Skip to main content

ISO/IEC 38500:2015

Information technology -- Governance of IT for the organization

General information

Withdrawn from 23.02.2024
Directives or regulations

Standard history

ISO/IEC 38500:2008
ISO/IEC 38500:2015 provides guiding principles for members of governing bodies of organizations (which can comprise owners, directors, partners, executive managers, or similar) on the effective, efficient, and acceptable use of information technology (IT) within their organizations.
It also provides guidance to those advising, informing, or assisting governing bodies. They include the following:
?   executive managers;
?   members of groups monitoring the resources within the organization;
?   external business or technical specialists, such as legal or accounting specialists, retail or industrial associations, or professional bodies;
?   internal and external service providers (including consultants);
?   auditors.
ISO/IEC 38500:2015 applies to the governance of the organization's current and future use of IT including management processes and decisions related to the current and future use of IT. These processes can be controlled by IT specialists within the organization, external service providers, or business units within the organization.
ISO/IEC 38500:2015 defines the governance of IT as a subset or domain of organizational governance, or in the case of a corporation, corporate governance.
ISO/IEC 38500:2015 is applicable to all organizations, including public and private companies, government entities, and not-for-profit organizations. ISO/IEC 38500:2015 is applicable to organizations of all sizes from the smallest to the largest, regardless of the extent of their use of IT.
The purpose of ISO/IEC 38500:20015 is to promote effective, efficient, and acceptable use of IT in all organizations by
?   assuring stakeholders that, if the principles and practices proposed by the standard are followed, they can have confidence in the organization's governance of IT,
?   informing and guiding governing bodies in governing the use of IT in their organization, and
?   establishing a vocabulary for the governance of IT.

Required fields are indicated with *

82.61 € incl tax
82.61 € incl tax
Standard monitoring

Customers who bought this item also bought


EVS-ISO/IEC/IEEE 15288:2016

Systems and software engineering - System life cycle processes (ISO/IEC/IEEE 15288:2015)
Withdrawn from 01.12.2023

ISO/IEC 38506:2020

Information technology -- Governance of IT -- Application of ISO/IEC 38500 to the governance of IT enabled investments
Newest version Valid from 19.02.2020

ISO/IEC 27001:2022

Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Newest version Valid from 25.10.2022

EVS-EN ISO/IEC 27002:2022

Information security, cybersecurity and privacy protection - Information security controls (ISO/IEC 27002:2022)
Newest version Valid from 01.12.2022