

        • CR-1001 Analytics Services

          The Analytics Services provide functions to support the decision-making needs of the enterprise, using information produced by gathering, consolidating, cross-referencing and enhancing information from various sources, and applying various data mining or statistical techniques to identify trends and draw insights from the data. Different types of analytics include, but is not limited to: • Descriptive – describes the past or current state or performance through summary statistics and visualizations. • Diagnostic – diagnoses the reasons for the outputs of descriptive analytics by mining historical data and applying statistical models to identify causal relationships or correlation analysis of past success or failure. • Predictive – predicts trends and behaviour patterns or forecasts the future development, mainly by applying statistical models (machine learning models) to historical data • Prescriptive – prescribes the best action through techniques of diagnostic and predictive analytics and optimization comparing different scenarios • Geo-related – supporting the analysis and interpretation of geographic and geospatial information and data such as to inform logistics route planning or line-of-sight for direct fires.

        • CR-1191 Data Engineering Services

          The Data Engineering Services provide functions to represent an essential part of Data Science and Artificial Intelligence (AI) activities by providing foundational infrastructures and capabilities. In particular, these services allow for data manipulation, ingestion, transformation, validation, and storage. Furthermore, these enable the orchestration and deployment of data solutions.

        • CR-1190 Reporting and Visualization Services

          The Reporting and Visualization Services provide functions to transform raw or processed data into into meaningful, accessible, and understandable reports and dynamic visual formats and to integrate with diverse data sources and pipelines. The objective is to produce timely, accurate, and relevant outputs that are tailored to meet the needs of different user audiences, to deliver actionable insights and support data-driven decisions, whether through static reports or real-time, interactive dashboards.

    • CR-1111 Platform Services

      The Platform Services provide functions to implement services in a loosely coupled environment, where flexible and agile service orchestration is a requirement. The services offer generic building blocks for implementation (e.g. discovery, message busses, orchestration, information abstraction and access, etc.) and can be used as a capability integration platform in a heterogeneous service-provisioning ecosystem.

      • CR-1105 Platform CIS Security Services

        The Platform CIS Security Services provide functions to implement uniform, consistent, interoperable and effective web service security. The services also offer the necessary means to implement and enforce CIS Security measures at the platform level.

        • CR-1106 Platform Guard Services

          The Platform Guard Services provide functions to connect networks of different information security and management policies and usage areas to control traffic flow in-between the networks following a set of predefined rules for platform services. The intent is to allow automated data exchange between two network enclaves that belong to different information domains. The services enable a cross-domain information exchange by mediating traffic flows, while offering sufficient protection against the unintended leakage of confidential information and possible degradation of integrity of resources by enforcing an appropriate access control policy.

        • CR-1122 Security Token Services

          The Security Token Services (STS) provide functions to identify providers responsible for issuing security tokens, which may or may not be structured as XML. These security tokens are issued after entity authentication to the STS, and are used to pass entity identity information to other services (relying parties) which trust the STS and its tokens.

        • CR-1114 Policy Enforcement Point Services

          The Policy Enforcement Point (PEP) Services provide functions to protect other services by providing a logical entry point that serves as an intermediary between a call from a service consumer to a service provider. The PEP can either be deployed as a separate device or appliance that sits between the consumer and provider, or as an inline component that is deployed as part of the container infrastructure of the service. The PEP validates the structure of the message, including the digital signature, and the credentials that are provided with the message. This provides a common mechanism to extract and pass on identity information from the service consumer to the service provider so that an Authorization decision can be made, either locally or through the use of a Policy Decision Point (PDP).

        • CR-1113 Policy Decision Point Services

          The Policy Decision Point (PDP) Services provide functions to authorize decisions by evaluating digital policies against the attributes of an authorization request. The request can contain attributes about the subject of the request (the service consumer), the object of the request (the resource that is being accessed), the action that is being performed and other attributes not related to the subject or resource (the "environment"). A decision is returned to the requesting entity, which can contain further obligations about how the request is to be treated. The PDP can be collocated with a Policy Enforcement Point (PEP) to improve performance.

        • CR-1087 Information Labeling Services

          The Information Labelling Services provide functions to apply metadata to an information object for the purpose of creating a label or mapping labels of "foreign" information security and management policies. Labelling (Ref ADatP-4778.1) facilitates the determination of the protection requirement for an information object, the release of an information object, or the determination of the mission value of an information object, as captured by release and protection policies defined for each metadata entry.

        • CR-1112 Policy Administration Point Services

          The Policy Administration Point (PAP) Services provide functions to compose, modify, manage, and control access control policies in a standard policy exchange format, enabling the policy enforcement through the Policy Enforcement Point (PEP) and Policy Decision Point (PDP) components.

        • CR-1176 Policy Information Point Services

          The Policy Information Point (PIP) Services provide functions to collect, aggregate, and deliver relevant attribute and contextual data required for making policy decisions. The PIP services act as an intermediary, connecting to multiple data sources to retrieve attributes about users, devices, resources, and environmental conditions.

        • CR-1193 Application Profiling Services

          The Application Profiling Services provide functions to create and manage dynamic application profiles that capture the application demands on access, priority, reachability, connections to dependency services, and connection pathways. This information is crucial for building robust access controls and detecting anomalous activity. Repeated profiles can be treated as a traffic class on the network.

        • CR-1194 Logical Segmentation Services

          The Logical Segmentation Services provide functions to create network micro-segmentation on a logical level by placing individual or groups of users and resources (e.g. network applications with defined application profiles) on a unique network segment, in order to segregate and secure workloads independently. This can be enforced by Policy Enforcement Points (PEP) implemented by intelligent switches, next generation firewalls, special purpose gateway devices in front of (data) resources, and/or (client-side) software agents on endpoint devices.

      • CR-1110 Platform SMC Services

        The Platform Service Management and Control (SMC) Services provide functions to ensure that platform services are up and running, accessible and available to users, protected and secure, and that they are operating and performing within agreed upon parameters. The services also offer the means to implement and enforce SMC policies at the platform level.

        • CR-1120 SMC Policy Enforcement Services

          The Service Management and Control (SMC) Policy Enforcement Services provide functions to enforce technical and business policies related to performance, quality of service, agreed service levels, and ensures compliance with business and legal rules. The services enforce policies on services hosted within the Platform. Depending on implementation, these services can be standalone components in front of protected services (e.g. functioning like reverse proxy); or they can be part of the web hosting platform (e.g. a pipeline in an application server).

        • CR-1123 Service Discovery Services

          The Service Discovery Services provide functions to discover a target service that matches certain functional and non-functional requirements. In this context discovery is the act of locating a service description of target service(s) which contain information about the (syntactic and semantic) interface of the service and other (non-functional) aspects of its service contract. The resulting service description is sufficient to inform a consumer on the mechanism required to bind to an instance of the target service.

        • CR-1107 Platform Logging Services

          The Platform Logging Services provide functions to capture, filter and write information about calls between services hosted in the platform. The logs can be used for auditing purposes, for troubleshooting, performance optimizations, etc.

        • CR-1109 Platform Monitoring Services

          The Platform Monitoring Services provide functions to gather information on the actual utilization and performance of monitored Platform Services. These services monitor service communication based on service calls and message exchange to identify performance issues and determine current availability in order to ensure that any failures are detected proactively, isolated, analyzed, and resolved with as little impact on the end user as possible.

        • CR-1108 Platform Metering Services

          The Platform Metering Services provide functions to measure levels of platform resource utilization such as number of web service/application requests, CPU cycles/time used to process requests to specific web service/application, number of transactions, number of message queue requests, incoming and outgoing network bandwidth (total size of incoming and outgoing messages), data storage volume used by application/service over various periods of time (e.g. second, hour, week, month, year).

