OIM - Identity management manual de 2025
OIM - Organización Internacional para las Migraciones
Descargar PDF
Disponible
Detalles
- Título
- OIM - Identity management manual de 2025
- Autor
- OIM - Organización Internacional para las Migraciones
- Categoría
- Doctrina
- Área del derecho
- Migratorio
- Año
- 2025
IDENTITY MANAGEMENT MANUALThe opinions expressed in this publication are those of the authors and do not necessarily reflect the views of the International Organization for Migration (IOM). The designations employed and the presentation of material throughout the publication do not imply expression of any opinion whatsoever on the part of IOM concerning the legal status of any country, territory, city or area, or of its authorities, or concerning its frontiers or boundaries. IOM is committed to the principle that humane and orderly migration benefits migrants and society. As an intergovernmental organization, IOM acts with its partners in the international community to: assist in meeting the operational challenges of migration; advance understanding of migration issues; encourage social and economic development through migration; and uphold the human dignity and well-being of migrants. This publication adheres to the IOM Legal Identity Strategy which lays the foundation for supporting individuals, States, and governments to meet Sustainable Development Goals (SDG) Target 16.9 and Objective 4 of the Global Migration Compact. This publication was made through the support IOM’s Cooperation on Migration and Partnerships for Sustainable Solutions (COMPASS) initiative, designed to protect people on the move, combat human trafficking and smuggling and support dignified return and sustainable reintegration. The programme focuses on systemic changes that are critical to addressing the underlying causes of migrants’ vulnerability, gender equality and exclusion, including in humanitarian and fragile settings; supporting rights-based policies and legislation; equitable access to essential protection services; strengthening local partnerships for migrant inclusion and social cohesion; access to legal identity; reinforcing data-driven responses; and influencing social behaviours and norms. The programme is being implemented in partnership with 14 partner States.
Publisher: International Organization for Migration 17 R oute des Morillons P .O. Box 17 1211 Gene va 19
S witzerland T el.: +41 22 717 9111
F ax: +41 22 798 6150
Ema il: hq@iom.int Website: www.iom.int
Coordination: I. Dourado and A. Boronbaeva.
Design: M. Fournier.
el.: +41 22 717 9111
F ax: +41 22 798 6150
Ema il: hq@iom.int Website: www.iom.int
Coordination: I. Dourado and A. Boronbaeva.
Design: M. Fournier.
This publication was issued without formal editing by IOM.
Required citation: International Organization for Migration (IOM) (2025). Identity management manual. IOM, Geneva.
ISBN 978-92-9278-077-7 (PDF)
© IOM 2025 Some rights reserved. This work is made available under the Creative Commons Attribution-NonCommercial-NoDerivs 3.0 IGO License (CC BY-NC-ND 3.0 IGO). For further specifications please see the Copyright and T erms of Use. This publication should not be used, published or redistributed for purposes primarily intended for or directed towards commercial advantage or monetary compensation, with the exception of educational purposes, e.g. to be included in textbooks.
Permissions: Requests for commercial use or further rights and licensing should be submitted to publications@iom.int. https://creativecommons.org/licenses/by -nc-nd/3.0/igo/legalcode
PUB2025/037/RIDENTITY
MANAGEMENT MANUAL1. INTRODUCTION • Advancing global goals and upholding human rights.... • Objectives of the manual .................................................... • Methodology ...........................................................................
2. IDENTITY MANAGEMENT FRAMEWORKS • ICAO traveller identification programme strategy....... ◦ Key elements of the ICAO traveller identification programme strategy ......................................................... • ICAO’s evidence of identity ............................................... ◦ Key principles of evidence of identity ......................... ◦ Objectives of evidence of identity ............................... ◦ Role of foundational documents and biometrics............ • ISO standards for identity management ......................... • National Institute of Standards and T echnology SP 800-63 guidelines for digital identity ............................... • The international telecommunication union guidelines on digital identity ............................................... • United Nations Legal Identity Agenda (UNLIA) .......... • World Bank identification for development initiative..
