29115-10.1 | Enrollment and identity proofing criteria | 0 |
29115-10.2 | Credential management criteria | 0 |
29115-10.3 | Entity authentication criteria | 0 |
29115-10.4 | Federation and assertion criteria | 0 |
29115-11 | Mapping other authentication schemes | 91 |
29115-12.1 | Exchanging authentication results | 91 |
29115-12.2 | Controls for mitigating threats | 91 |
29115-5.1 | Entity authentication assurance framework overview | 0 |
29115-5.2 | Authentication lifecycle phases | 0 |
29115-6.1 | Authentication context | 0 |
29115-7.1 | Level of Assurance 1 (LoA1) | 0 |
29115-7.2 | Level of Assurance 2 (LoA2) | 0 |
29115-7.3 | Level of Assurance 3 (LoA3) | 0 |
29115-7.4 | Level of Assurance 4 (LoA4) | 137 |
29115-9.1 | Threat analysis overview | 0 |
29115-9.2 | Enrollment and identity proofing threats | 0 |
29115-9.3 | Credential management threats | 0 |
29115-9.4 | Authentication mechanism threats | 0 |
ISO29115-10.1 | Audit and Accountability | 0 |
ISO29115-10.2 | Independent Assessment | 0 |
ISO29115-11.1 | Cross LoA Federation | 0 |
ISO29115-11.2 | Privacy in Authentication | 0 |
ISO29115-12.1 | Documented Operating Procedures | 2 |
ISO29115-5.1 | Authentication Assurance Level Selection | 0 |
ISO29115-5.2 | Enrolment Phase Controls | 0 |
ISO29115-5.3 | Identity Proofing at LoA 1 | 0 |
ISO29115-5.4 | Identity Proofing at LoA 2 | 0 |
ISO29115-5.5 | Identity Proofing at LoA 3 | 0 |
ISO29115-5.6 | Identity Proofing at LoA 4 | 0 |
ISO29115-6.1 | Credential Lifecycle Management | 0 |
ISO29115-6.2 | Authenticator Binding | 0 |
ISO29115-7.1 | Authentication Protocol Requirements | 0 |
ISO29115-7.2 | Multi Factor Authentication | 0 |
ISO29115-7.3 | Session Management | 0 |
ISO29115-8.1 | Credential Service Provider Assurance | 0 |
ISO29115-8.2 | Registration Authority Operations | 0 |
ISO29115-9.1 | Threat Mitigation Mapping | 0 |
ISO29115-9.2 | Fraud Detection and Response | 0 |
10 | 10 Threats and controls | 0 |
10.1 | 10.1 Threats to, and controls for, the enrolment phase | 0 |
10.1.C1 | Enrolment control #1: IdentityProofing: PolicyAdherence (all LoAs) | 0 |
10.1.C2 | Enrolment control #2: IdentityProofing: In Person (LoA4) | 0 |
10.1.C3 | Enrolment control #3: IdentityProofing: AuthoritativeInformation (LoA1) | 0 |
10.1.C4 | Enrolment control #4: IdentityProofing: AuthoritativeInformation (LoA2) | 0 |
10.1.C5 | Enrolment control #5: IdentityProofing: AuthoritativeInformation (LoA3) | 0 |
10.1.C6 | Enrolment control #6: IdentityProofing: AuthoritativeInformation (LoA4) | 0 |
10.2 | 10.2 Threats to, and controls for, the credential management phase | 0 |
10.2.C1 | Credential management control #1: AppropriateCredentialCreation (LoA1, LoA2) | 0 |
10.2.C10 | Credential management control #10: ActivatedByEntity (LoA3) | 0 |
10.2.C11 | Credential management control #11: ActivatedByEntity (LoA4) | 0 |
10.2.C12 | Credential management control #12: CredentialSecureStorage (LoA1) | 0 |
10.2.C13 | Credential management control #13: CredentialSecureStorage (LoA2) | 0 |
10.2.C14 | Credential management control #14: CredentialSecureStorage (LoA3) | 0 |
10.2.C15 | Credential management control #15: CredentialSecureStorage (LoA4) | 0 |
10.2.C16 | Credential management control #16: CredentialSecureRevocation&Destruction (all LoAs) | 0 |
10.2.C17 | Credential management control #17: CredentialSecureRenewal (LoA1, LoA2) | 0 |
10.2.C18 | Credential management control #18: CredentialSecureRenewal (LoA3) | 0 |
10.2.C19 | Credential management control #19: CredentialSecureRenewal (LoA4) | 0 |
10.2.C2 | Credential management control #2: AppropriateCredentialCreation (LoA3, LoA4) | 0 |
10.2.C20 | Credential management control #20: RecordRetention (LoA1, LoA2) | 0 |
10.2.C21 | Credential management control #21: RecordRetention (LoA3, LoA4) | 0 |
10.2.C3 | Credential management control #3: HardwareOnly (LoA4) | 0 |
10.2.C4 | Credential management control #4: StateLocked (LoA4) | 0 |