        • CR-1151 API Management Services

          The Application Programming Interface (API) Management Services provide functions to facilitate the end-to-end governance, optimization, and security of APIs within a digital ecosystem. The services govern the full API lifecycle, including exposure, security, traffic control, documentation, and monetization. They support the dynamic nature of API ecosystems, accommodating various deployment models and provide efficient API design, deployment, and the controlled, secure, and optimized operation of APIs.

        • CR-1147 Compute Workload Management Services

          The Compute Workload Management Services provide functions to integrate tools, platforms, or systems that help organizations efficiently manage and optimize the allocation of computing resources to various workloads. These services play a crucial role in dynamically adjusting resource allocation based on demand, ensuring optimal performance, scalability, and resource utilization. Compute workload management involves a combination of load balancing at the application level, resource orchestration and scheduling, auto-scaling, job scheduling, policy-based management of resource pools and clusters, integration with Cloud Services, incl. Hybrid and multi-Cloud Support, and support to monitoring and analytics.

        • CR-1152 Container Management Services

          The Container Management Services provide functions to facilitate container image registration and containerized application deployment. These services provide the functionality for efficiently registering, orchestrating, deploying, and managing containers within a cloud-native environment.

          • CR-1192 Container Image Scanning Services

            Container Image Scanning services examine container images, for potential vulnerabilities or issues that could compromise security or efficiency. This technique is commonly used in cloud native environments, where images play a crucial role in ensuring system safety and integrity. ==Key Features:== • Detect insecure containers • Detect outdated libraries • Detect incorrectly configured containers • Detect outdated operating system • Detect compliance validations • Suggest best practices • Data Storage & Optimization – designing data schemas and choosing appropriate storage system for the specific task to support efficient retrieval and analysis; optimizing performance through indexing, partitioning, or caching strategies. • Data Pipeline Development – developing ETL/ELT pipelines to automate data ingestion and transformation (E – Extract, T – Transform, L – Load); implementing orchestration tools to coordinate workflows. • Infrastructure Engineering – setting up and managing data infrastructure, whether on premise, hybrid or cloud, to support needs of Data Science and AI initiatives; containerization, deployment and orchestration of data solutions.

          • CR-1154 Container Orchestration Services

            The Container Orchestration Services provide functions to deploy, scale and manage containerized applications, e.g. micro-services, across various cloud environments. This service type abstracts underlying infrastructure complexities, and provides flexibility and consistency in container orchestration and management practices.

          • CR-1153 Container Registry Services

            The Container Registry Services provide functions to operate a centralized and scalable storage solution for managing container images. These services play a crucial role in the containerized application development and deployment workflow, allowing developers to store, organize, and distribute container images efficiently across different stages of the software development lifecycle.

      • CR-1099 Message-Oriented Middleware Services

        The Message-Oriented Middleware Services provide functions to support the exchange of messages (data structures) between data producer and consumer services, independent of the message format (XML, binary, etc.) and content. The services support different models of message exchange (direct, brokered, queues), exchange patterns (request/response, publish/subscribe, solicit response (polling for response), and for fire and forget), topologies (one-to-one, one-to-many) and modes of delivery (synchronous, asynchronous, long running). They also provide the support for routing, addressing, and caching.

        • CR-1076 Direct Messaging Services

          The Direct Messaging Services provide functions to exchange messages in a direct communication with another services. The exchange of messages can be implemented using any Message Exchange Pattern (e.g. request/response, publish/subscribe, fire and forget, solicit response). The services can be implemented to use synchronous (i.e. blocking) and asynchronous (i.e. non-blocking) communication modes. For example, in a Publish-Subscribe scenario a notification producer would be one direct messaging service sending one-way messages to a notification consumer that would be another direct messaging service receiving the message.

        • CR-1094 Message Brokering Services

          The Message Brokering Services provide functions to act as an intermediary between senders (message consumers ) and receivers (message subscribers) in order to permit the message consumers to subscribe to messages produced by these publishers. Within this Message Publish-Subscribe pattern, publishers do not send messages directly to specific consumers (those who subscribed), but instead send them to these services for further distribution to registered subscribers.

        • CR-1098 Message Routing Services

          The Message Routing Services provide functions to route messages at run time based on different criteria, e.g. message content or metadata or for load-balancing purposes. The routing logic shall be configurable. The services also offer one-to-many message delivery by multiplying a message and sending it to many recipients, e.g. this can be used to implement multicast messages.

        • CR-1096 Message Proxying Services

          The Message Proxying Services provide functions to act as an intermediary for other services, hiding their actual location and implementation from the service consumers. The services communicate on a behalf of the underlying service. They offer a capability to expose a virtual endpoint of the underlying service. These services tend to sit at the boundaries of organizations, either internal boundaries (between sites, before WAN links) or external boundaries (such as the Internet). They provide a number of benefits over the use of directly communicating through a router. A number of security features may be activated, such as content checking, authentication and authorization, auditing and anonymity (as the identity of the client machine can be hidden). The services can communicate with Message Caching Services to avoid having to make calls across sub-optimal WAN links, and can use other techniques (such as compression) to improve performance.

        • CR-1097 Message Queueing Services

          The Message Queueing Services provide functions to queue messages in intermediary buffers, allowing services and consumers to process messages independently by remaining temporally decoupled. Thus these services support asynchronous communication.

        • CR-1095 Message Caching Services

          The Message Caching Services provide functions to store messages sent between producers and consumers under certain conditions. The messages can be later served to consumers if they need to resynchronize their state or were unavailable and lost some messages. The cache can support synchronous (request/response) and asynchronous (fire and forget, publish/subscribe) communication.

      • CR-1131 Web Platform Services

        The Web Platform Services provide functions to support the deployment of services onto a common web-based application platform.

        • CR-1130 Web Hosting Services

          The Web Hosting Services provide functions to establish an environment for operating web applications and services. The services enable a service container that manages the service life cycle and underlying resources (such as memory, storage and CPU) to deliver the required service. The application or web service execution takes place within the container's run time environment.

        • CR-1132 Web Presentation Services

          The Web Presentation Services provide functions to combine rich content from different data sources into a single client web page or desktop, using a combination of Web 2.0 technologies such as HTML snippets, scripting code (JavaScript), on demand code (AJAX, JSON), web service calls and proprietary code (Flash, ActiveX and so on).

        • CR-1148 Application Hosting Services

          The Application Hosting Services provide function to simplify the deployment, scaling, and management of web based applications. These services are comprehensive, cloud-based solutions to support a variety of application types, from traditional web applications to micro-services architectures. They abstract away cloud infrastructure complexities, and provide a platform that enables developers to focus on building and improving their applications rather than managing underlying resources.

        • CR-1150 Serverless Computing Services

          The Serverless Computing Services provide function to write and deploy code as individual functions, without the need to manage the underlying infrastructure. In a serverless architecture, the cloud provider dynamically allocates and scales resources to execute functions in response to events or triggers, such as HTTP requests, database changes, or scheduled tasks. Developers focus on writing code for specific tasks, and the cloud provider handles the provisioning, scaling, and maintenance of the execution environment. Serverless computing follows a pricing model, where users are billed based on the actual execution of functions, promoting cost efficiency and scalability. The serverless model is well-suited for event-driven and stateless applications, providing automatic scaling, reduced operational overhead, and flexibility for diverse workloads.

      • CR-1138 Data Platform Services

        The Data Platform Services provide functions to access trusted data across distributed environments by utilizing active metadata, knowledge graphs, semantics and Machine Learning (ML) capabilities of data integration (as well as other data management tools, including data catalogues and data governance).

        • CR-1141 Data Discovery Services

          The Data Discovery Services provide functions to search, identify and register datasets or data assets together with their metadata to allow data consumers - such as data scientists, analysts, and data engineers - to find datasets of their interest and to gain real-time visibility into the datasets’ current state, in addition to their “catalogued” or ideal state. Data discovery enables security teams to identify sensitive or regulated information, including confidential or proprietary data as well as protected data to protect it and ensure its confidentiality, integrity, and availability. Data catalogues, data dictionaries and business glossaries are commonly used for data management. The services manage the data catalogues to gain a unified view and minimize the effort of searching for the right data; support enriching data with technical and business metadata (tagging); and improve data management to increase operational efficiency and productivity.

