Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Decoding ISO definitions is both an art and science.

ISO definitions use the 'replacement rule' approach - this means that wherever a defined term appears in text, the reader can directly substitute the definition and the resulting text shall make sense.

Or, in ISO Directives-speak: "The definition shall be written in such a form that it can replace the term in its context."


So, when you read the following description of Identity Assurance, these defined terms come into play:

SC 27/WG 5 describes Identity Assurance as:

  1. identity assurance is the term used to describe an assured process where:

    1. An identity is established through verification of a set of identity attributes using acceptable evidence or validated systemically against an authoritative data source; then

    2. This identity is bound to the entity.

    3. The outcome of the process is one or more assured identifiers that can be used as the basis for authentication.

    4. The process and the organization operating the process are assured in accordance with a defined policy that includes:


      1. A governance body or authority;
      2. A policy specification that is systemized in a process;
      3. One or more organizations that operate the process;
      4. The detection of policy violations, anomalies and indicators of compromise, and actions to address them;
      5. One or more organizations that assure and enforce the process and the processing organizations.

...

<<NOTE: Need to change the order of the terms to the same as used above - look for any odd usages etc>>

environment where can use a set of attributes for identification and other purposesformalized process of verification that, if successful, results in an authenticated identity for an level of assurance in the result of identification
TermDefinition
entityitem inside or outside an information and communication technology system, such as a person, an organization, a device, a subsystem, or a group of such items that has recognizably distinct existence
identityset of attributes related to an entity
attributecharacteristic or property of an entity that can be used to describe its state, appearance, or other aspects
identifieridentity information that unambiguously distinguishes one entity from another one in a given domain
identity assurancelevel of assurance in the result of identification
identificationprocess of recognizing an entity in a particular domain as distinct from other entities
identityset of attributes related to an entity
verificationprocess to determine that presented identity information associated with a particular entity is applicable for the entity to be recognized in a particular domain at some point in time
domainattributecharacteristic or property of an entity that can be used to describe its state, appearance, or other aspects
identity informationset of values of attributes optionally with any associated metadata in an identityauthentication
identity evidenceidentity information for an entity required for authentication of that entity
authenticated identityidentity information for an entity created to record the result of authenticationidentity assurance
entityitem inside or outside an information and communication technology system, such as a person, an organization, a device, a subsystem, or a group of such items that has recognizably distinct existence
identifieridentity information that unambiguously distinguishes one entity from another one in a given domain
authenticationformalized process of verification that, if successful, results in an authenticated identity for an entity
enrolmentprocess to make an entity known within a particular domain

identity proofing or

initial entity authentication

particular form of authentication based on identity evidence that is performed as the condition for enrolment
enrolmentprocess to make domainenvironment where an entity known within a particular domainidentity evidenceidentity information for an entity required for authentication of that entitycan use a set of attributes for identification and other purposes