Overview
EN ISO/IEC 24760-2:2022 / ISO/IEC 24760-2:2015 defines a reference architecture and requirements for an identity management framework. It provides guidelines for the implementation, operation and governance of systems that create, store, process or use identity information (for people, organizations, devices or software). The standard is applicable to any information system handling identity data and complements other identity, privacy and access-management standards.
Key topics and technical requirements
- Reference architecture: core architecture elements, component model and their relationships; views include context, functional and physical viewpoints.
- Viewpoints and models: stakeholder and actor definitions, context model, use-case model, compliance and governance model.
- Processes and services: specification of identity-management processes for issuance, administration, use and lifecycle management of identity information.
- Identity management scenarios: enterprise, federated, service and heterogeneous deployment scenarios are described to guide implementations.
- Identity information requirements:
- Access policy for identity information and governance requirements.
- Lifecycle policy: rules for creation, maintenance, archiving, termination and deletion.
- Interfaces and identifiers: requirements for identity information interfaces and reference identifiers.
- Quality and compliance: data quality, integrity and compliance requirements.
- Non‑functional requirements: performance, availability, scalability and security considerations.
- Legal and regulatory aspects: informative guidance on lawful processing and privacy implications.
Practical applications and who uses it
This standard is practical for organizations designing, procuring or operating identity and access management (IAM) systems. Typical users:
- Enterprise architects and solution architects designing IAM reference architectures.
- Security engineers and IAM implementers configuring identity stores, provisioning and federation.
- IAM vendors and product teams aligning products to standard architecture and interfaces.
- Compliance officers, data protection officers and auditors ensuring identity data handling meets governance and legal requirements.
- System integrators implementing federated identity, single sign-on (SSO), provisioning, and identity lifecycle processes.
Use cases include enterprise IAM rollouts, federated identity between organizations, service-provider identity integration, and modernization of identity stores to meet privacy and regulatory obligations.
Related standards
EN ISO/IEC 24760-2 provides a practical, standards-based foundation to design interoperable, secure and compliant identity management systems. Keywords: identity management, reference architecture, identity information, ISO/IEC 24760-2, IAM, identity lifecycle, identity governance.