          • CR-1159 Data Catalogue Services

            The Data Catalogue Services provide functions to discover, organize and manage data assets across various sources. They provide comprehensive metadata management, data lineage tracking, and governance capabilities, facilitating data discovery and collaboration among users. By offering a unified view of data assets, they enhance data accessibility, quality, and compliance, supporting informed decision-making and effective data utilization within an organization.

          • CR-1168 Data Dictionary Services

            The Data Dictionary Services provide functions to document and manage technical metadata - the definitions, names, and attributes of data elements within an information system or database. The services support data governance, compliance, and discovery efforts while facilitating data integration and interoperability across diverse systems. Thereby, they ensure data quality, support data discovery, and facilitate the interoperability of data systems by clearly defining the structure, meaning and representation of data elements. These services also integrate features of Metadata Registry and Repository Services, enhancing their scope and utility in the broader data management ecosystem.

          • CR-1167 Ontology Management Services

            The Ontology Management Services provide functions to create, manage and share large-scale ontologies and taxonomies, enabling the construction of enterprise knowledge graphs to represent data and relationships in a structured, semantically meaningful way. These services are essential for aligning disparate data sources, improving interoperability, and enhancing the discoverability and usability of data assets across an enterprise. By supporting semantic reasoning and insight generation from data, Ontology Management Services help organizations make more informed decisions, improve governance, and enhance data-driven innovation.

        • CR-1140 Data Management Services

          The Data Management Services provide functions to ingest, store, and efficiently use data securely and cost-effectively to help products, processes, organizations, and connected things optimize the use of data within the bounds of policies and regulations. These services enable continuous data governance as it is compiled by data pipelines, such as ensuring data privacy, precedence, and security or archiving and destroying data per retention schedules and compliance requirements. The services further enable the safe and reliable exchange of data across national borders and the proper tactical deployment of Multi-Domain Operations (MDO). A well-defined data management service will not only prepare an organization for the challenges they face today but ensures they are prepared to embrace inevitable future change. When speaking of the data, it is with reference to being ready to operate in a secure and non-secure hybrid cloud operational environment.

          • CR-1161 Data Quality Monitoring Services

            The Data Quality Monitoring Services (DQMS) provide functions to continuously verify the quality of data assets against established standard and quality metrics across various Data Quality Dimensions (e.g., accuracy, completeness, consistency, timeliness) by utilizing real-time monitoring tools that proactively detect, report, and help remediate issues. Data verification may be followed by corrective actions, such as data editing or data imputation.

          • CR-1178 Reference Data Management Services

            The Reference Data Management (RDM) Services provide functions to managing standardized data sets, such as airport or currency codes, Community of Interest and industry classifications, and organizational hierarchies, used across applications and business processes. These services support data standardization, helping organizations ensure that reference data remains accurate, consistent, and easily accessible. RDM Services play a crucial role in data interoperability, ensuring that all systems in an organization adhere to standardized values and definitions, reducing data discrepancies, and enhancing data integrity for both operational and analytical purposes. Both MDM and RDM Services form the backbone of organizational data management strategies, supporting data quality, governance, and consistency across the organization and ensuring that critical data is reliable and accessible for all stakeholders.

          • CR-1162 Data Repository Services

            The Data Repository Services provide functions to deliver comprehensive storage and management solutions for data across diverse formats and sources within a unified, scalable infrastructure. These services support structured, semi-structured, and unstructured data, facilitating both analytical and operational use cases within an organization.

          • CR-1160 Data Disposition Services

            The Data Disposition Services provide functions to manage the lifecycle of data, particularly the processes of archiving, retention, deletion, and destruction of data in compliance with regulatory, legal, and business requirements. These services ensure that data is securely and appropriately managed, archived, and eventually disposed of, while maintaining compliance with policies and regulations.

          • CR-1177 Master Data Management Services

            The Master Data Management (MDM) Services provide functions to manage an organization’s critical business entities and associated data, including customers, products, employees, and suppliers. These services ensure that core data assets are accurate, consistent, and accessible, creating a single, reliable source of truth across the organization. MDM Services support governance, data quality, and harmonization processes, helping organizations maintain operational and analytical consistency.

          • CR-1180 Knowledge Graph Services

            The Knowledge Graph Services provide functions to create, maintain and query knowledge graphs - data structures that capture relationships and dependencies among data points. The services bring powerful relationship mapping and contextual awareness to enterprise data ecosystems, enhancing decision-making by enabling advanced queries and data exploration.

        • CR-1018 Data Ingestion Services

          The Data Ingestion Services provide functions to automate the attainment and import of unstructured and structured data from various sources for immediate use or storage in a database. In other words, these services extract data from the source where it was created or originally stored, and load it into a destination or staging area such as long-term storage in a data warehouse or data lake. Ingested data can be streamed in real time or processed in batches. In real-time data ingestion, each data item is imported as the source emits it. When data is ingested in batches, data items are imported in discrete chunks at periodic intervals of time. The first step in an effective data ingestion process is to prioritize the data sources. Individual data object must be validated and data objects routed to the correct destinations.

          • CR-1163 Data Virtualization Services

            Data Virtualization Services (Ref DCRAv2) enable organizations to access, integrate, and manage data across various systems and sources without physically moving or replicating it. These services create an abstraction layer that allows users to query data in real-time, no matter where it is stored—whether in cloud systems, on-premises databases, or data lakes. By providing a unified view of distributed data, Data Virtualization Services eliminate data silos and reduce the need for costly ETL (Extract, Transform, Load) processes. ==Key Features== • Unified Data Access: These services provide a single point of access to data across multiple, heterogeneous data sources, such as SQL databases, NoSQL systems, cloud storage, and enterprise applications. • Real-Time Integration: Data is integrated in real time, allowing users to query live data without needing to physically consolidate or move it, which improves the efficiency of business operations. • Data Governance and Security: Data Virtualization Services enforce consistent security policies and governance rules across all data sources, ensuring that only authorized users can access specific data. • Scalability and Flexibility: These services can scale across complex, hybrid environments and adapt to various data workloads, whether in transactional databases or large analytical datasets.

          • CR-1166 Stream Processing Services

            Stream Processing Services (Ref DCRA; real-time data) provide real-time processing and analysis of continuous data streams, enabling organizations to trigger instant actions as data is ingested. These services handle unbounded streams of data with low latency, supporting event-driven architectures that react to individual data events. With stateful processing capabilities, Stream Processing Services allow for complex computations such as windowing and aggregations across time-based or session-based data. Designed for scalability and fault tolerance, these services are ideal for high-throughput environments like IoT data streams, real-time monitoring, and event-triggered automation, ensuring resilience and efficiency in handling live data flows. ==Key Features== • Real-Time, Low-Latency Processing: Continuously processes incoming data in real-time, ensuring ultra-low-latency response to events, enabling immediate decision-making and insights. • Event-Driven and Stateful Processing: Reacts instantly to data events with complex event-driven workflows, while retaining state over time for operations like aggregations and windowing. • Scalability and Fault Tolerance: Scales dynamically to handle large data volumes, with fault-tolerant systems ensuring reliability during real-time data flows and recovery from failures without data loss.

        • CR-1165 Pipeline Processing Services

          The Pipeline Processing Services provide functions to gather, transform, and deliver data from various sources to target environments such as data warehouses, lakes, or marts. These services ensure consistent and reliable data flows, supporting real-time analytics and reporting. With Change Data Capture (CDC) for efficient replication and incremental updates, Pipeline Processing Services enhance performance and minimize processing delays.

