Overview
ISO/IEC 24760-3:2016/Amd 1:2023 is an important amendment to the international standard for information technology security techniques, focusing on identity management. This amendment enhances Part 3 of the ISO/IEC 24760 series, which provides practical guidance for implementing a robust identity management framework. The focus of Amendment 1 is on the Identity Information Lifecycle processes, addressing risks and operational practices associated with managing identity data securely and effectively.
This standard is developed by the joint technical committee ISO/IEC JTC 1, Subcommittee SC 27, which specializes in information security, cybersecurity, and privacy protection. The updated guidelines help organizations control the lifecycle of identity information-covering registration, active use, suspension, and archiving of identities-while ensuring data integrity, confidentiality, and availability.
Key Topics
-
Identity Information Lifecycle
Defines the stages of identity management from registration to archiving, ensuring that authentication is only successful when an identity is in the active state.
-
Risk Management in Identity Systems
Emphasizes conducting risk assessments focused on identity errors and protecting sensitive identity information throughout its lifecycle.
-
Identifier Categorization
Introduces classifications of identifiers based on value creation methods:
- Combination of attributes (quasi-identifiers)
- Generated unique values
- Externally assigned unique values (authoritative identifiers)
-
Privacy and Security Controls
Recommends applying cryptographic hash functions to transform identifiers derived from attribute combinations or external values, enhancing privacy protection during identity registration and authentication.
-
Auditing Practices
Specifies the need for detailed auditing of identity information access and sharing, supporting regulatory compliance and operational transparency. Audits must include tracking of accessed data, operators, and any external parties involved.
Applications
ISO/IEC 24760-3:2016/Amd 1:2023 is essential for organizations aiming to implement or enhance identity management systems with strong security practices. Key practical applications include:
-
Enterprise Identity Management
Helps companies systematically manage digital identities and credential issuance in alignment with organizational security policies.
-
Digital Authentication Services
Supports the creation and operation of secure authentication systems by ensuring identity data lifecycle is carefully managed and risks minimized.
-
Credential Issuance and Management
Applies to issuers of physical and digital credentials (e.g., passports, driver licenses, hardware tokens), guiding the processing of identity data in compliance with international security standards.
-
Regulated Industries
Facilitates compliance with auditing and privacy requirements in sectors such as finance, healthcare, and government services where identity management is critical.
-
Privacy Protection Frameworks
Provides measures to transform identifiers to protect personally identifiable information (PII) during identity verification and data sharing.
Related Standards
-
ISO/IEC 24760-1 and ISO/IEC 24760-2
These parts provide the foundational framework and reference architecture for identity management that Part 3 builds upon.
-
ISO/IEC 29115
Although removed as a direct reference in this amendment, this standard relates to entity authentication assurance levels.
-
ISO/IEC TS 29003:2018
Provides guidance on identity proofing techniques, which complements the lifecycle and risk management concepts in ISO/IEC 24760-3.
-
ISO/IEC 18014 Series
Covers time-stamping and traceability requirements crucial for auditing and accountability in identity management systems.
By integrating ISO/IEC 24760-3:2016/Amd 1:2023, organizations can strengthen identity governance frameworks, enhance risk mitigation, and comply with global best practices for secure and privacy-conscious identity management throughout the information lifecycle.