International (ISO/IEC JTC 1/SC 27 with ITU-T SG 17)

ISO/IEC 29115:2013

130 controls. 164 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

130 controls 164 frameworks share controls with it International (ISO/IEC JTC 1/SC 27 with ITU-T SG 17) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
29115-10.1Enrollment and identity proofing criteria0
29115-10.2Credential management criteria0
29115-10.3Entity authentication criteria0
29115-10.4Federation and assertion criteria0
29115-11Mapping other authentication schemes91
29115-12.1Exchanging authentication results91
29115-12.2Controls for mitigating threats91
29115-5.1Entity authentication assurance framework overview0
29115-5.2Authentication lifecycle phases0
29115-6.1Authentication context0
29115-7.1Level of Assurance 1 (LoA1)0
29115-7.2Level of Assurance 2 (LoA2)0
29115-7.3Level of Assurance 3 (LoA3)0
29115-7.4Level of Assurance 4 (LoA4)137
29115-9.1Threat analysis overview0
29115-9.2Enrollment and identity proofing threats0
29115-9.3Credential management threats0
29115-9.4Authentication mechanism threats0
ISO29115-10.1Audit and Accountability0
ISO29115-10.2Independent Assessment0
ISO29115-11.1Cross LoA Federation0
ISO29115-11.2Privacy in Authentication0
ISO29115-12.1Documented Operating Procedures2
ISO29115-5.1Authentication Assurance Level Selection0
ISO29115-5.2Enrolment Phase Controls0
ISO29115-5.3Identity Proofing at LoA 10
ISO29115-5.4Identity Proofing at LoA 20
ISO29115-5.5Identity Proofing at LoA 30
ISO29115-5.6Identity Proofing at LoA 40
ISO29115-6.1Credential Lifecycle Management0
ISO29115-6.2Authenticator Binding0
ISO29115-7.1Authentication Protocol Requirements0
ISO29115-7.2Multi Factor Authentication0
ISO29115-7.3Session Management0
ISO29115-8.1Credential Service Provider Assurance0
ISO29115-8.2Registration Authority Operations0
ISO29115-9.1Threat Mitigation Mapping0
ISO29115-9.2Fraud Detection and Response0
1010 Threats and controls0
10.110.1 Threats to, and controls for, the enrolment phase0
10.1.C1Enrolment control #1: IdentityProofing: PolicyAdherence (all LoAs)0
10.1.C2Enrolment control #2: IdentityProofing: In Person (LoA4)0
10.1.C3Enrolment control #3: IdentityProofing: AuthoritativeInformation (LoA1)0
10.1.C4Enrolment control #4: IdentityProofing: AuthoritativeInformation (LoA2)0
10.1.C5Enrolment control #5: IdentityProofing: AuthoritativeInformation (LoA3)0
10.1.C6Enrolment control #6: IdentityProofing: AuthoritativeInformation (LoA4)0
10.210.2 Threats to, and controls for, the credential management phase0
10.2.C1Credential management control #1: AppropriateCredentialCreation (LoA1, LoA2)0
10.2.C10Credential management control #10: ActivatedByEntity (LoA3)0
10.2.C11Credential management control #11: ActivatedByEntity (LoA4)0
10.2.C12Credential management control #12: CredentialSecureStorage (LoA1)0
10.2.C13Credential management control #13: CredentialSecureStorage (LoA2)0
10.2.C14Credential management control #14: CredentialSecureStorage (LoA3)0
10.2.C15Credential management control #15: CredentialSecureStorage (LoA4)0
10.2.C16Credential management control #16: CredentialSecureRevocation&Destruction (all LoAs)0
10.2.C17Credential management control #17: CredentialSecureRenewal (LoA1, LoA2)0
10.2.C18Credential management control #18: CredentialSecureRenewal (LoA3)0
10.2.C19Credential management control #19: CredentialSecureRenewal (LoA4)0
10.2.C2Credential management control #2: AppropriateCredentialCreation (LoA3, LoA4)0
10.2.C20Credential management control #20: RecordRetention (LoA1, LoA2)0
10.2.C21Credential management control #21: RecordRetention (LoA3, LoA4)0
10.2.C3Credential management control #3: HardwareOnly (LoA4)0
