IT Management Frameworks

There are many different frameworks that can be used for managing the delivery of cost-effective IT services. Many frameworks only cover a specific aspect of IT (such as information security, service management, quality etc.).

On this page we will look at all the major frameworks, what they cover, how they interlink, and provide guidance and products on how to implement them.

For more information on any consultancy, training or books relating to these frameworks, please contact a member of our team on 00 800 48 484 484.  

Calder-Moir IT framework

The only super-framework that pulls all the existing frameworks together in a way that enables an organisation to maximise its benefit from them is the Calder-Moir IT Governance Framework.

Deploying the best practice guidance as set out in the IT governance Standard ISO38500, the Calder-Moir Framework identifies six business areas that can each contain separate frameworks to make up an overall IT governance framework:

  • Business strategy
  • Risk, conformance and compliance
  • IT strategy
  • Change
  • Information technology
  • Operations

Learn more and how to implement an overarching governance framework with the Calder-Moir Framework Toolkit.

ISO 27001 – information security management systems (ISMS)

ISO 27001 is the international standard which details the requirements for establishing and maintaining an information security management system (ISMS), an organised approach for managing an organisation’s information security which encompasses people, processes and technology.

ISO 27001 should be used in conjunction with ISO 27002, which provides implementation guidance and controls.

Learn more on our dedicated ISO 27001 page.

ISO/IEC 20000 – ITSM standard

ISO 20000 is the international standard which sets out a specification for a service management system (SMS). It also covers ongoing maintenance and continual improvement.

ISO 20000 enables an organisation to deliver effective IT services to meet business and customer requirements. The standard itself has two main parts:

  • Part 1: Specification (Organisations must comply with Part 1 to achieve ISO 20000 certification.)
  • Part 2: Code of Practice (Part 2 gives guidance on the implementation of an SMS that meets the requirements in Part 1.)

ISO 20000 can be implemented by any type or size of organisation. However, small organisations may find implementation more complex, so other frameworks maybe more appropriate in those circumstances.

Organisations looking to certify to ISO 20000 will want to establish their level of compliance to the standard prior to undertaking a formal certification. 

Learn more on our ISO 20000 page.

IT service capability maturity model

The IT service capability maturity model (CMM) is a five-level scale which allows organisations to measure and improve their IT service delivery capabilities. Each of the levels detail certain best practice process areas that have to be in place before the organisation resides on that level.

As an organisation implements these best practice processes the organisation moves up to the appropriate level on the IT service CMM, improving service delivery through the use of better processes.

No organisations currently run formal accreditation schemes against the IT service CMM, but there are third-party companies which will visit an organisation and perform a process assessment to judge the maturity of the organisation’s processes.

There are various different methodologies you can use to undertake a process assessment. Due to the similarities between the Software CMMI (created by Carnegie Mellon University) and the IT service CMM, the same methods can be used to perform a process assessment for both.

For more information see the Software Capability Maturity Model web page or the IT Service CMM website.

Six Sigma – quality and process improvement

Six Sigma is an effective and adaptable measurement-based improvement methodology which can be used for delivering quality IT services. The main aim of Six Sigma is to reduce variation in processes by offering a structure by which organisations can constantly improve routine IT processes and eliminate defects, waste and cost, thereby increasing service quality and customer satisfaction.

Six Sigma can be used in conjunction with the ITIL (Information Technology Infrastructure Library) framework.

There is no formal certification for an organisation against the Six Sigma framework. However, one of the main parts of Six Sigma implementation is the need to train certain individuals to a high degree of familiarity with the methodology itself so that they can work on the implementation/project team.

Various levels of qualification are available for these individuals to demonstrate their level of competence in Six Sigma. Black Belt, for example, certifies the individual is a highly experienced Six Sigma practitioner; Green Belt demonstrates that an individual has trained in Six Sigma and is qualified to work on the implementation/project team under the direction of a Six Sigma Black Belt.

Formal training and certification in these qualifications are available from Motorola Solutions, the creators of Six Sigma methodology.

IT balanced scorecard

The IT Balanced Scorecard is a metrics-based mechanism that can be used to enable better IT performance and facilitate the alignment of IT with overall business goals. The Balanced Scorecard (BSC) mechanism itself was originally developed on an enterprise-wide level by Robert Kaplan and David Norton.

When implementing the IT Balanced Scorecard there are many issues to consider. Jessica Keyes lays the groundwork for implementing the scorecard approach and successfully integrating it with corporate strategy in her comprehensive book Implementing the IT Balanced Scorecard: Aligning IT with Corporate Strategy.

ISO 38500 – the international standard for corporate governance of IT (IT governance)

ISO 38500 relates to the governance of management processes and decisions relating to an organisation’s information and communication services. ISO 38500 is the first international Standard for IT governance, and provides an efficient and effective framework for IT governance, leading to better alignment of IT with organisational decisions. The advice and guidance in this Standard is applicable whatever the size or type of organisation, whether it is in the corporate, public or not-for-profit sector. It is not only applicable to directors but also provides essential guidance on the appropriate governance of IT to all key members of staff. Visit our information page for further information on ISO 38500.


COBIT is a control framework that provides best practices, tools and guidance for the effective management and governance of enterprise IT.

COBIT 5 was published in early 2012, superseding COBIT 4.1. It builds and expands on the guidance in COBIT 4.1 by integrating many frameworks and standards, including ISACA©’s VAL IT and Risk IT, ITIL, and ISO standards including ISO 38500 and ISO 27001.

Learn more on our COBIT 5 page, where you can find information about the official manual and training courses.

M_o_R – management of risk

M_o_R (Management of Risk) was originally developed by the UK Office of Government Commerce (OGC) as a methodology to deal with the effective control of risk. It is used in both public and private sectors internationally.

