Overview
ISO/IEC 24745:2022 - Biometric information protection - specifies security and privacy requirements for the management, storage and transfer of biometric information. The standard addresses protection of biometric references and their binding to identity references, threat analysis, countermeasures, and lifecycle guidance to ensure confidentiality, integrity and renewability/revocability of biometric data. It is focused on technical and privacy controls for biometric systems and does not cover general physical security, environmental security or cryptographic key management.
Keywords: biometric information protection, biometric security, privacy protection, biometric systems, biometric template protection.
Key Topics and Requirements
- Security goals: Requirements for confidentiality, integrity, availability and renewability/revocability of biometric references (BRs).
- Privacy controls: Strong emphasis on irreversibility and unlinkability to prevent reconstruction or cross-linking of biometric data across databases.
- Secure binding: Requirements for securely binding a biometric reference (BR) to an identity reference (IR) to protect personally identifiable information (PII).
- Threats & countermeasures: Analysis of attacks on sensors, transmission channels, databases and processing components, with recommended mitigations.
- Application models: Detailed models (Model A–K) describing storage and comparison scenarios (e.g., store on server, store on token, compare on client/server) and their security implications.
- Lifecycle guidance: Controls for collection, transfer, use, storage, retention, archiving, backup and disposal of biometric information.
- Renewable biometric references: Guidance and frameworks for implementing renewable or revocable biometric templates as countermeasures to compromise.
- Separation of data: Recommendations for using separated or distributed databases and secure binding between BR and IR.
Applications and Who Uses It
ISO/IEC 24745 is practical for:
- Biometric system designers and vendors implementing secure biometric templates and authentication flows
- Security architects and identity management teams selecting appropriate storage/compare models
- Privacy officers and compliance teams demonstrating privacy-by-design (irreversibility, unlinkability)
- System integrators, auditors and regulators assessing biometric deployments for security and data protection
- Developers implementing renewable biometric references and secure BR–IR binding
Typical use cases include mobile/remote authentication, access control, e‑government ID systems, and identity lifecycle management where protection of biometric templates and privacy compliance are required.
Related Standards
- ISO/IEC 30136 - Performance testing of biometric template protection schemes (referenced normatively)
- ISO/IEC 29115 - Identity management - Authentication framework (definitions referenced)
- ISO/IEC 24745:2022 replaces the 2011 edition with clarified requirements and new application models
Adopting ISO/IEC 24745 helps organizations implement robust biometric information protection, reduce privacy risks, and align biometric deployments with international security and privacy best practices.