ISO/IEC 24760-2:2025 PDF
Information security, cybersecurity and privacy protection — A framework for identity management — Part 2: Reference architecture and requirements
Information security, cybersecurity and privacy protection — A framework for identity management — Part 2: Reference architecture and requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 46
- Дата публикации:
- 16 сентября 2025 г.
- Издание:
- ISO/IEC IS 24760 edition 2 version 1
- ICS:
- 35.030
This document: provides guidelines for the implementation of systems for the management of identity information; specifies requirements for the implementation and operation of a framework for identity management; is applicable to any information system where information relating to identity is processed or stored; is considered to be a horizontal document for the following reasons: it applies concepts such as distinguishing the term “identity” from the term “identifier” on the implementation of systems for the management of identity information and on the requirements for the implementation and operation of a framework for identity management, it provides an important contribution to assess identity management systems with regard to their privacy-friendliness and their ability to assure the relevant attributes of an identity, and consequently it provides a foundation and a common understanding for any other standard addressing identity, identity information, and identity management.
Abstract
Overview
ISO/IEC 24760-2:2025 - "Information security, cybersecurity and privacy protection - A framework for identity management - Part 2: Reference architecture and requirements" defines a reference architecture and implementation requirements for identity management. As a horizontal standard it applies to any information system that processes or stores identity information and provides a common foundation for other identity, privacy and security standards. The 2025 second edition updates the 2015 version and adds coverage of emerging concepts such as mobile identity and the principal’s private IMS (PPI).
Key topics and technical requirements
This standard describes architecture, stakeholders, actors, processes and technical requirements for managing identity information:
- Reference architecture and deployment scenarios
- Enterprise/internal identity models and architectures for external identities (including federated and service deployment scenarios).
- Stakeholders and actors
- Principals, identity management authority, identity information authority, relying parties, verifiers, auditors, regulators and consumer/citizen advocates.
- Processes, services and use cases
- Identity registration, lifecycle management, verification, provisioning, auditing and additional identity functions.
- Components and physical model
- Identity registers, identity information providers, interfaces and component models to support interoperable implementations.
- Functional requirements
- Policy for identity information lifecycle, conditions and procedures to maintain identity information, identity information interfaces, reference identifiers, and identity information quality and compliance.
- Non-functional requirements
- Availability, confidentiality, integrity, privacy-friendliness, archiving, termination and secure deletion of identity information.
- Governance and compliance
- Guidance to assess privacy-friendliness and assurance of identity attributes across implementations.
Practical applications and who benefits
ISO/IEC 24760-2:2025 is intended for organizations and professionals implementing or assessing identity management systems:
- IAM architects and engineers designing identity stores, identity providers, federated authentication and SSO.
- Security and cybersecurity teams enforcing identity-related controls and non-functional security requirements.
- Privacy officers and data protection teams evaluating privacy-friendliness and lifecycle controls for identity data.
- Auditors and regulators assessing compliance, governance and assurance of identity attributes.
- Software vendors and cloud service providers building identity management solutions, mobile identity services (PPI), or identity-as-a-service offerings.
- Enterprises and government agencies that manage employee, citizen or customer identities.
Related standards
- ISO/IEC 24760 series (see Part 1 for concepts and terminology)
- ISO/IEC SC 27 work on information security, cybersecurity and privacy protection
ISO/IEC 24760-2:2025 is a practical, standards-based blueprint for designing privacy-aware, interoperable and secure identity management frameworks usable across sectors and deployment scenarios.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 24760-2:2025
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
SIST EN ISO/IEC 24760-3:2023
ДействующийInformation technology - Security techniques - A framework for identity management - Part 3: Practice (ISO/IE…
Overview EN ISO/IEC 24760-3:2022 (ISO/IEC 24760-3:2016) provides practical guidance for managing identity information and for ensuring that an identity management system (IMS) conforms with ISO/IEC 2…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…
ISO/ASTMTR52917-EB
ДействующийAdditive Manufacturing — Round Robin Testing — General Guidelines
This document outlines the steps with regard to aspects of design to conduct and run a round robin study (RRS) to assess the degree of variability in an additive manufacturing material or process. Th…