M_o_R can be used by any type or size of organisation to identify, manage, reduce and eliminate risk. An in-depth resource for organisations looking to use M_o_R has been provided by AXELOS in the form of the official M_o_R manual – Management of Risk: Guidance for Practitioners – 2010 Edition, which should be used as the official source of best practice information relating to the management of risk.

There are two levels of official qualification available for practitioners: the Foundation and Practitioner. Training courses in M_o_R, including the exams, are available from Accredited Training Providers (ATOs).

BiSL – business information services library

The Business Information Services Library (BiSL) is a public-domain framework for the effective control of an organisation’s information systems. The current owner of the BiSL copyright is the ASL BiSL Foundation.

BiSL consists of a framework of processes, a library of best practices, and publications available from ASL BiSL Foundation website. BiSL is primarily used in the Netherlands and provides guidance in the areas of operational IT control, information systems in the organisations processes and information management.

The main aim of BiSL is to provide a tool which can be utilised to improve the performance of IT and of information system management departments and aid with the improvement of internal business processes.

For more information on BiSL see the ASL BiSL Foundation website.

ITIL – the IT infrastructure library

ITIL is a best practice framework for the effective delivery of IT services that add value. ITIL has now become the de facto standard for IT Service Management worldwide. ITIL is centred on the five core publications of the ITIL Lifecycle Publication Suite, each of which addresses a specific area of IT Service Management:

  • Service Design
  • Service Transition
  • Service Operation
  • Service Strategy
  • Continual Service Improvement

ITIL has a series of qualifications available to ITSM professionals, and is also very useful to organisations looking to achieve ISO20000 certification. Learn more about ITIL and ITIL qualifications on our ITIL page.

Business process framework (eTom)

The business process framework (eTom) is a critical component of the TM Forum’s blueprint for enabling successful change and transformation within an organisation. The blueprint is called Frameworx.

The business process framework (eTom) offers a catalogue of key business processes that are required to run a successful service-focused business. It has three major process areas, they are:

  • Strategy, Infrastructure and Product
  • Operations
  • Enterprise Management

For more information on eTOM see the TM Forum website.

ASL – application services library

The application services library (ASL) is a public domain, mainly European, framework, developed by the ASL BiSL Foundation, which provides guidance with supporting best practices for designing and carrying out effective application management. ASL does not focus on supporting the application itself, but focuses on supporting business processes using information systems (for example managing and maintaining the application (software), databases, documentation, availability, programming, system development, design and impact analysis).

Accreditation against the ASL framework is available on an individual and organisation wide basis. For more on these certifications and other information on ASL see the ASL BiSL Foundation website.

MSP – managing successful programmes

Managing successful programmes (MSP) is a methodology used around the world. The aim of MSP is to provide organisations with an effective tool to manage programmes in order to achieve a goal at a strategic level so that the organisation can achieve benefits and improvements in its business. It is often used for IT programmes.

Programme management should not be confused with project management. Programme management is an organised and systematic approach to setting up and managing a programme. Programmes are made up of multiple projects identified by an organisation that together will deliver some defined objective or goal for the organisation. A programme can only succeed if the projects within it succeed.

MSP is usually used in combination with PRINCE2, the project management methodology from AXELOS.

MSP provides organisations with a set of best-practice principles and processes for use when managing a programme. These are outlined by AXELOS, the authors of the MSP methodology in the MSP Manual.

No organisation-wide accreditation is available for organisations using the MSP method. However, organisations can now assess the level of maturity of their Programme Management processes.

PRINCE2 – projects in controlled environments

Projects in controlled environments (PRINCE2) is a structured method for managing all types of project in any size or type of organisation. PRINCE2 covers the management, control, organisation and delivery of a project.

PRINCE2 is often used for the management of projects within an MSP framework. It is the de facto Project Management standard in the UK, and has also been widely adopted in countries all over the world.

An in-depth description of the PRINCE2 project management method is provided in the PRINCE2 Manual – Managing Successful Projects with PRINCE2, which has been designed to be a role-specific handbook for project managers, team managers and project support.

There are currently three levels of PRINCE2 qualifications available to inidividuals. AXELOS, the owner of PRINCE2, provides essential advice and guidance on both of the Foundation and Practitioner exams in Passing the PRINCE2 Exams. This book has been updated to reflect the latest changes in PRINCE2 and provides multiple choice questions and specimen answers to typical project management situations.

PRINCE2 Practitioners have to re-register every three to five years by sitting and passing a Practitioner-level re-registration examination. Passing the PRINCE2 Exams will also be of aid to individuals studying for this exam.

Find out everything you need to know on PRINCE2 on our page.

PMBOK – project management body of knowledge

The project management body of knowledge (PMBOK) is a library of best practices in the field of project management developed by the Project Management Institute® (PMI®) institute in the United States. PMBOK consists of processes and knowledge areas that are generally accepted as best practice in the project management field.

PMBOK can be applied to any type or size of project, whether in the public, private or not-for-profit sectors. The PMBOK standard has also been adopted internationally by the IEEE as IEEE 1490.

The Project Management Institute’s PMBOK Guide, 5th Edition is an essential reference for every project management practitioner's library.

Find out everything you need about PMBOK on our information page.

OPM3 – organisational project management maturity model

The Organisational Project Management Maturity Model (OPM3), published by the Project Management Institute (PMI), is a maturity model that can be used to benchmark the current maturity of the organisation’s portfolio, programme and project processes and drive improvement.

OPM3 is made up of three key interlocking elements: the knowledge element, the assessment element, and the improvement element.

More information on OPM3 can be found on the PMI website.

Speak to an expert

Whatever the nature or size of your problem, we are here to help. Get in touch today using one of the contact methods below. 

SAVE 25%