ISO/IEC standard ensures security and privacy of biometric data

by Shane Henson — August 22, 2011—To ensure security and privacy when managing and processing biometric information, the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) have jointly published a new international standard, ISO/IEC 24745:2011, Information technology Security techniques Biometric information protection. Facilities personnel looking to further protect the data created by company employees and others accessing their buildings could benefit from learning about this standard.

Biometrics refers to the automated identification of individuals based on their behavioral and physiological characteristics. It includes recognition technologies based on face, iris or palms image, voice patterns and the like, explains ISO.

With biometrics, if the authentication information is compromised, usual solutions such as issuing a new password or token are not available because biometric characteristics are difficult or impossible to change, warn ISO and IEC officials. Moreover, as more and more personal identifiable information is linked with biometric references, and this data is shared across international borders, it is crucial to safeguard the security of a biometric system and the privacy of data subjects with solid countermeasures as outlined in ISO/IEC 24745. This is particularly applicable to personnel working in federal and military buildings because of the sensitive information they may deal with, and that may be linked to their biometric data.

The standard specifies:

  • Analysis of threats and countermeasures inherent in a biometric and biometric system application models;
  • Security requirements for binding between a biometric reference and an identity reference;
  • Biometric system application models with different scenarios for the storage and comparison of biometric references; and
  • Guidance on the protection of an individual’s privacy during the processing of biometric information.