Overview
ISO/IEC TR 38502:2017 - "Information technology - Governance of IT - Framework and model" is a Technical Report that provides guidance on the nature, mechanisms and relationships between governance and management of IT. Rather than a prescriptive standard, it offers a framework and model to help organizations establish boundaries, accountabilities and decision-making structures for the current and future use of IT. The document is intended to inform governing bodies, managers, advisors and standards developers.
Key Topics
- Governance model: Clarifies the roles and accountabilities of the governing body and of management in the use of IT.
- Governance tasks: Recommends the governing body’s core tasks - Evaluate, Direct, Monitor - in alignment with business strategy and stakeholder expectations.
- Relationship between governance and management: Describes how governance sets direction and oversight while management implements and operates within delegated authority.
- Governance framework elements: Defines components such as strategies, policies, decision‑making structures and accountabilities through which governance operates.
- Delegation and accountability: Guidance on delegating authority to managers while retaining governance oversight.
- Internal control and management systems: Discusses the role of policies, procedures and structures to provide reasonable assurance that objectives will be achieved.
- Risk appetite: Provides terminology and context for setting the amount and type of risk the organization is willing to accept in IT decisions.
- Applicability: Notes applicability across organizations of all sizes and types, including public bodies and small enterprises.
Applications
- Designing or improving an IT governance framework that aligns IT investments with business strategy.
- Clarifying board and executive responsibilities for IT oversight, compliance and risk management.
- Establishing delegation models so managers can operate effectively within governance boundaries.
- Integrating governance considerations into internal control, IT strategy formulation and performance monitoring.
- Guiding advisors and consultants who help boards and executives implement governance of IT practices.
Who Should Use This Standard
- Governing bodies (boards, supervisory bodies) seeking structured oversight of IT.
- Senior managers and CIOs responsible for implementing IT strategy within delegated authority.
- Governance advisors and consultants working on IT governance, compliance or risk programs.
- Standards developers creating complementary guidance or conformance models in IT governance and management.
Related Standards
- ISO/IEC 38500 (Governance of IT for the organization) - referenced for terms and principles.
- ISO guidance on risk and management system concepts (e.g., ISO Guide 73, ISO 9000 family) - for related terminology and context.
Keywords: ISO/IEC TR 38502:2017, governance of IT, IT governance framework, governing body, IT strategy, internal control, risk appetite, delegation, management of IT.