ISO/IEC 24760-2:2025
Information security, cybersecurity and privacy protection — A framework for identity management — Part 2: Reference architecture and requirements
Information security, cybersecurity and privacy protection — A framework for identity management — Part 2: Reference architecture and requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 46
- Дата публикации:
- 16 сентября 2025 г.
- Издание:
- ISO/IEC IS 24760 edition 2 version 1
- ICS:
- 35.030
This document: provides guidelines for the implementation of systems for the management of identity information; specifies requirements for the implementation and operation of a framework for identity management; is applicable to any information system where information relating to identity is processed or stored; is considered to be a horizontal document for the following reasons: it applies concepts such as distinguishing the term “identity” from the term “identifier” on the implementation of systems for the management of identity information and on the requirements for the implementation and operation of a framework for identity management, it provides an important contribution to assess identity management systems with regard to their privacy-friendliness and their ability to assure the relevant attributes of an identity, and consequently it provides a foundation and a common understanding for any other standard addressing identity, identity information, and identity management.
Abstract
Overview
ISO/IEC 24760-2:2025 - "Information security, cybersecurity and privacy protection - A framework for identity management - Part 2: Reference architecture and requirements" defines a reference architecture and implementation requirements for identity management. As a horizontal standard it applies to any information system that processes or stores identity information and provides a common foundation for other identity, privacy and security standards. The 2025 second edition updates the 2015 version and adds coverage of emerging concepts such as mobile identity and the principal’s private IMS (PPI).
Key topics and technical requirements
This standard describes architecture, stakeholders, actors, processes and technical requirements for managing identity information:
- Reference architecture and deployment scenarios
- Enterprise/internal identity models and architectures for external identities (including federated and service deployment scenarios).
- Stakeholders and actors
- Principals, identity management authority, identity information authority, relying parties, verifiers, auditors, regulators and consumer/citizen advocates.
- Processes, services and use cases
- Identity registration, lifecycle management, verification, provisioning, auditing and additional identity functions.
- Components and physical model
- Identity registers, identity information providers, interfaces and component models to support interoperable implementations.
- Functional requirements
- Policy for identity information lifecycle, conditions and procedures to maintain identity information, identity information interfaces, reference identifiers, and identity information quality and compliance.
- Non-functional requirements
- Availability, confidentiality, integrity, privacy-friendliness, archiving, termination and secure deletion of identity information.
- Governance and compliance
- Guidance to assess privacy-friendliness and assurance of identity attributes across implementations.
Practical applications and who benefits
ISO/IEC 24760-2:2025 is intended for organizations and professionals implementing or assessing identity management systems:
- IAM architects and engineers designing identity stores, identity providers, federated authentication and SSO.
- Security and cybersecurity teams enforcing identity-related controls and non-functional security requirements.
- Privacy officers and data protection teams evaluating privacy-friendliness and lifecycle controls for identity data.
- Auditors and regulators assessing compliance, governance and assurance of identity attributes.
- Software vendors and cloud service providers building identity management solutions, mobile identity services (PPI), or identity-as-a-service offerings.
- Enterprises and government agencies that manage employee, citizen or customer identities.
Related standards
- ISO/IEC 24760 series (see Part 1 for concepts and terminology)
- ISO/IEC SC 27 work on information security, cybersecurity and privacy protection
ISO/IEC 24760-2:2025 is a practical, standards-based blueprint for designing privacy-aware, interoperable and secure identity management frameworks usable across sectors and deployment scenarios.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 24760-2:2025
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 24760-1:2025
ДействующийInformation security, cybersecurity and privacy protection — A framework for identity management — Part 1: Co…
Overview ISO/IEC 24760-1:2025 is an international standard developed by ISO and IEC to provide a unified framework and terminology for identity management in information security, cybersecurity, and…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…