38500:2024 revision announcement

By Steve Tremblay on

ISO/IEC 38500:2024
Information Technology — Governance of IT for the Organization

Governance of information technology (IT) continues to be a significant issue for governing bodies and senior management.

The advent of digital ecosystems has transformed how organizations interact with customers and suppliers, offering both engagement mechanisms and channels for expressing dissatisfaction. The evolving landscape of information technology (IT) has fundamentally altered the operational models of organizations, allowing innovative approaches to service delivery.

While some entities have thrived in this digital environment, others have been challenged.

  • Organizations must adapt to remain competitive as digital technology advances, including cloud-based services and technologies like Artificial Intelligence and Blockchains. However, the organizational changes required to capitalize on digital opportunities are intricate and prone to failure;
  • Many struggle to address the demands, lacking flexibility due to outdated technology solutions. Inadequate investment and a lack of understanding of actual costs further impede technology adaptation, jeopardizing efficiency and long-term viability.
  • The increasing availability of data has offered increased opportunities. However, the vulnerability to system failures and data breaches poses risks such as reputational damage and regulatory non-compliance.

 

ISO/IEC 38500:2024 addresses the critical role of information technology (IT) in organizational success, emphasizing its transformative power and ability to shape new business models.   Aligned with the principles outlined in ISO 37000 Governance of Organizations - Guidance, it provides a model and framework for effective performance; responsible stewardship and ethical behaviour can be delivered. 

 

 

 

 

Trish Kenyon, chair of the SO/IEC JTC 1/SC 40, the committee responsible for IT service management and IT governance, comments: "The application of the principle and model in ISO/IEC 38500 will assist governing bodies to engage strategically and exercise proper oversight to ensure the organization's resilience and success in the ever-changing digital landscape. The alignment of ISO/IEC 38500 with ISO 37000 will increase the recognition that Governance of IT is an integral element of organizational governance".

ISO/IEC 38500 is the cornerstone of the Governance of IT standards family, based on the model and principles outlined in ISO/IEC 38500:2015. 

ISO/IEC 38500:2024 complements other governance codes and principles for effective governance. It serves as a standalone guide or a tool for upgrading existing governance based on the previous version of ISO/IEC 38500. While primarily directed at governing bodies, the document acknowledges the pervasive nature of governance throughout the organization. It guides IT governance practices across all levels and encourages interaction and collaboration among personnel, regardless of their roles.  

A plan for progressive revision of other standards is now underway, with first priority being given to ISO/IEC 38501 Governance of IT Implementation Guide and   ISO/IEC 38505-1 Governance of Data.

Steve Tremblay, Convenor, Working Group 1, Governance of IT noted, "The revision of ISO/IEC 38500 offers the opportunity for a necessary refresh of the ISO/IEC 38500 family of standards. This will be undertaken through a consensus process involving experts nominated by national bodies and organizations in liaison with SC40. This enables the revised standards to reflect best practices. If you are interested, we would encourage your involvement."