I think the administrator should have the ability to sign alerts created by the OISF engine with PGP. The administrator could use the private/public key model so they would be able to tell if the alerts had been spoofed or altered. -Josh