- ISO standards for identity management ......................... • National Institute of Standards and T echnology SP 800-63 guidelines for digital identity ............................... • The international telecommunication union guidelines on digital identity ............................................... • United Nations Legal Identity Agenda (UNLIA) .......... • World Bank identification for development initiative.. • Regional frameworks and standards ................................ ◦ European Union: General Data Protection Regulation and eIDAS Regulation ................................ ◦ African Union ..................................................................... ◦ Association of Southeast Asian Nations (ASEAN): mutual recognition and digital identity................................. ◦ Organization of American States (OAS).....................
◦ Gulf Cooperation Council (GCC).................................
3. INTERNATIONAL LAW AND HUMAN RIGHTS IN LEGAL IDENTITY • Key international standards and conventions ............. • Human rights principles in identity management ...... ◦ Right to privacy .................................................................. ◦ Challenges ............................................................................ • Principles of data protection ............................................. ◦ Practical strategies ............................................................ • Example: European Union’s General Data Protection Regulation ................................................................................ • Key provisions of the General Data Protection Regulation ................................................................................ • Data subject rights under the General Data Protection Regulation .......................................................... • Non-discrimination .............................................................. ◦ Challenges ............................................................................ ◦ Practical strategies ............................................................ • Inclusivity and accessibility .................................................. ◦ Challenges ............................................................................ ◦ Practical strategies ............................................................ • Accountability and oversight .............................................. ◦ Challenges ............................................................................ ◦ Practical strategies ............................................................
4. FUNDAMENTALS OF IDENTITY • What is identity? .................................................................... • Components of identity ...................................................... • Distinction between functional and foundational identities ◦ Foundational identities ..................................................... ◦ Characteristics ................................................................... ◦ Functional identities .......................................................... • T ypes of identities .................................................................. ◦ Legal identity........................................................................ ◦ Digital identity .................................................................... ◦ Biometric identity .............................................................. ◦ Social Identity .....................................................................
5. IDENTITY LIFECYCLE MANAGEMENT • Identity creation and registration ..................................... ◦ Processes and considerations ........................................ ◦ Recommended best practices ....................................... ◦ Key considerations ............................................................ ◦ Practical challenges ........................................................... • Credential issuance ..................................................................
◦ Biometric identity .............................................................. ◦ Social Identity .....................................................................
5. IDENTITY LIFECYCLE MANAGEMENT • Identity creation and registration ..................................... ◦ Processes and considerations ........................................ ◦ Recommended best practices ....................................... ◦ Key considerations ............................................................ ◦ Practical challenges ........................................................... • Credential issuance .................................................................. ◦ Processes and considerations .......................................
1 2 2 3 14 15 16 16 16 17 18 19 19 19 20 20 21 22 22 23 24 24 25 26 27 28 29 29 29 30 31 32 32 33 33 34 36 36 37 37 37 38 38 4 6 6 7 7 7 8 8 9 10 10 11 12 12 12 13 13 13 Contentsiii ◦ Recommended best practices .................................... ◦ Key considerations ......................................................... ◦ Practical challenges ........................................................ • Identity proofing and verification ..................................... ◦ Processes and considerations .................................... ◦ Recommended practices ............................................. ◦ Key considerations ........................................................ ◦ Practical challenges ....................................................... • Identity maintenance and auditing ................................... ◦ Processes and considerations .................................... ◦ Recommended best practices .................................... ◦ Key considerations........................................................... ◦ Practical challenges ........................................................ • Identity deactivation and revocation ............................... ◦ Processes and considerations .................................... ◦ Recommended best practices ................................... ◦ Key considerations ........................................................
6. HOW TO TRUST AN IDENTITY:
IDENTITY AUTHENTICATION AND LEVELS OF ASSURANCE • Authentication methods ...................................................... • Multi-factor authentication ............................................... ◦ T ypes of multi-factor authentication ...................... ◦ Challenges of implementing multi-factor authentication ................................................................ ◦ Recommended best practices .................................... ◦ Key considerations ......................................................... • Biometric authentication ..................................................... ◦ T ypes of biometric authentication ............................ ◦ Benefits of biometric authentication ....................... ◦ Challenges of biometric authentication .................. ◦ Best practices .................................................................. ◦ Key considerations ........................................................
