SIST EN ISO/IEC 29146:2026
Information technology - Security techniques - A framework for access management (ISO/IEC 29146:2024)
Information technology - Security techniques - A framework for access management (ISO/IEC 29146:2024)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 42
- Дата публикации:
- 29 мая 2026 г.
- Издание:
- ISO/IEC 29146:2024
- ICS:
- 35.030
This document defines and establishes a framework for access management (AM) and the secure management of the process to access information and information and communications technologies (ICT) resources, associated with the accountability of a subject within some contexts. This document provides concepts, terms and definitions applicable to distributed access management techniques in network environments. This document also provides explanations about related architecture, components and management functions. The subjects involved in access management can be uniquely recognized to access information systems, as defined in the ISO/IEC 24760 series. The nature and qualities of physical access control involved in access management systems are outside the scope of this document.
Abstract
Overview
SIST EN ISO/IEC 29146:2026 establishes a robust framework for access management (AM), focusing on secure and accountable processes for accessing information and ICT (information and communications technology) resources. Developed by the Slovenski inštitut za standardizacijo (SIST) in alignment with ISO and IEC standards, this document lays out core concepts, definitions, and function areas for distributed access management within networked environments. The standard emphasizes integration with identity management frameworks (notably ISO/IEC 24760) and focuses on logical access management over physical security measures.
Key Topics
-
Access Management Fundamentals The standard articulates the foundation and terminology for access management, ensuring clarity in how access to ICT resources is governed within organizations and across networks.
-
Access Control Models It details several access control methods, including:
- Identity-based access control (IBAC)
- Role-based access control (RBAC)
- Attribute-based access control (ABAC) These models support both centralized and distributed environments, with a focus on flexibility and scalability for modern IT systems.
-
Key Components and Architecture The framework defines critical elements such as:
- Policy Decision Point (PDP): Evaluates access requests and issues authorization decisions.
- Policy Enforcement Point (PEP): Enforces the decisions by controlling resource access.
- Policy Administration Point (PAP): Manages access policies.
- Policy Information Point (PIP): Provides necessary attributes for authorization decisions.
- Security Token Service (STS): Issues access tokens validating permissions.
-
Security Considerations Emphasizes the importance of safeguarding the integrity and confidentiality of access requests, especially in federated and distributed settings. The standard addresses the need for secure communication channels and outlines the impact of authentication assurance levels.
Applications
ISO/IEC 29146:2026 is applicable to a wide range of organizations seeking to improve or harmonize their information security processes, particularly in these areas:
-
Enterprise IT Systems: Used to standardize access to company resources, ensuring only authorized personnel gain entry to sensitive information and services.
-
Distributed Networks: Supports organizations with IT resources spread across multiple locations or operating in collaborative, multi-organization environments.
-
Cloud and Web Services: Provides models for secure access to distributed cloud platforms and online services, supporting single sign-on (SSO) and federated access scenarios.
-
Regulated Sectors: Helps meet compliance needs where strict accountability in access management is required, aligning with privacy, security, and data protection legislation.
-
Identity and Access Management (IAM) Integration: Complements identity management standards (such as ISO/IEC 24760), providing a holistic approach for verifying and managing subject identities and their access privileges.
Related Standards
Organizations implementing or referencing ISO/IEC 29146:2026 should also consider these complementary standards:
- ISO/IEC 24760 series - Framework for identity management: Provides terminology and models for identifying and authenticating entities.
- ISO/IEC 29115 - Entity authentication assurance framework: Sets criteria for identity proofing and assurance.
- ISO/IEC 27001 & ISO/IEC 27002 - Information security management systems: Relate to broader information security controls.
- ISO/IEC 10181-3 - Access control framework: Provides historical context and foundational concepts adopted by this standard.
Practical Value
Adopting SIST EN ISO/IEC 29146:2026 enables organizations to:
- Establish a consistent, policy-driven, and auditable approach to access management.
- Enhance security by rigorously controlling who may access particular information assets.
- Support compliance with global cybersecurity, privacy, and data protection standards.
- Simplify integration of various access control models in complex, multi-technology environments.
- Facilitate secure collaboration across organizational and network boundaries.
By utilizing this standard, organizations can strengthen their access control strategies, reduce security risks, and foster trust in their information systems.
Технические детали
- Технический комитет
- ITC - Information technology
- SKU
- SIST EN ISO/IEC 29146:2026
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 24760-1:2025
ДействующийInformation security, cybersecurity and privacy protection — A framework for identity management — Part 1: Co…
Overview ISO/IEC 24760-1:2025 is an international standard developed by ISO and IEC to provide a unified framework and terminology for identity management in information security, cybersecurity, and…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…
ISO/IEC 10181-3:1996
ДействующийInformation technology — Open Systems Interconnection — Security frameworks for open systems: Access control…
Overview ISO/IEC 10181-3:1996 - Access control framework defines a general framework for providing access control in Open Systems Interconnection (OSI) and other open systems. Part of the ISO/IEC 101…