ISO/IEC 24760-3:2025
Information security, cybersecurity and privacy protection — A framework for identity management — Part 3: Practice
Information security, cybersecurity and privacy protection — A framework for identity management — Part 3: Practice
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 31
- Дата публикации:
- 16 сентября 2025 г.
- Издание:
- ISO/IEC IS 24760 edition 2 version 1
- ICS:
- 35.030
This document: provides requirements and guidance for the management of identity information and for ensuring that an identity management system conforms to ISO/IEC 24760-1 and ISO/IEC 24760-2; is applicable to any information system where information relating to identity is processed or stored; is considered to be a horizontal document for the following reasons: it applies concepts such as distinguishing the term “identity” from the term “identifier” on the implementation of systems for the management of identity information and on the requirements for the implementation and operation of a framework for identity management, it provides an important contribution to assess identity management systems with regard to their privacy-friendliness and their ability to assure the relevant attributes of an identity, and consequently it provides a foundation and a common understanding for any other standard addressing identity, identity information, and identity management.
Abstract
Overview - ISO/IEC 24760-3:2025 (Part 3: Practice)
ISO/IEC 24760-3:2025 is the practical part of the ISO/IEC 24760 identity management framework. It provides requirements and guidance for managing identity information and for ensuring an identity management system (IdMS) conforms to ISO/IEC 24760-1 (core concepts) and ISO/IEC 24760-2 (reference architecture and requirements). Applicable to any information system that processes or stores identity information, this second edition is published as a horizontal document to support consistent, privacy-friendly identity management across sectors.
Key technical topics and requirements
- Risk assessment and mitigation: Guidance on assessing identity-related risk across the identity lifecycle, and defining assurance levels and confidentiality, integrity and availability requirements for identity information.
- Assurance in identity information: Practices for identity proofing, issuance and management of credentials, and establishing identity profiles using identity templates.
- Identifiers and identity information management: Distinctions between identity and identifier, categorization of identifiers (by entity type, linking nature, grouping, value creation) and practical controls for identifier lifecycle management.
- Access and audit controls: Policies for accessing identity information, auditing identity information usage, and controlling identity-based access to resources.
- Control objectives and controls: Contextual and architectural control components for establishing, operating and controlling an identity management system (including establishing identity information and managing its use).
- Federation and privacy-enhancing practices (informative annexes): Guidance on federated identity management and on using attribute-based credentials to enhance privacy protection.
Practical applications - who uses this standard
ISO/IEC 24760-3 is designed for practitioners responsible for design, implementation and governance of identity systems:
- Identity architects and system designers - to align IdMS architecture with identity lifecycle, identifiers and assurance requirements.
- Security and privacy officers - to perform risk assessments, define assurance levels, and ensure privacy-friendly controls.
- Identity providers, identity information authorities (IIA) and relying parties (RP) - to manage identity proofing, credential issuance and access decisions.
- Auditors and regulators - to assess conformance, controls and privacy protections.
- Software and service vendors - to develop IdMS components, federation services, and attribute-based credential solutions.
Related standards
This part is intended to work with and underpin:
- ISO/IEC 24760-1 (Core concepts and terminology)
- ISO/IEC 24760-2 (Reference architecture and requirements)
- Privacy and identity-related standards such as ISO/IEC 29100, 29101, 29115, 29134, 29146, 29151.
Keywords: ISO/IEC 24760-3, identity management, identity information, identity management system, identity proofing, credentials, identifiers, privacy protection, assurance, risk assessment, federated identity.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 24760-3:2025
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 24760-1:2025
ДействующийInformation security, cybersecurity and privacy protection — A framework for identity management — Part 1: Co…
Overview ISO/IEC 24760-1:2025 is an international standard developed by ISO and IEC to provide a unified framework and terminology for identity management in information security, cybersecurity, and…