        • CR-1139 Data Orchestration Services

          The Data Orchestration Services provide functions to execute data pipelines that are taking siloed data from multiple data storage locations, coordinating the combining, verifying, organizing and storing of that data and making it available for data analysis tools. Data orchestration services evolved from manual orchestration efforts with an emphasis on automation, conceptualization and analytics to support optimization. While data orchestration services operate within larger workflows, the actual work they accomplish can vary from between different implementations. By and large, however, these tasks fall into five primary parts: collection and preparation of data; transformation of the data; automated enrichment and stitching; decision-making around data; and synchronization.

        • CR-1142 Data Access Services

          The Data Access Services provide functions to serve data resources for the consumption of various types of data through common data interfaces, making data available like the web based Information Access Services but not limited to web specific technologies. These services rely on policies from Data Access Governance (DAG) to determine who has access to which data and how that data is classified, based on the defined mission roles, needs of the organization, and regulatory compliance. They relay the attributes of the data on request to enable a PEP to enforce the DAG rules and policies regarding access to the data. Enforcement can take place within identity and access infrastructure or through dedicated policy enforcement and control points, for which two approaches are possible: Attribute-based Access Control (ABAC) and Role-based Access Control (RBAC).

        • CR-1075 Data Storage Services

          The Data Storage Services provide functions to access shared, structured or semi-structured, physical or virtualised storage components for persistent storage and safeguarding of collections of data.

          • CR-1077 Directory Services

            The Directory Services provide functions to serve as a broker between its users that provide authoritative information (publishers) and those that consume that information (subscribers). Publishers can store their authoritative information in a Directory Service-specific directory/data repository to satisfy queries from subscribers. The information can either be retrieved by the service meta-tools and stored in the directory/data repository or stored directly into that directory/data repository by the publisher. Subscribers will be able to access the Directory Services information over a variety of different interfaces including file-based, remote procedure call (RPC) and service oriented architecture (SOA) interfaces. As well as directly accessing the information according to the schema, the Directory Services will be able to map the information to alternative schemas that are already in use by existing directories/data repositories.

          • CR-1133 Graph Database Services

            The Graph Database (GDB) Services provide functions to use graph structures for semantic queries with nodes, edges, and properties to represent and store data. A key concept of the GDB is the graph (or edge or relationship): the graph relates the data items in the store to a collection of nodes and edges, the edges representing the relationships between the nodes. The relationships allow data in the store to be linked together directly and, in many cases, retrieved with one operation. Graph databases hold the relationships between data as a priority. Querying relationships is fast because they are perpetually stored in the database. Relationships can be intuitively visualized using graph databases, making them useful for heavily inter-connected data.

          • CR-1134 Key-Value Database Services

            The Key-Value Database Services provide functions to implement a data storage paradigm designed for storing, retrieving, and managing associative arrays, and a data structure more commonly known today as a dictionary or hash table. Dictionaries contain a collection of objects, or records, which in turn have many different fields within them, each containing data. These records are stored and retrieved using a key that uniquely identifies the record, and is used to find the data within the database.

          • CR-1135 Wide-Column Datastore Services

            The Wide-Column Datastore Services provide functions to store data in schema-free extensible record stores with an ability to hold very large numbers of dynamic columns. Since the column names as well as the record keys are not fixed, and since a record can have billions of columns, wide column stores can be seen as two-dimensional key-value stores.

          • CR-1136 Document-oriented Database Services

            The Document-oriented Database Services provide functions to store data using a document-oriented database model. Document-oriented databases are similar to key-value databases in that, there’s a key and a value. Data is stored as a value; its associated key is the unique identifier for that value. In a document-oriented database, the value contains structured or semi-structured data. This structured/semi-structured value is referred to as a document. The structured/semi-structured data that makes up the document can be encoded using one of any number of methods, including XML, JSON, YAML, BSON, etc. It could also be encoded using binary, such as a portable document format (PDF), office documents, etc.

          • CR-1118 Relational Database Services

            The Relational Database Services provide functions to access data items organized as a set of formally-described tables from which data can be accessed or reassembled in many different ways without having to reorganize the database tables. The services can be accessed through the Structured Query Language (SQL) - SQL statements are used for schema manipulation, data manipulation and information retrieval.

          • CR-1145 Object-Oriented Database Services

            The Object-Oriented Database (OODB) Services provide functions to integrate database capabilities with object-oriented programming (OOP) capabilities to manipulate the data. Instead of using tables like in relational databases, data objects have members such as fields, properties, and methods that manipulate the data. This enables more complex forms of relationships and operations to be executed, such as inheritance and object identity. Objects also have a life cycle that includes the creation of an object, use of an object, and deletion of an object. OOP has key characteristics, encapsulation, inheritance, and polymorphism.

          • CR-1144 Spatial Database Services

            Spatial databases services provide standard databases services (usually a relational database) that have been enhanced to accept spatial data types and queries. Spatial data types store feature geometry that describes shape and location. Spatial database services typically allow the representation of simple geometric objects such as points, lines and polygons. Some can also handle more complex structures such as 3D objects, topological coverages, linear networks, and triangulated irregular networks (TINs). The geometry of spatial features is typically compressed and stored in a binary field along with the attribute data that describe the feature. The ISO/IEC 13249-3 SQL/MM Spatial - originally developed by the Open Geospatial Consortium (OGC) - extends the Simple Features data model, originally based on straight-line segments, adding circular interpolations (e.g. circular arcs) and other features like coordinate transformations and methods for validating geometries, as well as Geography Markup Language (GML) support.

          • CR-1143 Time-series Database Services

            The Time-series Database Services provide functions for accessing and optimized storing and serving time series through associated pairs of time(s) and value(s). In some fields, time series may be called profiles, curves, traces or trends. Time-series Database Services provide features such as retention policies, time-window aggregation, efficient storage and high write and query performance. In many cases, the repositories of time-series data will utilize compression algorithms to manage the data efficiently. Although it is possible to store time-series data in many different database types, the design of these systems with time as a key index is distinctly different from relational databases which reduce discrete relationships through referential models.

        • CR-1196 Data Privacy-Enhancement Services

          The Data Privacy-Enhancement Services provide functions to protect sensitive data by employing Privacy-Enhancing Technologies (PETs), ensuring secure data use without compromising privacy and authorized data exploitation. These services allow organizations to manage and protect sensitive data and facilitate safe data sharing and collaboration while complying with regulatory standards without compromising its analytical value.

      • CR-1088 Information Platform Services

        The Information Platform Services provide functions to manage the enterprise information sphere. They include generic services that deal with information transformation, provision and maintenance including quality assurance.

        • CR-1086 Information Discovery Services

          The Information Discovery Services provide functions to automate the discovery and retrieval of information products and their structure. Information products, in this regard, are aggregates of structured data. Discovered data is the result of a search upon an entire dataset, a search upon a subset of a dataset, or a search based on dataset and/or content metadata.

        • CR-1083 Information Access Services

          The Information Access Services provide functions to transform information stores or sources into web enabled services. The services provide a generic capability that can be configured as required to expose new information stores or sources in the required service protocols and formats. The intent is to minimize custom services and allow agile provisioning of new capabilities based on evolving operational requirements. By focusing on providing access to information from existing stores and sources, rather than on providing applications which use that information, these services de-couple the access to information from the use of the information. Since applications can use information in any number of ways to support any number of use cases, de-coupling the access to information from its use reduces the complexity and the combinations of interfaces which must be supported.

        • CR-1084 Information Aggregation Services

          The Information Aggregation Services provide functions to pull together related information from multiple (often heterogeneous) sources and present it as a single information set. This allows the easy integration of the aggregated information into other contexts, such as business processes, mash-ups, gadgets and business intelligence applications.