10.2.C4Credential management control #4: StateLocked (LoA4)0
10.2.C5Credential management control #5: TrackedInventory (all LoAs)0
10.2.C6Credential management control #6: AppropriateCredentialIssuance (LoA1)0
10.2.C7Credential management control #7: AppropriateCredentialIssuance (LoA2, LoA3)0
10.2.C8Credential management control #8: AppropriateCredentialIssuance (LoA4)0
10.2.C9Credential management control #9: ActivatedByEntity (LoA1, LoA2)0
10.310.3 Threats to, and controls for, the authentication phase0
10.3.C1Authentication control #1: MultiFactorAuthentication (LoA3, LoA4)0
10.3.C10Authentication control #10: MutualAuthentication0
10.3.C11Authentication control #11: NoTransmitPassword0
10.3.C12Authentication control #12: EncryptedAuthentication0
10.3.C13Authentication control #13: DifferentAuthenticationParameter0
10.3.C14Authentication control #14: Timestamp0
10.3.C15Authentication control #15: PhysicalSecurity0
10.3.C16Authentication control #16: EncryptedSession0
10.3.C17Authentication control #17: FixProtocolVulnerabilities0
10.3.C18Authentication control #18: CryptographicMutualHandshake0
10.3.C19Authentication control #19: CredentialActivation0
10.3.C2Authentication control #2: StrongPassword0
10.3.C20Authentication control #20: CodeDigitalSignature0
10.3.C21Authentication control #21: LivenessDetection0
10.3.C3Authentication control #3: CredentialLockOut0
10.3.C4Authentication control #4: DefaultAccountUse0
10.3.C5Authentication control #5: AuditAndAnalyze0
10.3.C6Authentication control #6: HashedPasswordWithSalt0
10.3.C7Authentication control #7: AntiCounterfeiting0
10.3.C8Authentication control #8: DetectPhishingFromMessages0
10.3.C9Authentication control #9: AdoptAntiPhishingPractice0
1111 Service assurance criteria0
66 Levels of assurance0
6.16.1 Level of assurance 1 (LoA1)0
6.26.2 Level of assurance 2 (LoA2)0
6.36.3 Level of assurance 3 (LoA3)0
6.46.4 Level of assurance 4 (LoA4)0
6.56.5 Selecting the appropriate level of assurance0
6.66.6 LoA mapping and interoperability0
6.76.7 Exchanging authentication results based on the 4 LoAs0
77 Actors0
88 Entity authentication assurance framework phases0
8.18.1 Enrolment phase0
8.1.18.1.1 Application and initiation0
8.1.28.1.2 Identity proofing and identity information verification0
8.1.38.1.3 Record-keeping/recording0
8.1.48.1.4 Registration0
8.28.2 Credential management phase0
8.2.18.2.1 Credential creation (pre-processing, initialization, binding)0
8.2.28.2.2 Credential issuance0
8.2.38.2.3 Credential activation0
8.2.48.2.4 Credential storage0
8.2.58.2.5 Credential suspension, revocation and/or destruction0
8.2.68.2.6 Credential renewal and/or replacement0
8.2.78.2.7 Record-keeping (credential management)0
8.38.3 Entity authentication phase0
8.3.18.3.1 Authentication0
8.3.28.3.2 Record-keeping (authentication)0
99 Management and organizational considerations0
9.19.1 Service establishment0
9.29.2 Legal and contractual compliance0
9.39.3 Financial provisions0
9.49.4 Information security management and audit0
9.59.5 External service components0
9.69.6 Operational infrastructure0
9.79.7 Measuring operational capabilities0
AA Annex A (normative): Characteristics of a credential0
APPIAppendix I (informative): Privacy and protection of PII0
FRONTClauses 1 to 5: scope, references, definitions, abbreviations and conventions0
STANDARDISO/IEC 29115:2013: the standard, its scope and what is held0
STATUSEdition status: 2013 remains the edition; the ITU revised X.1254 alone in 20200

Tell me when ISO/IEC 29115:2013 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO/IEC 29115:2013, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition