Overview
ISO/IEC 29115:2013 – Entity Authentication Assurance Framework is a globally recognized standard from ISO and IEC that outlines a comprehensive framework for managing authentication assurance for entities, including individuals and non-person entities, in information technology environments. This standard defines four distinct Levels of Assurance (LoAs), sets criteria and guidance for achieving each level, provides methodologies for mapping other entity authentication schemes to these levels, and offers direction for exchanging authentication results across systems. Additionally, it details threat mitigation strategies and organizational controls to enhance authentication processes and protect sensitive information.
Adoption of ISO/IEC 29115:2013 helps organizations systematically assess, communicate, and manage the risks related to authentication, enabling secure and trustworthy digital transactions.
Key Topics
-
Levels of Assurance (LoA):
- LoA1 (Low assurance) – Minimal confidence in claimed or asserted identity; suitable for low-risk transactions.
- LoA2 (Medium assurance) – Some confidence; single-factor authentication; moderate risk mitigation.
- LoA3 (High assurance) – High confidence; requires multi-factor authentication and strong credential protections.
- LoA4 (Very high assurance) – Very high confidence; strict requirements including in-person identity proofing and tamper-resistant devices.
-
Authentication Criteria and Guidelines:
ISO/IEC 29115 provides criteria for each assurance level, focusing on enrollment, credential management, and authentication phases.
-
Mapping and Interoperability:
The framework supports mapping between different authentication schemes, ensuring interoperability in federated or multi-domain environments.
-
Threats and Controls:
The standard identifies potential threats at each phase (e.g., phishing, man-in-the-middle attacks) and recommends controls to mitigate risks, emphasizing cryptographic protection and secure credential handling.
-
Organizational Considerations:
Guidance covers legal compliance, information security management, operational infrastructure, and audit requirements relevant to authentication assurance.
Applications
Implementing ISO/IEC 29115:2013 brings practical benefits to a range of information and communications technology (ICT) environments, enhancing trust and resilience:
-
Credential Service Providers (CSPs):
Define and demonstrate authentication assurance levels for digital identity services, ensuring compliance and trust from relying parties.
-
Relying Parties (RPs):
Assess and specify the required level of assurance for accessing systems, protecting resources, and managing sensitive transactions.
-
Federated Identity Management:
Map between distinct authentication schemes to achieve interoperability and consistent identity assurances across organizational and national boundaries.
-
Regulated Sectors:
Applicable in sectors with stringent authentication needs such as finance, e-government, healthcare, and critical infrastructure, where protection of sensitive or personal data is required.
-
Risk-Based Security Management:
Facilitate informed decisions about authentication controls by aligning LoAs with organizational risk assessments and business objectives.
Related Standards
Organizations seeking a holistic approach to entity authentication assurance may also consider integrating ISO/IEC 29115:2013 with other security frameworks and standards:
- ISO/IEC 27001: Information security management systems for comprehensive risk assessment and security controls.
- ISO/IEC 24760: A series on identity management, providing foundational definitions and guidelines.
- ISO/IEC 19790: Security requirements for cryptographic modules.
- ITU-T X.1252 and X.1254: Global recommendations for identity assurance and authentication protocols.
- SAML (Security Assertion Markup Language): Widely-used protocol for exchanging authentication and authorization data, compatible with LoA expressions.
By applying ISO/IEC 29115:2013, organizations can strengthen their authentication ecosystems, improve security assurance, and meet the requirements of clients, partners, and regulatory bodies in an increasingly connected world.