        • CR-1100 Metadata Repository Services

          The Metadata Repository Services provide functions to store, query and retrieve authoritative metadata within the enterprise. The services offer administrative as well as programmatic interfaces for metadata registries and repositories. The registries and repositories can be federated across the enterprise, thus these services support federation for storing, querying and retrieving metadata (i.e. for single central registries/repositories as well as multiple registries/repositories throughout the network). The services store a wide range of standards and specifications that describe the structure, format and definitions of data, as well as the relationships among data elements. These standards and specifications are stored in machine readable formats that can be interpreted automatically within the service-oriented environment (e.g. XML schemas, ontologies). It gives developers and architects visibility into methods to compose and encode data and to share usage across the organization. Registration of such metadata is especially critical to achieve the data goals of interoperability and coherence by promoting semantic and structural understanding.

        • CR-1085 Information Annotation Services

          The Information Annotation Services provide functions to annotate and enhance information objects with additional information such as: metadata, tags, comments, attachments, relationship with other information objects and/or content. An annotation is a collection of assertions about one or more information objects and so must be able to uniquely reference those objects. Further, annotations are made by an entity, user, system etc. and so information such as who created the annotation, when it was created, the confidence, reliability and authenticity of the assertions must also be recorded. The services allow for persisting, searching and retrieving these annotations. Since the annotations are additional information that makes reference to existing information, these services can be logically decoupled from the service providing that existing information. Furthermore, they can be complemented by Information Discovery Services that allow information consumers to query not only the original information objects but also any annotations which relate to them.

        • CR-1068 Business Rules Services

          The Business Rules Services provide functions to create, test, manage, deploy and maintain business rules in an operational environment. These business rules are statements describing a business/enterprise policy or procedure (e.g. discount calculation) and can be represented using formal language.

        • CR-1149 Information Delivery Services

          The Information Delivery Services provide function to orchestrate and deliver content within a heterogeneous service-provisioning ecosystem. The services distribute static and dynamic information, such as images, videos, stylesheets, scripts, and other web content, across a network of edge servers. Those servers are strategically positioned in various geographical locations within the enterprise network. These edge servers store replicated or cached copies of content and deliver them to users based on their geographic or network proximity reducing the physical distance data needs to travel. This reduces the load on the origin, minimizes latency, accelerates the loading times of web content and ensures a faster and more responsive user experience.

      • CR-1071 Composition Services

        The Composition Services provide functions to access and fuse data and behavior on demand, and return a single result to the consumer. The services can, from queues and/or in batch, provide a set of data transforms and routings to transactions that can serve machine-to-machine business processes. A service composition is a coordinated aggregate of services. The consistent application of service-orientation design principles leads to the creation of services with functional contexts that are agnostic to any one business process. These agnostic services are therefore capable of participating in multiple service compositions. Services are expected to be capable of participating as effective composition members, regardless of whether they need to be immediately enlisted in a composition. There are two aspects of composition: composition synthesis is concerned with synthesizing a specification of how to coordinate the component services to fulfil the client request; and orchestration, is concerned with how to actually achieve the coordination among services, by executing the specification produced by the composition synthesis and by suitably supervising and monitoring that execution.

        • CR-1104 Orchestration Services

          The Orchestration Services provide functions to coordinate the execution of multiple technical services in such a way that the coordinated whole of technical services appears as a single, aggregate technical service responding to a single individual request. Such an aggregation could be said to implement a business process that is characterized by the fact that it runs within own organization boundaries, with the own organization having full control over the execution of the process. Orchestration describes one particular component activity of the composition that oversees and directs the other component activities. An orchestration has one and only one direction activity. In a service-oriented software solution, the component services of an orchestration are software services performed by software programs. A service composition described by an orchestration is again a service itself and can be re-used in further compositions.

        • CR-1070 Choreography Services

          The Choreography Services provide functions to model the compositions of multiple technical services into so called choreographies and to specify the interfaces and protocols implemented by services participating in a choreography. Choreography mechanisms are used to specify the coordination agreement and behaviour of each service in choreography, including the external interfaces exposed by the services involved and the protocol implemented by each of the services involved, including order of messages being exchanged and specification of services that these messages will be exchanged with. Choreography is a set of autonomous activities that have a defined pattern of behaviour with respect to each other. There is no single activity that directs the other activities in choreography. Choreography distributes the control and relies on the ability of its component activities to understand and respond to events. Choreography treats services as peers that interact based on an agreement, rather than imposing a single-point-of-entry brokering pattern on top of them. In a choreography scenario composition is understood as the collaborative exchange that takes place based on the description of messages exchange and the interaction of a set of services seen from a global perspective.

        • CR-1125 Transaction Services

          The Transaction Services provide functions to link multiple individual actions together as a single, indivisible activity. All actions in a transaction are either completed without error or none of them are; if some of the actions are completed but errors occur when the others are attempted, the transaction-processing system rolls back all of the actions of the transaction (including the successful ones), thereby erasing all traces of the transaction and restoring the system to the consistent, known state that it was in before processing of the transaction began. In scenarios when usual transactional properties (like atomicity, consistency, isolation, and durability) are too strong or unimplementable (e.g. in complex business processes), some limited transactional properties must be satisfied to guarantee a process is not left in an inconsistent state. For example, compensating activities can bring the process to a consistent state, albeit not necessarily identical as the state before the process started.

      • CR-1093 Mediation Services

        The Mediation Services provide functions to establish a middle layer between incompatible producers of information and consumers of information. The services process the data of the information producer and transform it into a representation which is understandable for the consumer. In doing so, Mediation Services bridge the gap between both parties, enabling interaction between them which has not been possible beforehand.

        • CR-1116 Protocol Transformation Services

          The Protocol Transformation Services provide functions to mediate between communication parties by adjusting the way in which data is exchanged between both parties. The services enable the use of different protocols for handling information between information providers and consumers over a possibly heterogeneous network. They are important when different types of communication patterns are being used (e.g. static, deployable or mobile) that would require special protocols to ensure that the information is being transferred in the most efficient possible way. The services mediate between various transport protocols, which, for example, in a web services setting usually comprise single protocols like HTTP, HTTPS, TLS, SMTP and FTP, but also entire message-oriented middle-ware solutions like IBM's WebSphere MQ or JMS.

        • CR-1073 Data Format Transformation Services

          The Data Format Transformation Services provide functions to encode information in different formats. This is needed when information consumers cannot directly process the information in the format chosen by the information provider. The services also play a role when the boundary between one network type to another is crossed (e.g. static IP network to tactical radio network) and a conversion from one data representation to another (e.g. for bandwidth utilization purposes) is required. The relation between the data and the information which it represents can be changed during a data format transformation. To this regard important aspects of data transformation include format conversion where data is encoded differently using another format. Both data encodings represent the same information and are usually compatible. Typical examples are the conversion of temperature from Celsius to Fahrenheit, or the conversion of the bit representation between Big- and Little-Endian formats.

    • CR-1047 Infrastructure Services

      The Infrastructure Services provide functions to host infrastructure services in a distributed and/or federated environment in support of operations and exercises. They include computing, storage and high-level networking services that can be used as the basis for data centre or cloud computing implementations. The services are aligned with "Infrastructure as a Service" (IaaS) concepts that are used and promoted by industry today as part of their cloud computing developments.

      • CR-1039 Infrastructure CIS Security Services

        The Infrastructure CIS Security Services provide functions to implement and enforce CIS Security measures at the infrastructure level.

        • CR-1022 Digital Identity Services

          The Digital Identity Services provide functions to capture, record, and validate information to uniquely identify an individual human or entity, determine suitability, and to create and manage a digital identity over the full identity life cycle (e.g. on-boarding, off-boarding, commissioning, de-commissioning) and continuously enforce dynamically updated identity policies across the enterprise. Digital identity is the representation of identity in a digital environment. Identity attributes may be part of a larger federated community and may include non-enterprise employees or links to non-enterprise assets for collaboration. The services integrate identity stores across federated environments (e.g. self-managed, hosted, and cloud-based) in support of Authentication Services.

