International Standard
ISO/IEC 24760-1:2025
Information security, cybersecurity and privacy protection — A framework for identity management — Part 1: Core concepts and terminology
Reference number
ISO/IEC 24760-1:2025
Edition 3
2025-09
Read sample
ISO/IEC 24760-1:2025
87485
Published (Edition 3, 2025)

ISO/IEC 24760-1:2025

ISO/IEC 24760-1:2025
87485
Language
Format
CHF 0

What is ISO/IEC 24760-1?

ISO/IEC 24760-1:2025 defines the core terminology and concepts essential to identity management in the context of information security, cybersecurity and privacy protection. As the foundational part of the ISO/IEC 24760 series, it provides the language and structure needed to design, implement and evaluate identity management systems across all types of digital environments.

Whether you're managing user accounts in an enterprise system or verifying components in a connected ecosystem, this standard clarifies the distinctions between identity, identifier, attributes, and other core concepts, enabling consistent and secure identity handling.

Why is ISO/IEC 24760-1 important?

As digital systems increasingly rely on identity-based decisions—from authentication to authorization and access control—a unified understanding of identity concepts becomes critical. Without a clear framework, identity management can become inconsistent, exposing organizations to privacy risks, compliance issues, and security threats.

ISO/IEC 24760-1 establishes that framework, making it easier for systems and stakeholders to communicate, integrate, and trust identity-related processes.

It also serves as a horizontal document, meaning it supports and connects a wide range of standards—such as ISO/IEC 29100 (privacy), ISO/IEC 29115 (entity authentication), and others—ensuring interoperability and compliance across sectors.

Benefits

  • Improves clarity in system design, integration, and auditing
  • Supports privacy-by-design through precise identity definitions
  • Forms the foundation for related standards in cybersecurity and privacy
  • Helps organizations assess the trustworthiness and privacy friendliness of identity systems
  • Applicable to any system that processes identity information, including IT components, individuals, or organizations

 

FAQ

This edition updates the title and applies editorial revisions, incorporating previous amendments to ensure alignment with evolving practices in identity management. It also reinforces the distinction between key terms like “identity” and “identifier” to support clearer system implementation.

By precisely defining identity-related concepts and their relationships, ISO/IEC 24760-1 helps ensure that identity information is handled responsibly, minimizing unnecessary data use and enabling better privacy assessments. It underpins privacy-related standards and strengthens compliance with legal and regulatory obligations.

General information

  •  : Published
     : 2025-09
    : International Standard published [60.60]
  •  : 3
     : 23
  • ISO/IEC JTC 1/SC 27
    35.030  01.040.35 
  • RSS updates

Buy together

Package - 10% discount
ISO/IEC 24760 identity management essentials package

Secure identities, build trust

  • ISO/IEC 24760-1: Core concepts and terminology.
  • ISO/IEC 24760-2: Reference architecture and requirements. 
  • ISO/IEC 24760-3: Practice

Got a question?

Check out our Help and Support