Overview
ISO/IEC 27554:2024 provides targeted guidance for assessing identity-related risk, applying the ISO 31000:2018 risk management methodology specifically to identity management contexts. It helps organisations establish context, identify and analyse identity risks, and evaluate and treat those risks for processes and services that rely on or are related to identity information. The document is intended to be used in connection with ISO 31000 and focuses on identity-specific threats and consequences; it does not cover general delivery, technology or broader security risks.
Key topics and technical requirements
ISO/IEC 27554:2024 elaborates the ISO 31000 process with identity-specific detail. Key topics include:
- Principles and framework elements: leadership and commitment, integration, design, implementation, evaluation and improvement.
- Risk process steps mapped to identity use: communication and consultation; scope, context and criteria; risk assessment (identification, analysis, evaluation); risk treatment; monitoring, review, recording and reporting.
- Identity-related context establishment: defining actors (subscribers/actors, administrators), types of personal data and service/transaction scope, and relevant policies and regulations.
- Risk identification & analysis: identifying identity-specific events (e.g., identity theft or fabrication), sources, causes and affected parties.
- Consequences and impact: categories of consequences for identity-related incidents and guidance for risk impact assessment.
- Risk treatment options consistent with ISO 31000: avoidance, mitigation, sharing, acceptance and controls tailored to identity lifecycles.
Practical applications
ISO/IEC 27554:2024 is actionable for organizations that need to understand and manage risks tied to identities and identity information:
- Conducting formal risk assessments for identity-dependent services (authentication, credential issuance, account provisioning).
- Developing identity-specific controls and mitigation plans informed by assessed likelihood and impact.
- Feeding risk assessment outputs into identity management processes and assurance-level decisions.
- Aligning identity risk practices with privacy, compliance and business requirements.
- Establishing monitoring, reporting and continual improvement for identity risk programs.
Who should use this standard
- Identity and Access Management (IAM) architects and engineers
- Risk managers, security and privacy professionals
- Compliance officers and auditors assessing identity-related controls
- Service providers and organizations issuing or relying on digital identities
Related standards
- ISO 31000:2018 - Risk management - Guidelines (primary methodology)
- Identity-management terminology and concepts referenced (e.g., ISO/IEC 24760 series)
By using ISO/IEC 27554:2024, organisations can apply a consistent, risk-based approach to identity management that supports informed decisions on controls, assurance levels and privacy protection.