ISO/IEC 29146:2024
Information technology — Security techniques — A framework for access management
Information technology — Security techniques — A framework for access management
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 34
- Дата публикации:
- 19 января 2024 г.
- Издание:
- ISO/IEC IS 29146 edition 2 version 1
- ICS:
- 35.030
This document defines and establishes a framework for access management (AM) and the secure management of the process to access information and information and communications technologies (ICT) resources, associated with the accountability of a subject within some contexts. This document provides concepts, terms and definitions applicable to distributed access management techniques in network environments. This document also provides explanations about related architecture, components and management functions. The subjects involved in access management can be uniquely recognized to access information systems, as defined in the ISO/IEC 24760 series. The nature and qualities of physical access control involved in access management systems are outside the scope of this document.
Abstract
Overview
ISO/IEC 29146:2024 - "Information technology - Security techniques - A framework for access management" defines a comprehensive framework for access management (AM) in distributed networked environments. The standard explains concepts, terms and definitions, describes a reference architecture and core components (authentication endpoints, policy decision point (PDP), policy enforcement point (PEP), policy information point (PIP), policy administration point (PAP)), and sets out management functions and processes for secure control of access to ICT resources. Physical access control is explicitly out of scope.
Key topics and requirements
- Access control model and policies: Framework for defining authorization policies, attributes (subject, resource, environment) and models used to govern access decisions.
- Identity and authentication linkage: Access management relies on underlying identity management (see ISO/IEC 24760 series) and entity authentication assurances (ISO/IEC 29115).
- Access tokens: Definition and role of trusted objects that encapsulate authority for a subject to access resources; issued by PDP and enforced by PEP.
- Reference architecture and components: Clear roles and interactions for endpoints, PDP, PEP, PIP, PAP and additional service components for subject-centric and enterprise-centric implementations.
- Management functions and processes: Authorization, privilege management, policy-related attribute management, monitoring, alarm management and audit/validation of AMS.
- Federated access control: Considerations for cross-organization collaborations and federated authorization.
- Operational concerns: Threats, control objectives, validation of the access management framework and ongoing maintenance requirements.
Applications and practical value
ISO/IEC 29146:2024 is practical for organizations designing, implementing or evaluating an Access Management System (AMS) in on-premises, cloud or hybrid environments. Typical uses include:
- Designing policy-driven IAM solutions and authorization flows.
- Integrating identity services with access control for distributed applications and APIs.
- Implementing access tokens and secure enforcement points in microservices and cloud platforms.
- Defining privilege lifecycle and authorization processes for enterprise systems.
- Validating and auditing AMS behavior, monitoring and alarm handling for security operations.
Who should use this standard
- Security architects and engineers
- Identity & Access Management (IAM) practitioners
- System and solution integrators building authorization services
- Compliance officers and auditors assessing access controls
- Vendors of access management and security products
Related standards
- ISO/IEC 24760 series - framework for identity management (terminology and concepts)
- ISO/IEC 29115 - entity authentication assurance framework
Keywords: ISO/IEC 29146:2024, access management, access control, access token, PDP, PEP, PIP, IAM, authorization, privilege management, federated access.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 29146:2024
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 24760-1:2025
ДействующийInformation security, cybersecurity and privacy protection — A framework for identity management — Part 1: Co…
Overview ISO/IEC 24760-1:2025 is an international standard developed by ISO and IEC to provide a unified framework and terminology for identity management in information security, cybersecurity, and…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…