Who are we?

Who are we?

ISO/IEC JTC 1/SC 40/WG 1

 

ISO/IEC JTC 1/SC 40/WG 1 Governance of Information Technology was established in June 2013 to develop a set of documents providing information and guidance to the governing bodies on how to meet any obligation in the relationships between the organization, stakeholders and information technology.

What is the objective of Governance of IT?

The objective of governance of IT is to ensure presence of a system by which the current and future use of IT is directed and controlled.

The 38500-series of International Standards provide principles, definitions, and a model for good governance of IT, to assist those at the highest level of organizations to understand and fulfil their legal, regulatory and other stakeholder obligations in respect of their organizations' use of IT.

The 38500-series of International Standards is aligned with the definition of corporate governance that was published as a Report of the Committee on the Financial Aspects of Corporate Governance (the Cadbury Report) in 1992 and based on the foundation definition in the OECD Principles of Corporate Governance in 1999 (revised in 2004). Governance is distinct from management, and for the avoidance of confusion, the two concepts are defined in relation to information technology in 38500 and elaborated in 38502.

The purpose of the 38500-series of International Standards is to promote effective, efficient, and acceptable use of IT in all organizations by

  • assuring stakeholders that, if the principles and practices proposed by the standards are followed, they can have confidence in the organization's governance of IT,
  • informing and guiding governing bodies in governing the use of IT in their organization, and
  • establishing a vocabulary for governance of IT.

Why International Standards for good Governance of IT?  

The commercial breakthrough of technologies such as artificial intelligence and blockchain are examples that affects today’s business environment and strategies. Such technologies drive innovation investments with the purpose of creating outcome based value for the organization and stakeholders but also makes it necessary to change how the business is run and in terms of meeting increasing legal, regulatory and other stakeholder requirements. 

Changes in the global delivery models of IT products, services and data have raised concerns and expectations of stakeholders and society at large related to trustworthiness, security, privacy, safety and ethics. These conceptual changes are taking place across national borders and, therefore, requires a global consensus-based perspective and international understanding of what good governance of information technology should look like.