        • CR-1017 Credentialing Services

          The Credentialing Services provide functions to bind an identity to a physical or digital credential, which can subsequently be used as a proxy for the identity or proof of having particular attributes. These services manage the full lifecycle of hardware and software-based credentials in support of Authentication and Authorization Services. Different types of credentials may be issued (e.g. smart card, badges, identification documents, software certificates or passwords) with different kinds of protection mechanisms against physical and other types of attacks, depending on the acceptable assurance level for the mission.

        • CR-1006 Authentication Services

          The Authentication Services provide functions to verify that a claimed identity is genuine and based on valid credentials (as provided by the Credentialing Services). Authentication typically leads to a mutually shared level of assurance by the relying parties in the identity.

          • CR-1169 Password Authentication Services

            Password Authentication Services offer a traditional, single-factor authentication method by validating users through passwords. Password Authentication Services store passwords as hashed and salted entries in a secure database, providing robust protection against unauthorized access. Password authentication is simple to implement and widely supported across systems but is often paired with MFA for added security. This service manages password complexity policies, expiration, and history to encourage secure password practices. By adding configurable rules for password strength, the service reduces vulnerability to common password-based attacks, such as brute force or credential stuffing. ==Key Features== • Encrypted storage of hashed and salted passwords in a secure database. • Enforces password policies (complexity, expiration, reuse restrictions). • Supports integration with Identity and Access Management systems for centralized user management. • Generates audit logs of login attempts for compliance and security analysis. • Configurable password recovery and reset mechanisms.

          • CR-1170 Multi-Factor Authentication Services

            The Multi-Factor Authentication (MFA) Services provide functions to add multiple verification layers, requiring users to authenticate through a combination of credentials. Typically, these include something the user knows (password), something the user has (OTP, smartphone), and something the user is (biometric data).

          • CR-1172 Biometric Authentication Services

            Biometric Authentication Services verify a user’s identity by analyzing unique physical characteristics like fingerprints, facial recognition, voice recognition, or iris scans. These services integrate with specialized hardware (e.g., fingerprint readers or cameras) to capture and process biometric data, storing it as encrypted templates. During authentication, new biometric data is compared with stored templates to confirm identity. Commonly used in high-security environments like banking and healthcare, biometric services enhance security by providing a difficult-to-duplicate authentication factor, ensuring the data is securely stored and accessed only by authorized applications. ==Key Features== • Supports multiple biometric methods (fingerprint, facial, voice recognition). • Secure biometric data storage using encryption and secure hardware enclaves. • Rapid matching and verification process to minimize delays in authentication. • Compliance with privacy standards for biometric data handling (e.g., GDPR). • Seamless integration with identity management systems for centralized access control.

          • CR-1173 Certificate-Based Authentication Services

            The Certificate-Based Authentication Services provide functions to leverage digital certificates as a secure and verified credential for authenticating users, devices, or applications. By using certificates issued by a Certificate Authority (CA) within a Public Key Infrastructure (PKI), this service ensures that only verified entities can access sensitive resources.

          • CR-1174 Adaptive Authentication Services

            Adaptive Authentication Services, also known as risk-based authentication, dynamically adjust security requirements based on real-time contextual data (e.g., location, device type, IP address). By analyzing these factors, the service can either increase or decrease security requirements based on the perceived risk level. For example, if a login attempt occurs from an unfamiliar device or location, additional verification steps like MFA may be required. This approach minimizes friction for users in low-risk situations while ensuring high security for suspicious activity, making it particularly valuable for applications with varying risk profiles. ==Key Features== • Assesses contextual and behavioral factors to determine risk level. • Dynamically adjusts authentication requirements based on real-time risk. • Supports integration with device recognition, IP analysis, and geolocation. • Enhances user experience by minimizing unnecessary security prompts. • Monitors session activity to detect and respond to anomalies in real time.

          • CR-1175 Token Authentication Services

            Token Authentication Services facilitate secure access by issuing time-bound, unique tokens upon successful initial authentication. When a user first logs in, the service verifies their credentials and issues a token (e.g., JWT, OAuth token) that can be used for continued access without re-authentication. This token is presented to services, which validate its authenticity and expiration. Ideal for web and mobile applications, token authentication provides security without requiring users to repeatedly enter credentials. Tokens are encrypted and transmitted over secure channels, and session management policies ensure tokens expire or refresh aftr specific periods. ==Key Features== • Issuance of unique, encrypted tokens for session-based or API access. • Configurable token expiration and refresh policies for session management. • Supports various token formats, including JWT, SAML, and OAuth tokens. • Seamless integration with web applications and RESTful APIs. • Enhanced security via secure token storage and encrypted transmission.

        • CR-1053 Privilege Management Services

          The Privilege Management Services provide functions to establish and maintain the entitlement or privilege attributes that comprise an individual's access profile. These attributes are features of an individual that can be used as the basis for determining access decisions to both physical and digital resources. The Privilege Management Services govern the management of the data that constitutes the user's privileges and other attributes regarding the storage, organization and access to information.

        • CR-1007 Authorization and Access Control Services

          The Authorization and Access Control Services provide functions to grant or deny access to all resources accessible through the network, including information processing services and data, as well as physical facilities. They enforce information security and management policies by ensuring individuals can only access those resources they are entitled to use for approved purposes, as well as provide an audit trail of access and permission activities. Authorization Services can grant just-in-time and just-enough expiring (privileged) access tailored to individual actions and resources and support automated and periodic review/audit mechanisms by the Security Audit Services. Enforcement can take place within identity and access infrastructure or through dedicated policy enforcement and control points. There are two possible approaches: Attribute-based Access Control (ABAC) and Role-based Access Control (RBAC).

        • CR-1021 Digital Certificate Services

          The Digital Certificate Services provide functions to create, manage, distribute, use, store, suspend, resume and revoke digital certificates. They provide a trust framework across organizational, operational, physical, and network boundaries, required to enable the services that rely on digital certificates.

          • CR-1182 Digital Certificate Issuance Services

            The Digital Certificate Issuance Services provide functions to create and distribute digital certificates, which are electronic credentials that bind an entity's public key to its identity. These certificates are issued by a trusted Certificate Authority (CA) after verifying the identity of the requesting party.

          • CR-1183 Digital Certificate Validation Services

            The Digital Certificate Validation Service provide functions to ensure the validity and authenticity of certificates used in secure communications or transactions. The services enable mechanisms to confirm the authenticity and validity of a digital certificate in real-time. These services ensure that the certificate has been issued by a trusted Certification Authority (CA) and has not been revoked or expired.

          • CR-1184 Digital Certificate Revocation Services

            The Digital Certificate Revocation Services provide functions to revoke a certificate before it expires, which is no longer valid due to compromise, expiration, or mis-issuance. Revocation information is made available to Digital Certificate Validation services through CRL distribution points (as indicated within the certificate) or through a separate service (OCSP).

          • CR-1185 Digital Certificate Monitoring and Audit Services

            The Digital Certificate Monitoring and Audit Services provide functions to oversee the lifecycle of digital certificates to ensure compliance with policies and detect anomalies. These services provide visibility into certificate usage, expiration, and renewal statuses, enabling proactive management. Auditing ensures that certificate operations comply with regulatory or organizational standards.

        • CR-1048 Intrusion Detection Services

          The Intrusion Detection Services enable visibility into intrusion events, possible incidents, policy violations, and potential malicious activity, including from social engineering. It can warn about possible ongoing attacks against resources by leveraging access logs, especially for privileged credentials. Intrusion Detection Services can provide automated real-time behaviour-based analysis, for example through correlation between log types, using the latest information regarding vulnerabilities, using heuristics, and leveraging Artificial Intelligence (AI). The collected security centric information from the analyses can be used to refine policies. Intrusion Detection Services can also help identify gaps in visibility, for example missing log or log types, to direct augmentation in the collection of logs. Intrusion prevention systems are considered extensions of intrusion detection systems because they both monitor network traffic and/or system activities for malicious activity. The main differences are, unlike intrusion detection systems, intrusion prevention systems are placed in-line and are able to actively prevent or block intrusions that are detected.

