SIST EN ISO/IEC 24760-2:2023 PDF
Information technology - Security techniques - A framework for identity management - Part 2: Reference architecture and requirements (ISO/IEC 24760-2:2015)
Information technology - Security techniques - A framework for identity management - Part 2: Reference architecture and requirements (ISO/IEC 24760-2:2015)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 55
- Дата публикации:
- 30 ноября 2022 г.
- Издание:
- (ISO/IEC 24760-2:2015)
- ICS:
- 35.030
ISO/IEC 24760-2:2015 provides guidelines for the implementation of systems for the management of identity information, and specifies requirements for the implementation and operation of a framework for identity management. ISO/IEC 24760-2:2015 is applicable to any information system where information relating to identity is processed or stored.
Abstract
Overview
EN ISO/IEC 24760-2:2022 / ISO/IEC 24760-2:2015 defines a reference architecture and requirements for an identity management framework. It provides guidelines for the implementation, operation and governance of systems that create, store, process or use identity information (for people, organizations, devices or software). The standard is applicable to any information system handling identity data and complements other identity, privacy and access-management standards.
Key topics and technical requirements
- Reference architecture: core architecture elements, component model and their relationships; views include context, functional and physical viewpoints.
- Viewpoints and models: stakeholder and actor definitions, context model, use-case model, compliance and governance model.
- Processes and services: specification of identity-management processes for issuance, administration, use and lifecycle management of identity information.
- Identity management scenarios: enterprise, federated, service and heterogeneous deployment scenarios are described to guide implementations.
- Identity information requirements:
- Access policy for identity information and governance requirements.
- Lifecycle policy: rules for creation, maintenance, archiving, termination and deletion.
- Interfaces and identifiers: requirements for identity information interfaces and reference identifiers.
- Quality and compliance: data quality, integrity and compliance requirements.
- Non‑functional requirements: performance, availability, scalability and security considerations.
- Legal and regulatory aspects: informative guidance on lawful processing and privacy implications.
Practical applications and who uses it
This standard is practical for organizations designing, procuring or operating identity and access management (IAM) systems. Typical users:
- Enterprise architects and solution architects designing IAM reference architectures.
- Security engineers and IAM implementers configuring identity stores, provisioning and federation.
- IAM vendors and product teams aligning products to standard architecture and interfaces.
- Compliance officers, data protection officers and auditors ensuring identity data handling meets governance and legal requirements.
- System integrators implementing federated identity, single sign-on (SSO), provisioning, and identity lifecycle processes.
Use cases include enterprise IAM rollouts, federated identity between organizations, service-provider identity integration, and modernization of identity stores to meet privacy and regulatory obligations.
Related standards
- ISO/IEC 24760-1 (Terminology and concepts)
- ISO/IEC 29100 (Privacy framework)
- ISO/IEC 29101 (Privacy reference architecture)
- ISO/IEC 29115 (Entity authentication assurance)
- ISO/IEC 29146 (Access management framework)
EN ISO/IEC 24760-2 provides a practical, standards-based foundation to design interoperable, secure and compliant identity management systems. Keywords: identity management, reference architecture, identity information, ISO/IEC 24760-2, IAM, identity lifecycle, identity governance.
Технические детали
- Технический комитет
- ITC - Information technology
- SKU
- SIST EN ISO/IEC 24760-2:2023
Похожие стандарты
Стандарты, упомянутые в описании
SIST EN ISO/IEC 24760-1:2022
ДействующийIT Security and Privacy - A framework for identity management - Part 1: Terminology and concepts (ISO/IEC 247…
Overview SIST EN ISO/IEC 24760-1:2022 - IT Security and Privacy: A framework for identity management – Part 1: Terminology and concepts (ISO/IEC 24760-1:2019) provides a foundational reference for id…
SIST EN ISO/IEC 29100:2020
ДействующийInformation technology - Security techniques - Privacy framework (ISO/IEC 29100:2011, including Amd 1:2018)
Overview EN ISO/IEC 29100:2020 (ISO/IEC 29100:2011, including Amd 1:2018) defines a high-level privacy framework for the protection of personally identifiable information (PII) in information and com…
SIST EN ISO/IEC 29101:2021
ДействующийInformation technology - Security techniques - Privacy architecture framework (ISO/IEC 29101:2018)
Overview EN ISO/IEC 29101:2021 (ISO/IEC 29101:2018) defines a privacy architecture framework for information and communication technology (ICT) systems that store and process personally identifiable…
ISO/IEC 29115:2013
ДействующийInformation technology — Security techniques — Entity authentication assurance framework
Overview ISO/IEC 29115:2013 – Entity Authentication Assurance Framework is a globally recognized standard from ISO and IEC that outlines a comprehensive framework for managing authentication assuranc…
EN ISO/IEC 29146:2026
ДействующийInformation technology - Security techniques - A framework for access management (ISO/IEC 29146:2024)
Overview EN ISO/IEC 29146:2026 defines a comprehensive framework for access management (AM) in information technology and information and communications technologies (ICT). Developed by CEN and based…