ISO/IEC 24760-3:2016
Information technology — Security techniques — A framework for identity management — Part 3: Practice
Information technology — Security techniques — A framework for identity management — Part 3: Practice
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 31
- Дата публикации:
- 21 июля 2016 г.
- Издание:
- ISO/IEC IS 24760 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 24760-3:2016 provides guidance for the management of identity information and for ensuring that an identity management system conforms to ISO/IEC 24760-1 and ISO/IEC 24760-2. ISO/IEC 24760-3:2016 is applicable to an identity management system where identifiers or PII relating to entities are acquired, processed, stored, transferred or used for the purposes of identifying or authenticating entities and/or for the purpose of decision making using attributes of entities. Practices for identity management can also be addressed in other standards.
Abstract
Overview
ISO/IEC 24760-3:2016 - Information technology - Security techniques - A framework for identity management - Part 3: Practice - provides practical guidance for managing identity information and operating an identity management system (IdMS) that conforms to ISO/IEC 24760-1 (terminology/concepts) and ISO/IEC 24760-2 (reference architecture/requirements). It applies where identifiers or personally identifiable information (PII) are acquired, processed, stored, transferred or used to identify/authenticate entities or to make attribute-based decisions.
Key topics and requirements
- Risk assessment for identity information
- Assess identity-related risks (confidentiality, integrity, availability) tied to each application and determine appropriate risk management criteria.
- Relying parties set required levels of assurance based on assessed risk.
- Assurance and identity proofing
- Define and apply assurance levels (see ISO/IEC 29115) for identity proofing, enrollment and credential issuance.
- Identity proofing can use multiple independent identity information providers to increase assurance.
- Credentials and cryptographic validation
- Support multiple credential types with varying assurance; high-assurance credentials should include cryptographic validation services for relying parties.
- Identity information structures
- Use identity profiles and identity templates to define attribute sets for specific technical or business purposes.
- Policies for accessing, managing and protecting identity information.
- Identifiers and identifier management
- Categorization and lifecycle management of identifiers (by entity type, nature of linking, grouping).
- Auditing and control objectives
- Audit usage of identity information; define control objectives and implement contextual and architectural controls when establishing or operating an IdMS.
- Federation and privacy-enhancing credentials
- Normative guidance for federated identity management (Annex A) and for using attribute-based credentials to enhance privacy (Annex B).
Practical applications and who uses this standard
ISO/IEC 24760-3 is designed for practitioners who design, deploy or govern identity systems:
- Identity and access management (IAM) architects
- Security architects and system integrators
- Privacy officers and data protection teams
- IT risk managers and auditors
- Relying parties, identity providers and federation managers
Typical use cases include building enterprise IdMS, setting assurance and proofing policies for user enrollment, defining identifier lifecycles, establishing federation agreements, and selecting privacy-enhancing credential flows.
Related standards
- ISO/IEC 24760-1, ISO/IEC 24760-2 (family)
- ISO/IEC 29100 (Privacy framework)
- ISO/IEC 29101 (Privacy reference architecture)
- ISO/IEC 29115 (Entity authentication assurance)
- ISO/IEC 29146 (Access management)
- ISO/IEC 29003, ISO/IEC 29134, ISO/IEC 29151 (identity proofing and privacy guidance)
This practical guidance helps organizations manage identity information securely, set appropriate assurance levels, protect PII, and support interoperable, privacy-aware identity management deployments.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 24760-3:2016
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 24760-1:2025
ДействующийInformation security, cybersecurity and privacy protection — A framework for identity management — Part 1: Co…
Overview ISO/IEC 24760-1:2025 is an international standard developed by ISO and IEC to provide a unified framework and terminology for identity management in information security, cybersecurity, and…