Overview
ISO/IEC 24760-1:2019 - "IT Security and Privacy - A framework for identity management - Part 1: Terminology and concepts" defines the foundational vocabulary and core concepts for identity management. Published as the second edition in 2019 by ISO/IEC JTC 1/SC 27, this document is applicable to any information system that processes identity information. Its primary goal is to promote a common understanding of identity, identifiers, attributes, lifecycle events and privacy considerations so organizations can design interoperable, secure identity management solutions.
Key topics and technical concepts
ISO/IEC 24760-1 focuses on standardized terminology and conceptual structures rather than prescriptive technical implementations. Main areas covered include:
- Terms and definitions for identity management (entities, identity, attribute, identifier, principal).
- Identity information: classification of identity data, attribute types and domains of origin.
- Identifiers and reference identifiers: uniqueness, persistence and scope within a domain.
- Credentials and credential management**: conceptual handling of authentication material.
- Identity lifecycle: enrolment, registration, maintenance, authentication and de-provisioning.
- Identification and verification processes, including identity proofing and evidence.
- Federation concepts: relationships across domains (authoritative sources/attribute authorities).
- Privacy protection and implementation aspects that influence how identity data should be handled.
- Clause structure and normative references (including ISO/IEC 24760-2:2015 for architecture/requirements).
While not prescribing technical protocols, the standard establishes consistent definitions that support technical design, legal compliance and interoperability.
Practical applications
ISO/IEC 24760-1 is a foundational reference for:
- Designing identity management (IdM) systems and architectures.
- Creating identity governance and administration (IGA) policies.
- Specifying requirements for authentication, enrolment and identity proofing workflows.
- Mapping attributes, identifiers and domains of origin for federated identity or SSO projects.
- Informing privacy impact assessments and compliance with regulatory obligations that touch identity data.
Adopting the standard helps teams reduce ambiguity in requirements, ease integration between identity domains, and align security and privacy controls.
Who should use this standard
- Identity architects and security engineers
- IAM/IGA product vendors and integrators
- Privacy officers and compliance teams
- System and application designers processing identity information
- Standards writers, auditors and procurement teams specifying identity requirements
Related standards
- ISO/IEC 24760-2:2015 - Reference architecture and requirements (normative reference in Part 1)
- ISO/IEC 24760 series - additional parts in the identity management framework
Keywords: ISO/IEC 24760-1, identity management, identity lifecycle, identity proofing, authentication, identifiers, identity information, IT security and privacy.