ISO/IEC 38500

International Standard for Corporate Governance of IT (IT Governance)

What is ISO 38500?

ISO/IEC 38500 is the International Standard for the Corporate Governance of Information Technology and is the official IT governance standard.

This standard applies to the governance of management processes relating to the information and communication services used by an organisation. These processes could be controlled by IT specialists within an organisation or by external service providers.

Buy your copy of ISO/IEC 38500 now

About ISO 38500

ISO/IEC 38500 applies to the governance of management processes and decisions relating to an organisation’s information and communication services.
It defines six principles:

  • Establish responsibilities
  • Plan to best support the organisation
  • Make acquisitions for valid reasons
  • Ensure necessary levels of performance
  • Ensure conformance with rules
  • Ensure respect for human factors
This Standard originated from an existing Australian standard, AS8015. ISO/IEC 29382, Corporate Governance of Information and Communication Technology, was first published early in 2007 and was officially re-named ISO/IEC 38500 in 2008. 

ISO/IEC 38500: A pocket guide, second edition

ISO/IEC 38500: A pocket guide, second edition

This useful pocket guide is an ideal introduction for those wanting to understand more about ISO 38500.

It describes the scope, application and objectives of the Standard and outlines its six core principles. It covers:

  • What is ISO/IEC 38500?
  • The corporate governance context
  • Scope, application and objectives
  • Principles and model for good governance of it
  • Implementing the six IT governance principles
  • ISO/IEC 38500 and the IT steering committee
  • Project governance
  • Other IT governance standards and frameworks
  • Integrated frameworks

Shop now

Implementing ISO 38500

Although ISO/IEC 38500 is a short and straightforward international standard, actual implementation of an IT governance framework can be challenging. The Calder-Moir IT Governance Framework evolved alongside the international standard as a conceptual approach to help organisations visualise effective IT governance, drawing on and integrating the wide range of IT management tools and systems that exist in the world today.

Start your implementation project with these key tools

  • ISO/IEC 38500: A pocket guide - this book provides an ideal introduction to the ISO/IEC 38500 standard and the much-discussed topic of IT Governance.
  • IT Governance: implementing frameworks and standards for the corporate governance of IT - this book provides practical guidance on implementing an IT governance framework based on ISO/IEC 38500 in your own organisation.
  • ISO 38500 IT governance standard - the advice and guidance in this standard is applicable to all organisations, including public and private companies, government organisations, and not-for-profit organisations, irrespective of their size or type, and regardless of the extent of their use of IT. It not only applies to directors but also provides essential guidance on the appropriate governance of IT to all key members of staff.