ISO/IEC 24760-2:2015 PDF
Information technology — Security techniques — A framework for identity management — Part 2: Reference architecture and requirements
Information technology — Security techniques — A framework for identity management — Part 2: Reference architecture and requirements
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 47
- Дата публикации:
- 3 июня 2015 г.
- Издание:
- ISO/IEC IS 24760 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 24760-2:2015 provides guidelines for the implementation of systems for the management of identity information, and specifies requirements for the implementation and operation of a framework for identity management. ISO/IEC 24760-2:2015 is applicable to any information system where information relating to identity is processed or stored.
Abstract
Overview
ISO/IEC 24760-2:2015 - "Information technology - Security techniques - A framework for identity management - Part 2: Reference architecture and requirements" defines a reference architecture and a set of implementation and operational requirements for identity management systems (IMS). It provides guidelines to design, document and operate systems that process or store identity information (including PII), and is applicable to any information system handling identity-related data.
Key technical topics and requirements
This part of ISO/IEC 24760 organizes identity management as an architecture-driven discipline. Major technical topics include:
- Reference architecture elements: stakeholders, actors, views, models, components, processes, information flows.
- Architecture viewpoints: mandatory context and functional views; optional physical and information views.
- Context view components: stakeholder analysis, actor definitions, context and use-case models, compliance and governance modeling.
- Functional view components: component model, identity management processes and services, physical deployment considerations.
- Identity management scenarios: enterprise, federated, service, and heterogeneous deployments.
- Requirements for identity information management:
- Access policy for identity information
- Lifecycle policies: issuance, maintenance, invalidation/revocation, archiving, termination/deletion
- Interfaces and reference identifiers for interoperability
- Identity information quality, compliance and recordkeeping
- Non‑functional requirements (e.g., availability, integrity, privacy and security controls)
- Supporting materials (informative annexes): legal/regulatory aspects, use-case examples, component and business process models.
Practical applications and who uses this standard
ISO/IEC 24760-2 is intended for practical use by:
- Enterprise architects and IAM architects designing documented identity management solutions and architecture descriptions.
- Security engineers and system integrators implementing identity services (authentication, provisioning, attribute management, federation).
- Privacy officers and compliance teams aligning identity data handling with legal and regulatory requirements.
- Procurement, auditors and regulators evaluating IMS implementations against recognized architecture and operational requirements.
- Vendors producing IAM products that must interoperate across deployments.
Typical applications:
- Designing or documenting an Identity and Access Management (IAM) program.
- Specifying identity lifecycle management, attribute repositories, and reference identifiers.
- Planning federated identity or cross-organizational authentication services.
- Ensuring governance, auditability and privacy protections around identity data.
Related standards
ISO/IEC 24760-2 complements and references other standards, including:
- ISO/IEC 24760‑1 (Terminology and concepts)
- ISO/IEC 29100 (Privacy framework)
- ISO/IEC 29101 (Privacy reference architecture)
- ISO/IEC 29115 (Entity authentication assurance framework)
- ISO/IEC 29146 (Access management framework)
Adopting ISO/IEC 24760-2 helps organizations create a structured, auditable and standards-aligned approach to identity management architecture, governance and operational requirements.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 24760-2:2015
Похожие стандарты
Стандарты, упомянутые в описании
SIST EN ISO/IEC 24760-3:2023
ДействующийInformation technology - Security techniques - A framework for identity management - Part 3: Practice (ISO/IE…
Overview EN ISO/IEC 24760-3:2022 (ISO/IEC 24760-3:2016) provides practical guidance for managing identity information and for ensuring that an identity management system (IMS) conforms with ISO/IEC 2…
SIST EN ISO/IEC 24760-2:2023
ДействующийInformation technology - Security techniques - A framework for identity management - Part 2: Reference archit…
Overview EN ISO/IEC 24760-2:2022 / ISO/IEC 24760-2:2015 defines a reference architecture and requirements for an identity management framework. It provides guidelines for the implementation, operatio…
SIST EN ISO/IEC 24760-1:2022
ДействующийIT Security and Privacy - A framework for identity management - Part 1: Terminology and concepts (ISO/IEC 247…
Overview SIST EN ISO/IEC 24760-1:2022 - IT Security and Privacy: A framework for identity management – Part 1: Terminology and concepts (ISO/IEC 24760-1:2019) provides a foundational reference for id…
SIST EN ISO/IEC 29100:2020
ДействующийInformation technology - Security techniques - Privacy framework (ISO/IEC 29100:2011, including Amd 1:2018)
Overview EN ISO/IEC 29100:2020 (ISO/IEC 29100:2011, including Amd 1:2018) defines a high-level privacy framework for the protection of personally identifiable information (PII) in information and com…
SIST EN ISO/IEC 29101:2021
ДействующийInformation technology - Security techniques - Privacy architecture framework (ISO/IEC 29101:2018)
Overview EN ISO/IEC 29101:2021 (ISO/IEC 29101:2018) defines a privacy architecture framework for information and communication technology (ICT) systems that store and process personally identifiable…
ISO/IEC 29115:2013
ДействующийInformation technology — Security techniques — Entity authentication assurance framework
Overview ISO/IEC 29115:2013 – Entity Authentication Assurance Framework is a globally recognized standard from ISO and IEC that outlines a comprehensive framework for managing authentication assuranc…
EN ISO/IEC 29146:2026
ДействующийInformation technology - Security techniques - A framework for access management (ISO/IEC 29146:2024)
Overview EN ISO/IEC 29146:2026 defines a comprehensive framework for access management (AM) in information technology and information and communications technologies (ICT). Developed by CEN and based…