ISO/IEC 25642:2025 PDF
Information technology — Data governance — Data collaboration framework
Information technology — Data governance — Data collaboration framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 6
- Дата публикации:
- 1 октября 2025 г.
- Издание:
- ISO/IEC IS 25642 edition 1 version 1
- ICS:
- 35.020
This document specifies minimum recommendations for zero-copy data integration and includes guidance for building modular capabilities within a controlled data management environment which can be applied either as stand-alone experiences or combined into advanced solutions. This document provides a blueprint for IT and other leaders who rely on organizational data integrity to perform their functions to support the build of new digital solutions with granular and universally enforced data controls. This document applies to all sectors, including public and private companies, government entities, and not-for-profit organizations. This document is not intended for non-data intensive operational roles and does not specify interfaces with other systems or components. NOTE 1: This document does not define the specific people or groups who represent the rightful owner of given data – this is to be worked out by individual organizations. NOTE 2 to entry: This document does not force organizations into converging on a single data ontology, rather, it is intended to support a diversity of data models using the same physical data. NOTE 3: This document does not cover data exchanges or the management of data usage, including potential applications involving artificial intelligence. Guidance for data usage can be found in the following: ISO/IEC 5207 and ISO/IEC 5212.
Abstract
Overview
ISO/IEC 25642:2025 - Information technology - Data governance - Data collaboration framework defines minimum recommendations for zero-copy data integration and modular data capabilities inside a controlled data management environment. The standard describes a blueprint for IT and organizational leaders to build new digital solutions that reuse the same physical data across multiple data models while enforcing granular, universally applied access controls. It targets all sectors (public, private, government, not‑for‑profit) and is intended for data‑intensive roles; it is not a specification of system interfaces nor a definition of who legally owns data within an organization.
Key topics and technical requirements
- Zero-copy data integration: Emphasizes access-based collaboration instead of copying data into application-specific silos.
- Decouple data from applications: Design data architectures so applications consume shared data rather than creating new isolated databases.
- Data-as-a-product: Govern and manage data through defined data products, data domains, and stewards to assign responsibilities and quality requirements.
- Metadata-layer controls: Enforce access, protection and policy at the metadata level (not in application code), enabling uniform controls across consumers.
- Metadata-driven experiences: Use metadata to drive application behavior, access enforcement, versioning, lineage, and recoverability.
- Enterprise composability and modularity: Build modular capabilities that can operate standalone or be combined into advanced solutions.
- Operational governance mechanisms: Automate versioning, recoverability, lineage, and usage reporting to support auditability and compliance.
- Terminology and roles: Defines key terms such as data owner, data steward, data custodian, data domain, data product, and data schema.
Note: the standard does not cover data usage policies or AI-specific usage management (refer to ISO/IEC 5207 and ISO/IEC 5212).
Applications and practical value
- Accelerates digital transformation by reducing the integration overhead created by copy‑based architectures.
- Lowers compliance and privacy risk by centralizing access control and making deletion, portability, and auditability feasible.
- Supports cross‑functional collaboration (human-to-human, human-to-system, system-to-system), including scenarios involving multiple AI systems, without proliferating data copies.
- Applicable to initiatives such as open banking, smart cities, precision healthcare, and enterprise data platforms where data integrity, traceability, and reusable data models are needed.
Who should use this standard
- CIOs, data governance leads, enterprise architects, data engineers, and data stewards building or governing data-intensive systems.
- Organizations seeking to eliminate data silos, enforce consistent access controls, and enable composable data-driven solutions.
Related standards
- ISO/IEC 38500 (IT governance)
- ISO/IEC 38505‑1 (data governance for IT)
- ISO/IEC 5207 and ISO/IEC 5212 (guidance on data usage and AI-related data usage management)
Keywords: ISO/IEC 25642:2025, data governance, data collaboration framework, zero-copy data integration, metadata controls, data products, data domains, enterprise composability, data silos.
Технические детали
- Технический комитет
- ISO/IEC JTC 1 - Information technology
- SKU
- ISO/IEC 25642:2025
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 5207:2024
ДействующийInformation technology. Data usage. Terminology and use cases
1 Scope This document sets out terminology and use cases for data use, sharing and exchange. This document provides use cases detailing various types of data usage from both historical and hypothetic…
BS ISO/IEC 5212:2024
ДействующийInformation technology. Data usage. Guidance for data usage
1 Scope This document provides high-level guidance to data users, whether organizations or individuals, to assist in realizing the benefits from data usage while managing risks.
ISO/IEC 38505-1:2017
ДействующийInformation technology — Governance of IT — Governance of data — Part 1: Application of ISO/IEC 38500 to the…
Overview ISO/IEC 38505-1:2017 - Information technology - Governance of IT - Governance of data (Part 1) is a high‑level, principles‑based ISO standard that applies the governance model of ISO/IEC 385…