- Biometric Authentication and General Data
◦ Key considerations ......................................................... • Biometric authentication ..................................................... ◦ T ypes of biometric authentication ............................ ◦ Benefits of biometric authentication ....................... ◦ Challenges of biometric authentication .................. ◦ Best practices .................................................................. ◦ Key considerations ........................................................ • Biometric Authentication and General Data Protection Regulation .......................................................... • Password-based authentication ......................................... ◦ Challenges ........................................................................ ◦ Recommended best practices ................................... ◦ Key considerations ........................................................ • T oken-based authentication ............................................... ◦ T ypes of tokens................................................................ ◦ Benefits of token-based authentication .................. ◦ Challenges ........................................................................ ◦ Racommended best practices ................................... ◦ Key considerations ........................................................ • Digital identity and public key infrastructure .............. ◦ Challenges ........................................................................ ◦ Recommended best practices ................................... ◦ Key considerations ........................................................ • Levels of assurance .............................................................. ◦ Levels of assurance models ....................................... ◦ Guidelines on levels of assurance using National Institute of Standards and T echnology Special publication 800-63-3 .............................................................. ◦ Practical examples of levels of assurance implementation.... ◦ Challenges ........................................................................ ◦ Recommended best practices ................................... ◦ Key considerations .........................................................
7. IDENTITY MANAGEMENT
ARCHITECTURE: BIOMETRICS AND DIGITAL IDENTITY • Biometrics and digital identity management ................. • Key features of digital identities ........................................ • Digital identity ecosystem .................................................. • Identity federation ................................................................. ◦ Key components of identity federation .................. • Single Sign-On ........................................................................ • Use-case: National Institute of Standards and T echnology Digital Identity Guidelines ........................... • SP 800-63A: Enrolment and identity proofing ............. • Integrated identity management architecture .............. • Key considerations for implementing integrated identity management architectures .................................
8. ACCESS CONTROL • Models of access control ........................................................ • Role-based access control ...................................................... • Mandatory access control ...................................................... • Attribute-based access control ............................................ • Discretionary access control ................................................ • Cloud access control models ............................................... • Access control implementation in Identity and Access Management ...............................................................................
8. ACCESS CONTROL • Models of access control ........................................................ • Role-based access control ...................................................... • Mandatory access control ...................................................... • Attribute-based access control ............................................ • Discretionary access control ................................................ • Cloud access control models ............................................... • Access control implementation in Identity and Access Management ............................................................................... • Key considerations for government practitioners .........
9. CYBERSECURITY • Risks in cybersecurity for identity management ............. • Global challenges in cybersecurity regulation .................. • Recommended practices for strengthening cybersecurity in identity management ............................... ◦ Risk assessments ................................................................ ◦ Data encryption and pseudonymization .................... ◦ Access controls .................................................................. ◦ Continuous monitoring and auditing ........................... ◦ Incident response and breach notification ................
10. BREEDER DOCUMENTS • Importance of breeder documents in identity management ............................................................................... • Birth certificates as a breeder document .......................... • Challenges in birth certificate management ..................... • Best practices in breeder document management ........ • Key considerations ...................................................................
11. TRAVEL DOCUMENTS • Passports ..................................................................................... ◦ T ypes of passports ............................................................ ◦ International standards governing passports ............ ◦ Security features in modern passports ...................... ◦ Electronic passports (ePassports) ............................... ◦ Issuance and lifecycle management ............................. ◦ Passport issuance process ............................................. ◦ Best practices for passport issuance and management ............................................................................. • Identity cards ............................................................................. ◦ Key functions of identity cards .................................... ◦ Security features of identity cards according to ICAO Doc 9303 ................................................................ ◦ Identity card issuance process ...................................... ◦ Best practices for identity card issuance and management .................................................................................
12. EMERGING TRENDS AND TECHNOLOGIES • The evolution of digital identity ............................................... ◦ Key considerations ................................................................. • Decentralized identity systems ................................................. ◦ Key benefits for governments ........................................... ◦ Key considerations ................................................................. • Biometric authentication ............................................................. ◦ Key considerations ................................................................. • Artificial intelligence and identity management .............. ◦ Applications of artificial intelligence in identity management .......................................................................
