ISO/IEC 24760-1:2019/Amd 1:2023 PDF
IT Security and Privacy — A framework for identity management — Part 1: Terminology and concepts — Amendment 1
IT Security and Privacy — A framework for identity management — Part 1: Terminology and concepts — Amendment 1
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 4
- Дата публикации:
- 9 января 2023 г.
- Издание:
- ISO/IEC IS 24760 edition 2 version 1
- ICS:
- 35.030
Abstract
Overview
ISO/IEC 24760-1:2019/Amd 1:2023 is an internationally recognized amendment to the ISO/IEC 24760-1:2019 standard, issued by ISO and IEC. It focuses on enhancing the framework for identity management within the domain of IT security and privacy. This amendment updates key terminology and concepts related to identity management, addressing evolving security requirements and technological innovations.
The standard is critical for organizations aiming to establish robust identity management systems that ensure secure, reliable authentication and authorization. It defines foundational terms such as authenticators, authentication factors, and access tokens, which are essential in safeguarding digital identities and controlling access to resources.
Key Topics
-
Readily-verifiable Identifier An identifier designed to be easily validated as belonging to a known entity, supporting efficient authentication processes. Example: A digital signature derived from solving a cryptographic puzzle.
-
Authoritative Identifier A unique identifier issued by a trusted authority within a well-established domain, such as government-issued IDs, ensuring high trust in identity verification.
-
Access Token A trusted object encapsulating permissions that authorize a principal’s access to resources, often obtained after successful authentication. It can be either physical or virtual and may contain cryptographic information to verify its integrity.
-
Authentication Factors Four types are recognized to enhance authentication security:
- Cognition factor: What the principal knows (e.g., a password).
- Possession factor: What the principal holds (e.g., a security token).
- Inherent factor: Physical characteristics (e.g., fingerprint).
- Behaviour factor: Typical actions or patterns (e.g., typing rhythm).
-
Multi-factor Authentication Employs two or more authenticators from different authentication factors to increase security assurance.
-
Authenticator A secure device or software representing an entity in the authentication process, controlled by the principal. Examples include OTP generators, mobile authentication apps, and electronic identity cards.
-
One-Time Password (OTP) A single-use, randomly generated password for authentication, typically produced by an authenticator.
-
Personal Secret Exclusive knowledge to the principal, such as passwords or PINs, used for identity validation.
-
Entity Authentication Assurance & Level of Assurance These define the reliability and strength of confidence in identity assertions, guiding organizations in selecting appropriate authentication methods per risk level.
-
Principal’s Personal Identity Management System (PPI) An identity management system held under exclusive control by the principal, often implemented as a mobile identity or dedicated token.
Applications
ISO/IEC 24760-1:2019/Amd 1:2023 serves as a foundational reference for designing and implementing identity management solutions that prioritize IT security and privacy. Key application areas include:
-
Enterprise Identity and Access Management (IAM) Establishing reliable and standardized identity verification across corporate resources.
-
Government Identity Programs Supporting secure issuance and management of authoritative identifiers used in digital government services.
-
Multi-factor Authentication Deployment Enhancing user authentication security by integrating authenticators across various authentication factors.
-
Digital Identity Wallets and Mobile Identity Solutions Guiding the creation of personal identity management systems that empower users with control over their digital identities.
-
Secure Access Control Systems Implementing access tokens and assurance levels to fine-tune access privileges in cloud services, applications, and IoT devices.
Organizations benefit by aligning with this standard to improve interoperability, compliance with data protection regulations, and resilience against identity fraud.
Related Standards
-
ISO/IEC 29146:2016 Provides guidelines on access control frameworks, referenced for defining access tokens in identity management.
-
ISO/IEC 19790:2012 Details security requirements for cryptographic modules, informing multi-factor authentication concepts.
-
ISO/IEC 29115:2013 Defines entity authentication assurance levels, crucial for interpreting assurance terms in identity management.
-
ISO/IEC 24760 Series The broader series addresses various aspects of identity management frameworks, offering comprehensive coverage.
-
ISO/IEC 24760-3:2016 Offers examples and annexes on using authenticators for attribute-based credentials, related to authentication device management.
Conclusion
Implementing ISO/IEC 24760-1:2019/Amd 1:2023 helps organizations advance their identity management capabilities with up-to-date terminology and concepts critical for secure IT environments. By understanding and applying these definitions and principles, businesses and governments can strengthen privacy, trust, and control in digital identity ecosystems.
Keywords: ISO/IEC 24760-1 amendment, identity management framework, IT security, privacy, authentication factors, authenticators, access tokens, multi-factor authentication, digital identity, entity authentication assurance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 24760-1:2019/Amd 1:2023
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
SIST EN ISO/IEC 24760-3:2023
ДействующийInformation technology - Security techniques - A framework for identity management - Part 3: Practice (ISO/IE…
Overview EN ISO/IEC 24760-3:2022 (ISO/IEC 24760-3:2016) provides practical guidance for managing identity information and for ensuring that an identity management system (IMS) conforms with ISO/IEC 2…
SIST EN ISO/IEC 24760-1:2022
ДействующийIT Security and Privacy - A framework for identity management - Part 1: Terminology and concepts (ISO/IEC 247…
Overview SIST EN ISO/IEC 24760-1:2022 - IT Security and Privacy: A framework for identity management – Part 1: Terminology and concepts (ISO/IEC 24760-1:2019) provides a foundational reference for id…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…