ISO/IEC 24760-1:2025
Information security, cybersecurity and privacy protection — A framework for identity management — Part 1: Core concepts and terminology
Information security, cybersecurity and privacy protection — A framework for identity management — Part 1: Core concepts and terminology
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 23
- Дата публикации:
- 16 сентября 2025 г.
- Издание:
- ISO/IEC IS 24760 edition 3 version 1
- ICS:
- 01.040.35
This document: defines terms for identity management and specifies core concepts of identity and identity management, and their relationships; is applicable to any information system where information relating to identity is processed or stored; is considered to be a horizontal document for the following reasons: it applies concepts such as distinguishing the term “identity” from the term “identifier” on the implementation of systems for the management of identity information and on the requirements for the implementation and operation of a framework for identity management, it provides an important contribution to assess identity management systems with regard to their privacy-friendliness and their ability to assure the relevant attributes of an identity, and consequently it provides a foundation and a common understanding for any other standard addressing identity, identity information, and identity management.
Abstract
Overview
ISO/IEC 24760-1:2025 is an international standard developed by ISO and IEC to provide a unified framework and terminology for identity management in information security, cybersecurity, and privacy protection contexts. This foundational document defines the core concepts and terms related to identity, identifiers, credentials, and identity management processes. Its purpose is to create a common understanding across various industries and sectors, ensuring consistency in the interpretation and implementation of identity management systems.
This standard is applicable to any information system where identity-related data is processed or stored. By clarifying terms such as "identity," "identifier," and "attribute," the document supports robust identity management, privacy protection, and regulatory compliance. As a horizontal standard, ISO/IEC 24760-1:2025 forms the basis for other standards dealing with identity and identity information.
Key Topics
- Core Terminology: Clearly defines critical terms including entity, identity, identifier, attribute, credential, authentication, principal, and domain, supporting consistent communication and implementation.
- Identity and Identifier Distinction: Explains the difference between identity (a set of attributes relating to an entity) and identifier (a unique characteristic within a domain), which is fundamental in developing identity management systems.
- Identity Lifecycle: Outlines processes such as identification, enrolment, verification, registration, authentication, and management of identity information.
- Identity Management Systems: Describes mechanisms, policies, and procedures for maintaining identity and associated metadata across systems and domains.
- Privacy and Security Principles: Covers selective disclosure, minimal disclosure, pseudonym usage, and privacy protection requirements in identity management.
- Federation and Interoperability: Discusses the concept of identity federation for cross-domain identity management and trust establishment.
Applications
ISO/IEC 24760-1:2025 has broad applicability across multiple domains and industries where secure and private management of identity information is essential:
- Information Security Programs: Lays down the vocabulary and baseline concepts for developing secure identity management frameworks.
- Cybersecurity Initiatives: Assists organizations in building resilient authentication and authorization mechanisms, reducing security risks.
- Privacy Compliance: Supports adherence to privacy regulations by detailing privacy-friendly identity management features such as selective and minimal disclosure.
- System Architecture: Guides IT architects and system designers in the development and evaluation of technical solutions for identity registration, proofing, authentication, and federation.
- Digital Services: Facilitates trusted access control and user management in cloud services, online platforms, and digital government solutions.
- Interoperability and Standardization: Acts as the reference point for integrating different identity management systems and aligning with other international standards.
Related Standards
- ISO/IEC 24760-2 – Reference architecture and requirements for identity management, which complements the core concepts by specifying the technical architecture.
- ISO/IEC 29100 – Privacy framework, providing a high-level privacy standard that interfaces with identity management systems.
- ISO/IEC 29101 – Privacy architecture framework, relevant for designing privacy-enhanced identity systems.
- ISO/IEC 29115 – Entity authentication assurance framework, detailing assurance levels for identity verification.
- ISO/IEC 29146 – A standard that addresses governance of identity management.
Conclusion
ISO/IEC 24760-1:2025 is a cornerstone standard that ensures a common language and understanding for identity management across information security, cybersecurity, and privacy protection landscapes. By applying its framework, organizations can enhance the security, privacy, and effectiveness of their identity management systems, while supporting regulatory compliance and interoperability with global standards. For professionals seeking to implement, evaluate, or audit identity systems, this standard offers essential guidance and a solid conceptual foundation.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 24760-1:2025
Похожие стандарты
Стандарты, упомянутые в описании