        • CR-1051 Malware Detection Services

          The Malware Detection Services provide functions to prevent, detect, and remove malware, including but not limited to computer viruses, computer worms, trojan horses, spyware, social engineering exploits and adware.

        • CR-1041 Infrastructure Guard Services

          The Infrastructure Guard Services provide functions to connect networks of different information domains and usage areas while controlling data flow between the networks using a set of predefined rules.

        • CR-1195 Computational Governance Services

          The Computational Governance Services provide functions to ensure that the enterprise remains compliant with any regulatory regime by the employment of rule engines, audit logs, and real-time analytics to monitor compliance with governance policies continuously. These result in an automated enforcement of data quality, protection, and compliance policies, reducing the burden on manual oversight. The services can provide an integrated way of managing devices, virtual assets, software, configurations, and vulnerabilities across all environments.

        • CR-1040 Infrastructure Cryptography Services

          The Infrastructure Cryptography Services provide functions to use different ciphers including encryption and decryption processes to ensure confidentiality and integrity of data at rest, in transit, and in use, while allowing to switch between different cryptographic algorithms and mechanisms without disrupting functionality for cryptographic agility. Typically, asymmetric cryptography is used for authenticated key exchange, symmetric encryption for data confidentiality, and cryptographic hash functions and digital signatures for data integrity.

      • CR-1046 Infrastructure SMC Services

        The Infrastructure Service Management and Control (SMC) Services provide functions to implement and enforce SMC policies at the Infrastructure level. The services coordinate and communicate with other technical services (Communications Services, Platform Services, etc.) to fulfil the requirements of service delivery. The requirements are translated into Infrastructure specific parameters and distributed to other Infrastructure Services.

        • CR-1045 Infrastructure Provisioning Services

          The Infrastructure Provisioning Services provide functions to manage the instantiation, runtime management and disposal of dynamically scalable and virtualized infrastructure resources. The services sustains the infrastructure footprint for all consumers and locations continuously.

        • CR-1042 Infrastructure Logging Services

          The Infrastructure Logging Services provide functions to capture significant events and errors in a distributed (and often virtualized) environment for the purpose of regulatory compliance, (security) auditing, and trouble shooting. Infrastructure/Network and System Activity Logging Services also aggregate asset logs, network traffic, resource access actions, and other events that provide real-time (or near-real-time) feedback on the security posture of enterprise information systems to Intrusion Detection (and Prevention) Services.

        • CR-1126 Virtualization Management Services

          The Virtualization Management Services provide functions to interface with virtual environments and the underlying physical hardware to: manage resource administration (discovering, configuring, managing and monitoring virtual and physical resources); enhance data analyses; and streamline service operations. These services automate management tasks, including workload placement and rebalancing to enable infrastructure and application performance, optimizing resources, and enforcing security measures. The services also automate service monitoring and apply real-time log analytics as well as predictive analytics.

        • CR-1044 Infrastructure Monitoring Services

          The Infrastructure Monitoring Services provide functions to monitor the health and performance of Infrastructure Services and services upon which they are dependent. In case of an exception or fault, an alarm will be raised to notify the appropriate actors.

        • CR-1043 Infrastructure Metering Services

          The Infrastructure Metering Services provide functions to measure the utilization of Infrastructure resources over specific period of times. Metering measures levels of resource utilization such as number of virtual machines (VMs) created and used, CPU cycles/time, allocated amount of RAM, incoming and outgoing network bandwidth, data storage volume, etc. over various periods of time (e.g. second, hour, week, month, year). Calculated average values of the measurements can be then used to enforce Service Level Agreements (SLAs), load balancing, for billing purposes and overall usage trend forecasting.

        • CR-1124 Time Zone Data Distribution Services

          The Time Zone Data Distribution Services provide functions to deliver time zone data and leap-second rules to client systems - such as calendaring and scheduling applications or operating systems. These services produce data for the set of time zones known to servers and expected to be used by clients. These are key services to ensure server-to-server and client-to-server content interoperability. If such services are not available, all participants would need to agree up front to configure their systems with a common timezone reference datasource.

      • CR-1090 Infrastructure Processing Services

        The Infrastructure Processing Services provide functions to access physical and/or virtual computing resources. They primarily provide operating system (OS) capabilities to time-share computing resources (e.g. CPU, memory and input/output busses) between various tasks, threads or programs based on stated policies and algorithms.

        • CR-1103 Operating System Services

          The Operating System (OS) Services provide functions to manage platform resources, including the processor, memory, files, input and output. The services typically encompasses kernel operations, command interpreter, batch processing, file and directory synchronization services.

        • CR-1128 Virtualized Processing Services

          The Virtualized Processing Services provide functions to establish simplified, fit-for-purpose, tailor-made and on-demand IT infrastructure resources. The services support the centralization of management and maintenance while more flexibly and efficiently allocating IT infrastructure resources. They hide the physical characteristics of a processing platform and present an abstracted processing platform to the consumer. Hence the user is spared from having to understand and manage complex details of IT infrastructure resources.

        • CR-1078 Distributed Processing Services

          The Distributed Processing Services provide functions to manage the task dispatching, scheduling and execution across a cluster of nodes. It provides more scalable, more durable, more changeable and more fine-tuned than a monolithic application deployed on a single machine.

        • CR-1072 Container Runtime Services

          The Container Runtime Services provide functions to execute and manage containers on a host machine by interacting with the underlying operating system's kernel. Containers are lightweight, portable, and consistent environments that encapsulate an application and its dependencies. The container runtime is the component that allows these containers to be executed on a host system. While container runtime services are a fundamental component for running containers on a single host, when dealing with orchestrating containers across a cluster of machines, additional Container Orchestration Services are used to manage the deployment and scaling of containers.

        • CR-1199 Trusted Execution Environment Services

          The Trusted Execution Environment (TEE) Services provide functions to maintain a secure enclave within a CPU, using embedded encryption keys and embedded attestation mechanisms that ensure the keys are accessible to authorized application code only. If malware or other unauthorized code attempts to access the keys or if the authorized code is hacked or altered in any way, the TEE denies access to the keys and cancels the computation. In this way, sensitive data can remain protected in memory until the application tells the TEE to decrypt it for processing. While decrypted and throughout the entire computation process, the data is invisible to the operating system (or hypervisor in a virtual machine), to other compute stack resources, and to the cloud provider and its employees.

      • CR-1091 Infrastructure Storage Services

        The Infrastructure Storage Services provide functions to access shared physical and/or virtual storage components for data persistence. The services offer data retention at different levels of complexity, ranging from simple block level access to sophisticated big data object storage. The services also need to provide a cloud-to-edge storage management framework that supports both legacy enterprise storage and modern cloud services for infrastructure automation and data-driven decision-making.

        • CR-1067 Block-Level Storage Services

          The Block-Level Storage Services provide functions to access physical and/or virtual storage devices that manage their available space as a sequence of fixed size data blocks. Consumers of these services are responsible for giving meaning to each of the blocks and often file systems or relational databases are used to abstract block-level storage.

        • CR-1146 Storage Load Balancing Services

          The Storage Load Balancing Services provide functions to evenly distribute data access and storage workloads across multiple cloud based storage services, devices or arrays. The services are a critical component of a storage architecture, the primary objective is to enhance performance, maximize resource utilization, and ensure high availability of data.

        • CR-1081 File System Storage Services

          The File System Storage Services provide functions to access named storage containers. The services offer logical access to data since they abstract away physical storage topologies. These services also transparently handle fragmentation, caching and storage integrity.