10.2.C5 | Credential management control #5: TrackedInventory (all LoAs) | 0 |
10.2.C6 | Credential management control #6: AppropriateCredentialIssuance (LoA1) | 0 |
10.2.C7 | Credential management control #7: AppropriateCredentialIssuance (LoA2, LoA3) | 0 |
10.2.C8 | Credential management control #8: AppropriateCredentialIssuance (LoA4) | 0 |
10.2.C9 | Credential management control #9: ActivatedByEntity (LoA1, LoA2) | 0 |
10.3 | 10.3 Threats to, and controls for, the authentication phase | 0 |
10.3.C1 | Authentication control #1: MultiFactorAuthentication (LoA3, LoA4) | 0 |
10.3.C10 | Authentication control #10: MutualAuthentication | 0 |
10.3.C11 | Authentication control #11: NoTransmitPassword | 0 |
10.3.C12 | Authentication control #12: EncryptedAuthentication | 0 |
10.3.C13 | Authentication control #13: DifferentAuthenticationParameter | 0 |
10.3.C14 | Authentication control #14: Timestamp | 0 |
10.3.C15 | Authentication control #15: PhysicalSecurity | 0 |
10.3.C16 | Authentication control #16: EncryptedSession | 0 |
10.3.C17 | Authentication control #17: FixProtocolVulnerabilities | 0 |
10.3.C18 | Authentication control #18: CryptographicMutualHandshake | 0 |
10.3.C19 | Authentication control #19: CredentialActivation | 0 |
10.3.C2 | Authentication control #2: StrongPassword | 0 |
10.3.C20 | Authentication control #20: CodeDigitalSignature | 0 |
10.3.C21 | Authentication control #21: LivenessDetection | 0 |
10.3.C3 | Authentication control #3: CredentialLockOut | 0 |
10.3.C4 | Authentication control #4: DefaultAccountUse | 0 |
10.3.C5 | Authentication control #5: AuditAndAnalyze | 0 |
10.3.C6 | Authentication control #6: HashedPasswordWithSalt | 0 |
10.3.C7 | Authentication control #7: AntiCounterfeiting | 0 |
10.3.C8 | Authentication control #8: DetectPhishingFromMessages | 0 |
10.3.C9 | Authentication control #9: AdoptAntiPhishingPractice | 0 |
11 | 11 Service assurance criteria | 0 |
6 | 6 Levels of assurance | 0 |
6.1 | 6.1 Level of assurance 1 (LoA1) | 0 |
6.2 | 6.2 Level of assurance 2 (LoA2) | 0 |
6.3 | 6.3 Level of assurance 3 (LoA3) | 0 |
6.4 | 6.4 Level of assurance 4 (LoA4) | 0 |
6.5 | 6.5 Selecting the appropriate level of assurance | 0 |
6.6 | 6.6 LoA mapping and interoperability | 0 |
6.7 | 6.7 Exchanging authentication results based on the 4 LoAs | 0 |
7 | 7 Actors | 0 |
8 | 8 Entity authentication assurance framework phases | 0 |
8.1 | 8.1 Enrolment phase | 0 |
8.1.1 | 8.1.1 Application and initiation | 0 |
8.1.2 | 8.1.2 Identity proofing and identity information verification | 0 |
8.1.3 | 8.1.3 Record-keeping/recording | 0 |
8.1.4 | 8.1.4 Registration | 0 |
8.2 | 8.2 Credential management phase | 0 |
8.2.1 | 8.2.1 Credential creation (pre-processing, initialization, binding) | 0 |
8.2.2 | 8.2.2 Credential issuance | 0 |
8.2.3 | 8.2.3 Credential activation | 0 |
8.2.4 | 8.2.4 Credential storage | 0 |
8.2.5 | 8.2.5 Credential suspension, revocation and/or destruction | 0 |
8.2.6 | 8.2.6 Credential renewal and/or replacement | 0 |
8.2.7 | 8.2.7 Record-keeping (credential management) | 0 |
8.3 | 8.3 Entity authentication phase | 0 |
8.3.1 | 8.3.1 Authentication | 0 |
8.3.2 | 8.3.2 Record-keeping (authentication) | 0 |
9 | 9 Management and organizational considerations | 0 |
9.1 | 9.1 Service establishment | 0 |
9.2 | 9.2 Legal and contractual compliance | 0 |
9.3 | 9.3 Financial provisions | 0 |
9.4 | 9.4 Information security management and audit | 0 |
9.5 | 9.5 External service components | 0 |
9.6 | 9.6 Operational infrastructure | 0 |
9.7 | 9.7 Measuring operational capabilities | 0 |
A | A Annex A (normative): Characteristics of a credential | 0 |
APPI | Appendix I (informative): Privacy and protection of PII | 0 |
FRONT | Clauses 1 to 5: scope, references, definitions, abbreviations and conventions | 0 |
STANDARD | ISO/IEC 29115:2013: the standard, its scope and what is held | 0 |
STATUS | Edition status: 2013 remains the edition; the ITU revised X.1254 alone in 2020 | 0 |