Information technology - Security techniques - A framework for identity management - Part 3: Practice (ISO/IEC 24760-3:2016)

ISO/IEC 24760-3:2016 provides guidance for the management of identity information and for ensuring that an identity management system conforms to ISO/IEC 24760-1 and ISO/IEC 24760-2.
ISO/IEC 24760-3:2016 is applicable to an identity management system where identifiers or PII relating to entities are acquired, processed, stored, transferred or used for the purposes of identifying or authenticating entities and/or for the purpose of decision making using attributes of entities. Practices for identity management can also be addressed in other standards.

Informationstechnik - Sicherheitsverfahren - Rahmenwerk für Identitätsmanagement - Teil 3: Umsetzung (ISO/IEC 24760-3:2016)

Dieser Teil von ISO/IEC24760 stellt einen Leitfaden für das Management von Identitätsinformationen und für die Sicherstellung der Konformität eines Identitätsmanagementsystems mit ISO/IEC24760-1 und ISO/IEC24760-2 bereit.
Dieser Teil von ISO/IEC24760 gilt für ein Identitätsmanagementsystem, in dem Identifikatoren oder pbD, die sich auf Entitäten beziehen, zum Zwecke der Identifizierung oder Authentifizierung von Entitäten und/oder zum Zwecke der Entscheidungsfindung unter Verwendung von Attributen von Entitäten erfasst, verarbeitet, gespeichert, übertragen oder verwendet werden. Umsetzungen für das Identitätsmanagement können auch in anderen Normen behandelt werden.

Technologies de l'information - Techniques de sécurité - Cadre pour la gestion de l'identité - Partie 3: Mise en oeuvre (ISO/IEC 24760-3:2016)

La présente partie de l'ISO/IEC 24760 fournit des recommandations pour la gestion des informations d'identité et pour s'assurer qu'un système de gestion de l'identité est conforme à l'ISO/IEC 24760-1 et à l'ISO/IEC 24760-2.
La présente partie de l'ISO/IEC 24760 est applicable à un système de gestion de l'identité dans lequel des identificateurs ou des DCP relatifs à des entités sont acquis, traités, stockés, transférés ou utilisés à des fins d'identification ou d'authentification d'entités et/ou à des fins de prise de décision à l'aide d'attributs d'entités. Les pratiques relatives à la gestion de l'identité peuvent également être traitées dans d'autres normes.

Informacijska tehnologija - Varnostne tehnike - Okvir za upravljanje identitete - 3. del: Izvajanje (ISO/IEC 24760-3:2016)

ISO/IEC 24760-3:2016 podaja smernice za upravljanje informacij o identiteti in za zagotavljanje, da je sistem za upravljanje identitete skladen s standardoma ISO/IEC 24760-1 in ISO/IEC 24760-2.
ISO/IEC 24760-3:2016 se uporablja za sisteme upravljanja identitete, v katerih se identifikatorji ali PII v zvezi s subjekti pridobivajo, obdelujejo, shranjujejo, prenašajo ali uporabljajo za namene identifikacije ali preverjanja pristnosti subjektov in/ali za namen odločanja na podlagi atributov subjektov. Prakse za upravljanje identitete lahko obravnavajo tudi drugi standardi.

General Information

Status
Published
Publication Date
20-Sep-2022
Current Stage
6060 - Definitive text made available (DAV) - Publishing
Start Date
21-Sep-2022
Due Date
24-Nov-2023
Completion Date
21-Sep-2022

Buy Standard

Standard
EN ISO/IEC 24760-3:2023 - BARVE
English language
39 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day

Standards Content (Sample)


SLOVENSKI STANDARD
01-januar-2023
Informacijska tehnologija - Varnostne tehnike - Okvir za upravljanje identitete - 3.
del: Izvajanje (ISO/IEC 24760-3:2016)
Information technology - Security techniques - A framework for identity management -
Part 3: Practice (ISO/IEC 24760-3:2016)
Informationstechnik - Sicherheitsverfahren - Rahmenwerk für Identitätsmanagement -
Teil 3: Umsetzung (ISO/IEC 24760-3:2016)
Technologies de l'information - Techniques de sécurité - Cadre pour la gestion de
l'identité - Partie 3: Mise en oeuvre (ISO/IEC 24760-3:2016)
Ta slovenski standard je istoveten z: EN ISO/IEC 24760-3:2022
ICS:
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

EUROPEAN STANDARD EN ISO/IEC 24760-3

NORME EUROPÉENNE
EUROPÄISCHE NORM
September 2022
ICS 35.030
English version
Information technology - Security techniques - A
framework for identity management - Part 3: Practice
(ISO/IEC 24760-3:2016)
Technologies de l'information - Techniques de sécurité Informationstechnik - Sicherheitsverfahren -
- Cadre pour la gestion de l'identité - Partie 3: Mise en Rahmenwerk für Identitätsmanagement - Teil 3:
oeuvre (ISO/IEC 24760-3:2016) Umsetzung (ISO/IEC 24760-3:2016)
This European Standard was approved by CEN on 5 September 2022.

CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for
giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.

CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.

CEN-CENELEC Management Centre:
Rue de la Science 23, B-1040 Brussels
© 2022 CEN/CENELEC All rights of exploitation in any form and by any means
Ref. No. EN ISO/IEC 24760-3:2022 E
reserved worldwide for CEN national Members and for
CENELEC Members.
Contents Page
European foreword . 3

European foreword
The text of ISO/IEC 24760-3:2016 has been prepared by Technical Committee ISO/IEC JTC 1
"Information technology” of the International Organization for Standardization (ISO) and has been
taken over as EN ISO/IEC 24760-3:2022 by Technical Committee CEN-CENELEC/ JTC 13 “Cybersecurity
and Data Protection” the secretariat of which is held by DIN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by March 2023, and conflicting national standards shall
be withdrawn at the latest by March 2023.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN-CENELEC shall not be held responsible for identifying any or all such patent rights.
Any feedback and questions on this document should be directed to the users’ national standards body.
A complete listing of these bodies can be found on the CEN and CENELEC websites.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Endorsement notice
The text of ISO/IEC 24760-3:2016 has been approved by CEN-CENELEC as EN ISO/IEC 24760-3:2022
without any modification.
INTERNATIONAL ISO/IEC
STANDARD 24760-3
First edition
2016-08-01
Information technology — Security
techniques — A framework for
identity management —
Part 3:
Practice
Technologies de l’information — Techniques de sécurité — Cadre
pour la gestion de l’identité —
Partie 3: Mise en oeuvre
Reference number
ISO/IEC 24760-3:2016(E)
©
ISO/IEC 2016
ISO/IEC 24760-3:2016(E)
© ISO/IEC 2016, Published in Switzerland
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form
or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior
written permission. Permission can be requested from either ISO at the address below or ISO’s member body in the country of
the requester.
ISO copyright office
Ch. de Blandonnet 8 • CP 401
CH-1214 Vernier, Geneva, Switzerland
Tel. +41 22 749 01 11
Fax +41 22 749 09 47
copyright@iso.org
www.iso.org
ii © ISO/IEC 2016 – All rights reserved

ISO/IEC 24760-3:2016(E)
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Symbols and abbreviated terms . 2
5 Mitigating identity related risk in managing identity information . 2
5.1 Overview . 2
5.2 Risk assessment . 2
5.3 Assurance in identity information . 3
5.3.1 General. 3
5.3.2 Identity proofing . 3
5.3.3 Credentials . 3
5.3.4 Identity profile . 3
6 Identity information and identifiers . 4
6.1 Overview . 4
6.2 Policy on accessing identity information . 4
6.3 Identifiers . 4
6.3.1 General. 4
6.3.2 Categorization of identifier by the type of entity to which the identifier is linked 4
6.3.3 Categorization of identifier by the nature of linking . 5
6.3.4 Categorization of identifier by the grouping of entities . 6
6.3.5 Management of identifiers . 6
7 Auditing identity information usage . 6
8 Control objectives and controls . 6
8.1 General . 6
8.2 Contextual components for control . 7
8.2.1 Establishing an identity management system . 7
8.2.2 Establishing identity information . 9
8.2.3 Managing identity information .10
8.3 Architectural components for control .11
8.3.1 Establishing an identity management system .11
8.3.2 Controlling an identity management system .13
Annex A (normative) Practice of managing identity information in a federation of identity
management systems .15
Annex B (normative) Identity management practice using attribute-based credentials to
enhance privacy protection .24
Bibliography .31
© ISO/IEC 2016 – All rights reserved iii

ISO/IEC 24760-3:2016(E)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international
organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the
work. In the field of information technology, ISO and IEC have established a joint technical committee,
ISO/IEC JTC 1.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular the different approval criteria needed for
the different types of document should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject
of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent
rights. Details of any patent rights identified during the development of the document will be in the
Intr
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.