        • CR-1129 Virtualized Storage Services

          The Virtualized Storage Services provide functions to hide the physical characteristics of a storage platform and instead present abstracted storage platform to the consumer. Virtualization enables the provisioning of simplified, fit-for-purpose, tailor-made and on-demand IT infrastructure resources, sparing the user from having to understand and manage complex details of IT infrastructure resources. These services support the centralization of management and maintenance while more flexibly and efficiently allocating IT infrastructure resources.

        • CR-1066 Object Storage Services

          The Object Storage Services provide functions to manage data as "blobs" or "objects", as opposed to other storage architectures like file systems, which manage data as a file hierarchy, and block storage, which manages data as blocks within sectors and tracks. Each object is typically associated with a variable amount of metadata, and a globally unique identifier. Object storage can be implemented at multiple levels, including the device level (object-storage device), the system level, and the interface level. In each case, object storage seeks to enable capabilities not addressed by other storage architectures, like interfaces that are directly programmable by the application, a namespace that can span multiple instances of physical hardware, and data-management functions like data replication and data distribution at object-level granularity. Object storage systems allow retention of massive amounts of unstructured data in which data is written once and read once (or many times).

        • CR-1197 Content-Addressable Storage Service

          The Content-Addressable Storage (CAS) Services provide functions to store and retrieve files or data objects based on their content, rather than their physical location or file name. Using cryptographic hash functions, the services generate a unique identifier for each piece of content, ensuring efficient data deduplication, integrity verification, and immutability. This means that identical data only needs to be stored once, saving storage space, while also making it easy to detect and prevent tampering or corruption. CAS services are especially useful in scenarios like backup systems, version control, and distributed storage networks, offering scalable, secure, and high-integrity data management.

        • CR-1137 Distributed Object Storage Services

          The Distributed Object Storage Services provide functions to manage objects (data) in an object-storage system. Object storage is a data storage architecture for handling large amounts of unstructured data. Objects can be stored locally, but most often reside on cloud servers, with accessibility from anywhere via the network. Each object is a simple, self-contained repository that includes the data, metadata (descriptive information associated with an object), and a unique identifying ID number (instead of a file name and file path). This information enables an application to locate and access the object. Software-defined object storage solutions aggregate individual object storage devices into larger storage pools, which can be distributed across different locations. This allows for unlimited scale, policy-driven data-management functions like data replication and data distribution at object-level granularity, to optimize data availability, protection, performance, and cost.

      • CR-1089 Infrastructure Networking Services

        The Infrastructure Networking Services provide functions to access high-level protocols and methods that fall into the realm of process-to-process communications across an Internet Protocol (IP) network. They are akin to components in the Open Systems Interconnection's (OSI) application layer but are limited to those services required for the infrastructure layer in that taxonomy. OSI application layer protocols such as those for e-mail and directory services are covered by other Core Enterprise Services.

        • CR-1069 Caching Services

          The Caching Services provide functions to accelerate service requests by retrieving content saved from a previous request, allowing organizations to significantly reduce their upstream bandwidth usage and costs, while simultaneously increasing performance. This means that the requested resource does not need to be downloaded from a remote server, possibly over a connection with limited bandwidth, but can be retrieved from a store located on the local LAN. Caching Services do this by keeping local copies of requested resources and serving those to the client rather than fetching them from the original server. If the resource is not already present in the cache, then it is retrieved from the requested URL, and a copy is written to the local store. Caching Services are often used by Proxy Services, and are indeed often collocated with them. However, they are separate, and an entire caching infrastructure can be built independent of proxy services.

        • CR-1117 Proxying Services

          The Proxying Services provide functions to handle HTTP message exchanges on behalf of other entities. From the perspective of the counterpart in the message exchange, it is communicating with the proxy, and is not necessarily aware that this is the case. The services tend to sit at the boundaries of organizations, either internal boundaries (between sites, before WAN links) or external boundaries (such as the Internet). They can be delivered through either one of three types: Forward Proxy, Reverse Proxy or transparent Proxy.

        • CR-1115 Printing Services

          The Printing Services provide functions to produce electronic records in a physical format. A variety of objects can be created from the basis of electronic files in a variety of physical formats. Most commonly, a printer can create documents by putting ink on paper or other carriers. Nonetheless, there are different types and styles of printers with varying technology, capabilities and printing methods. For instance, printers can also be used to create three-dimensional objects.

        • CR-1121 Scanning Services

          The Scanning Services provide functions to survey physical objects and record these in electronic form. A variety of objects can be scanned, accessed, edited, exported, transmitted using scanners and associated processing software for proper application of information. The scanning is executed on devices that use optical, mechanical or other techniques to survey the objects. For instance, it scans text, pictures, film and other two-dimensional objects into file formats. that can be processed by computers. These techniques can also be used to can scan three-dimensional objects from various angles as to build op an electronic copy on a computer for further storage and processing.

        • CR-1127 Virtualized Networking Services

          The Virtualized Networking Services provide functions to consolidate multiple physical networks, divide a network into multiple segments or create software-only networks between virtual machines (VMs). The goal of network virtualization is to improve the agility to direct appropriate network resources to VMs in data center environments and the ability to consolidate or segment networks. Virtual networks can be created in two ways – inside or outside the server. External software uses switches, adapters and the network to aggregate physical local area networks (LANs) into a single logical LAN, or to break a physical LAN into multiple virtual LANs (VLANs). Internal software allows virtual machines (VMs) to exchange data on a host without an external network. Virtualized Networking Services may also perform micro-segmentation by creating an overlay network at OSI layer 7 or a lower layer. Such a Software-Defined perimeter (SDP) may use concepts from Software Defined Networks (SDN) and Intent-Based Networking (IBN).

        • CR-1082 Host Configuration Services

          The Host Configuration Services provide functions to complete a subscription to a network with configuration parameters. The required parameters are determined by the network being subscribed to, but may include the host address, sub-net mask, name server and others.

        • CR-1101 Network Load Balancing Services

          The Network Load Balancing Services provide functions to distribute workload across the network, to multiple processing resources, network links, central processing units, disk drives, or other resources, to achieve optimal resource utilization, maximize throughput, minimize response time, and avoid overload. Using multiple components with load balancing, instead of a single component, may increase reliability through redundancy.

        • CR-1074 Data Transfer Services

          The Data Transfer Services provide functions to establish data communications for other services and applications, making use of the IP communication layers in LAN infrastructure and/or Communications Services. The data transfer functions have many dimensions for various data transfer scenarios, the major emphasis being on the following: • Synchronous – Asynchronous • Connection Oriented – Connectionless • Point to Point – Point to Multipoint • Real Time – Non Real Time • Guaranteed – Not Guaranteed

        • CR-1080 Domain Name Services

          The Domain Name Services (DNS) provide functions to access a hierarchical distributed naming system for computers, services, or any resource connected to the Internet or a private network. The services associate various information with domain names assigned to each of the participating entities. Most importantly, these services translate domain names meaningful to humans into the numerical identifiers associated with networking equipment for the purpose of locating and addressing these devices worldwide.

        • CR-1092 Location Awareness Services

          The Location Awareness Services provide functions to access geographic and/or network location data of a device that have been acquired through multiple sources including network carriers, Wi-Fi, IP addresses and landlines. Location data provided through Location Awareness Services can be used to realize greater operational efficiencies, optimize information management and increase security. Location awareness services are typically actively supported by devices using positioning systems, without the active participation of the device "non-cooperative locating" or detection mechanisms can be used.

        • CR-1079 Distributed Time Services

          The Distributed Time Services provide functions to execute synchronized time co-ordination as required among distributed processes when executed on different infrastructure segments and across time zones. This will ensure that information from each entity as well as data from each source is consistently timestamped and that it all can be referenced accurately throughout the federation. Consistent time is an essential prerequisite for the correct function of user applications and of infrastructure services like authentication, authorization services and message loggers.

        • CR-1119 Remote Access Services

          The Remote Access Services provide functions to remotely access the user interface of a computing resource for the purpose of installation, configuration, monitoring, metering, auditing or process management.