Overview
ISO/IEC 24760-2:2015 - "Information technology - Security techniques - A framework for identity management - Part 2: Reference architecture and requirements" defines a reference architecture and a set of implementation and operational requirements for identity management systems (IMS). It provides guidelines to design, document and operate systems that process or store identity information (including PII), and is applicable to any information system handling identity-related data.
Key technical topics and requirements
This part of ISO/IEC 24760 organizes identity management as an architecture-driven discipline. Major technical topics include:
- Reference architecture elements: stakeholders, actors, views, models, components, processes, information flows.
- Architecture viewpoints: mandatory context and functional views; optional physical and information views.
- Context view components: stakeholder analysis, actor definitions, context and use-case models, compliance and governance modeling.
- Functional view components: component model, identity management processes and services, physical deployment considerations.
- Identity management scenarios: enterprise, federated, service, and heterogeneous deployments.
- Requirements for identity information management:
- Access policy for identity information
- Lifecycle policies: issuance, maintenance, invalidation/revocation, archiving, termination/deletion
- Interfaces and reference identifiers for interoperability
- Identity information quality, compliance and recordkeeping
- Non‑functional requirements (e.g., availability, integrity, privacy and security controls)
- Supporting materials (informative annexes): legal/regulatory aspects, use-case examples, component and business process models.
Practical applications and who uses this standard
ISO/IEC 24760-2 is intended for practical use by:
- Enterprise architects and IAM architects designing documented identity management solutions and architecture descriptions.
- Security engineers and system integrators implementing identity services (authentication, provisioning, attribute management, federation).
- Privacy officers and compliance teams aligning identity data handling with legal and regulatory requirements.
- Procurement, auditors and regulators evaluating IMS implementations against recognized architecture and operational requirements.
- Vendors producing IAM products that must interoperate across deployments.
Typical applications:
- Designing or documenting an Identity and Access Management (IAM) program.
- Specifying identity lifecycle management, attribute repositories, and reference identifiers.
- Planning federated identity or cross-organizational authentication services.
- Ensuring governance, auditability and privacy protections around identity data.
Related standards
ISO/IEC 24760-2 complements and references other standards, including:
Adopting ISO/IEC 24760-2 helps organizations create a structured, auditable and standards-aligned approach to identity management architecture, governance and operational requirements.