◦ Key considerations ................................................................. • Decentralized identity systems ................................................. ◦ Key benefits for governments ........................................... ◦ Key considerations ................................................................. • Biometric authentication ............................................................. ◦ Key considerations ................................................................. • Artificial intelligence and identity management .............. ◦ Applications of artificial intelligence in identity management ....................................................................... ◦ Key considerations ................................................................. ◦ Examples of artificial intelligence in action .............. • Cloud-based identity management ......................................... ◦ Key considerations ................................................................. • Identity-as-a-service ...................................................................... ◦ Key considerations ................................................................. • Digital travel credentials ............................................................... ◦ How digital travel credentials function in practice.. ◦ Key considerations ........................................................... ◦ ICAO data barcode ......................................................... ◦ Key considerations ...........................................................
13. CONCLUSION
64 65 66 66 68 68 69 69 71 72 73 126 46 47 48 49 49 49 50 50 50 52 52 53 53 54 54 54 55 55 55 55 56 56 56 56 56 57 57 57 58 58 60 60 61 62 62 38 39 39 40 40 40 41 41 42 42 43 43 43 44 44 45 45 74 75 76 78 80 81 82 83 83 84 86 86 87 87 87 87 87 87 88 90 90 91 91 93 94 96 97 97 98 98 99 101 102 105 105 106 110 112 114 116 116 116 116 116 117 117 118 118 118 119 119 119 120 120 120 120 122 124 124In an increasingly interconnected world, identity management has become a cornerstone for protection, security, accessibility and efficiency across various sectors. From safeguarding personal identities to enabling seamless cross-border travel and digital transactions, identity management frameworks are pivotal to building trust and ensuring the integrity of interactions in both physical and digital environments.
124 124In an increasingly interconnected world, identity management has become a cornerstone for protection, security, accessibility and efficiency across various sectors. From safeguarding personal identities to enabling seamless cross-border travel and digital transactions, identity management frameworks are pivotal to building trust and ensuring the integrity of interactions in both physical and digital environments. This document also aligns with the IOM Strategic Plan 2024–2028, which prioritizes capacity development for States in migration governance and enhancing the protection and empowerment of migrants. By strengthening identity management, IOM contributes to improving identity and border management, access to services and the recognition of migrants’ rights. Additionally, the Strategic Plan reflects the goals of the IOM Legal Identity Strategy, which underscore the importance of holistic, inclusive and rights-based approaches to identity management systems. This document explores emerging trends, challenges, and real-world case studies to offer a comprehensive perspective on the evolving landscape of identity management. It seeks to address the complexities of implementing secure and robust identity solutions while fostering crossborder collaboration and innovation. The manual is designed to assist Member States in strengthening their legal identity systems by providing clear, standardized guidelines that improve migrants’ access to legal identity and uphold protections through inclusive, rights-based identity management practices.
This manual delves into the complexities and innovations in identity management, offering in-depth analyses on legal frameworks, technological advancements and best practices. With contributions from leading experts and organizations, it serves as a comprehensive guide for policymakers, practitioners and stakeholders committed to strengthening identity systems worldwide. Identity management is a policy that does not begin with complex layers of technological solutions and high-end travel documents. Instead, it starts with a clear policy outlining what needs to be achieved using available resources to effectively manage identities throughout their lifecycle. Technology is merely a tool in supporting the policy and processes of identity management, with the aim of improving customer experience and security simultaneously. Technology should adhere to the policies and process in place, not
achieved using available resources to effectively manage identities throughout their lifecycle. Technology is merely a tool in supporting the policy and processes of identity management, with the aim of improving customer experience and security simultaneously. Technology should adhere to the policies and process in place, not the other way around. After all, if an identity is not created and verified reliably, all that follows becomes compromised. Improving identity management is intrinsically aligned with the Global Compact for Migration, as it addresses key objectives central to both frameworks. The Global Compact for Migration, particularly through Objective 4, emphasizes the importance of provision of legal identity and adequate documentation to all migrants. Enhancing identity management systems ensures that migrants have access to secure and universally recognized identity credentials, reducing vulnerabilities to exploitation and promoting inclusivity.
