Overview
EN ISO/IEC 24760-1:2022 - "IT Security and Privacy - A framework for identity management - Part 1: Terminology and concepts" defines a common vocabulary and the core concepts for identity and identity management. Applicable to any information system that processes identity information, this standard establishes the relationships between identity, identity information, identifiers, credentials, attributes and management processes. It is the first part of the ISO/IEC 24760 series and was prepared under ISO/IEC JTC 1 SC 27.
Key topics
The standard focuses on terminology and conceptual structure rather than prescriptive technical implementations. Key topics include:
- Definitions and terms for identity management, ensuring a shared vocabulary across organizations and vendors.
- Identity and identity information: how entities (people, devices, software) are represented.
- Identifiers and credentials: concepts of identifiers, credentials and credential management.
- Attributes: attribute types, domains of origin and attribute semantics.
- Identity lifecycle: enrolment, registration, identity proofing, verification, authentication, maintenance and revocation.
- Authentication and verification: conceptual models for proving and authenticating identity information.
- Federation: conceptual relationships where identities and attributes cross administrative domains.
- Privacy protection: privacy concepts related to identity data handling and minimization.
- Implementation aspects and operational structures that support identity management processes.
Practical applications
EN ISO/IEC 24760-1:2022 is useful when you need a standardized conceptual foundation for identity and access management (IAM) initiatives:
- Design and architecture: create IAM architectures that align with standardized concepts for identifiers, credentials and attribute management.
- Procurement and interoperability: specify requirements that vendors can interpret consistently, reducing ambiguity in contracts and integrations.
- Governance and policy: develop identity lifecycle policies (enrolment, proofing, authentication, maintenance) using a common terminology.
- Compliance and audit: document identity-management practices against recognized terminology and concepts.
- Privacy-by-design: map identity flows and apply privacy concepts such as data minimization and domain of origin.
Typical users: IAM architects, security engineers, CIOs, privacy officers, compliance teams, system integrators and standardization bodies.
Related standards
- Part of the ISO/IEC 24760 series and prepared under ISO/IEC JTC 1 SC 27.
- Use this document as the conceptual basis before applying implementation-focused or domain-specific identity standards and technical specifications.
Keywords: identity management, identity information, identity lifecycle, authentication, identifiers, credentials, privacy, IAM standard, EN ISO/IEC 24760-1.