Overview
ISO/IEC 29146:2024 - "Information technology - Security techniques - A framework for access management" defines a comprehensive framework for access management (AM) in distributed networked environments. The standard explains concepts, terms and definitions, describes a reference architecture and core components (authentication endpoints, policy decision point (PDP), policy enforcement point (PEP), policy information point (PIP), policy administration point (PAP)), and sets out management functions and processes for secure control of access to ICT resources. Physical access control is explicitly out of scope.
Key topics and requirements
- Access control model and policies: Framework for defining authorization policies, attributes (subject, resource, environment) and models used to govern access decisions.
- Identity and authentication linkage: Access management relies on underlying identity management (see ISO/IEC 24760 series) and entity authentication assurances (ISO/IEC 29115).
- Access tokens: Definition and role of trusted objects that encapsulate authority for a subject to access resources; issued by PDP and enforced by PEP.
- Reference architecture and components: Clear roles and interactions for endpoints, PDP, PEP, PIP, PAP and additional service components for subject-centric and enterprise-centric implementations.
- Management functions and processes: Authorization, privilege management, policy-related attribute management, monitoring, alarm management and audit/validation of AMS.
- Federated access control: Considerations for cross-organization collaborations and federated authorization.
- Operational concerns: Threats, control objectives, validation of the access management framework and ongoing maintenance requirements.
Applications and practical value
ISO/IEC 29146:2024 is practical for organizations designing, implementing or evaluating an Access Management System (AMS) in on-premises, cloud or hybrid environments. Typical uses include:
- Designing policy-driven IAM solutions and authorization flows.
- Integrating identity services with access control for distributed applications and APIs.
- Implementing access tokens and secure enforcement points in microservices and cloud platforms.
- Defining privilege lifecycle and authorization processes for enterprise systems.
- Validating and auditing AMS behavior, monitoring and alarm handling for security operations.
Who should use this standard
- Security architects and engineers
- Identity & Access Management (IAM) practitioners
- System and solution integrators building authorization services
- Compliance officers and auditors assessing access controls
- Vendors of access management and security products
Related standards
- ISO/IEC 24760 series - framework for identity management (terminology and concepts)
- ISO/IEC 29115 - entity authentication assurance framework
Keywords: ISO/IEC 29146:2024, access management, access control, access token, PDP, PEP, PIP, IAM, authorization, privilege management, federated access.