ForewordAAL: Authenticator assurance levels – A measure of the confidence that the user accessing a system is who they claim to be, defined in standards like
NIST SP 800-63.
ABAC: Attribute-based access control – An access control system that grants access based on attributes (e.g., roles, environmental factors).
AI: Artificial intelligence – A broad area of computer science focused on creating smart machines that can perform tasks requiring human intelligence.
CEN: European Committee for Standardization – Develops standards for a wide range of sectors in Europe.
CISA: Cybersecurity information sharing act – U.S. law promoting the sharing of cybersecurity threat data between the government and private sector.
CRVS: Civil registration and vital statistics – Systems used for recording vital events like births, deaths, and marriages.
DAC: Discretionary access control – An access control system where the owner of the data decides who gets access to it.
DTC: Digital travel credentials – Digital platforms for storing passport or travel-related information, following standards like ICAO.
EOI: Evidence of identity – Processes to verify an individual’s identity using
control system where the owner of the data decides who gets access to it.
DTC: Digital travel credentials – Digital platforms for storing passport or travel-related information, following standards like ICAO.
EOI: Evidence of identity – Processes to verify an individual’s identity using reliable sources (e.g. birth certificates).
EU: European Union – A political and economic union of 27 member States located in Europe.
FALs: Federation Assurance Levels
GDPR: General data protection regulation – European Union law governing data protection and privacy in the European Union and the European
Economic Area.
List of abbreviationsvii LIST OF ABREVIATIONS IAM: Identity and access management – A framework of policies and technologies to ensure that the right individuals access the right resources.
ICAO: International Civil Aviation Organization – A UN specialized agency responsible for establishing global civil aviation standards, including for travel documents.
ID4D: Identification for development ISO: International Organization for Standardization – International body that develops and publishes standards.
ITU – International Telecommunication Union
LoA: Levels of assurance – A term used to describe the degree of confidence in the accuracy of the identity verification process.
MAC: Mandatory access control – Access control system where the system, not the owner, determines access rights
MFA: Multi-factor authentication – Security system requiring multiple forms of verification to access a resource.
MRTDs: Machine readable travel documents – Passports and other travel documents that can be read by machines for identification.
MRZ: Machine-readable zone – The section of a travel document (such as a passport) that contains data readable by machines.
NIST: National Institute of Standards and Technology – U.S. agency that develops and promotes measurement standards, including for cybersecurity.
OCR: Optical character recognition – Technology to convert different types of documents into machine-readable text.
data readable by machines.
NIST: National Institute of Standards and Technology – U.S. agency that develops and promotes measurement standards, including for cybersecurity.
OCR: Optical character recognition – Technology to convert different types of documents into machine-readable text.
PKD: Public key directory – ICAO-managed system for securely exchanging public keys used in e-passports.
RBAC: Role-based access control – An access control policy that restricts system access to authorized users based on their role.
SAML: Security assertion markup language – An open standard for exchanging authentication and authorization data between parties.
SSO: Single sign-on – A system allowing users to access multiple applications with one set of login credentials.
TRIP: Traveller Identification Programme
UNLIA: United Nations Legal Identity AgendaIntroduction
1.1 Identity management plays a crucial role in modern governance and international security, enabling accurate identification, verification and authentication of individuals across physical and digital environments. It entails a structured approach involving processes, policies and technologies that enable the accurate establishment and verification of an individual’s identity. According to the IOM Glossary on Migration, Identity Management is defined as: “ ” A system comprising a vision, policy and facilities for the management of identities.1 At its core, identity management encompasses the entire lifecycle of identity, from creation to ver
Estás viendo una vista previa
Lee el documento completo con Ariel
Este es un fragmento de uno de los más de 1.2 millones de documentos de la biblioteca de Ariel. Crea tu cuenta para leerlo completo, descargarlo y consultarlo con Ariel, que siempre te lleva a la fuente exacta: Ariel NO alucina.