• ISO/IEC 38505-1:2017

    Current The latest, up-to-date edition.

    Information technology — Governance of IT — Governance of data — Part 1: Application of ISO/IEC 38500 to the governance of data

    Available format(s):  Hardcopy, PDF, PDF 3 Users, PDF 5 Users, PDF 9 Users

    Language(s):  English

    Published date:  31-03-2017

    Publisher:  International Organization for Standardization

    Add To Cart

    Abstract - (Show below) - (Hide below)

    ISO/IEC 38505-1:2017 provides guiding principles for members of governing bodies of organizations (which can comprise owners, directors, partners, executive managers, or similar) on the effective, efficient, and acceptable use of data within their organizations by

    - applying the governance principles and model of ISO/IEC 38500 to the governance of data,

    - assuring stakeholders that, if the principles and practices proposed by this document are followed, they can have confidence in the organization's governance of data,

    - informing and guiding governing bodies in the use and protection of data in their organization, and

    - establishing a vocabulary for the governance of data.

    ISO/IEC 38505-1:2017 can also provide guidance to a wider community, including:

    - executive managers,

    - external businesses or technical specialists, such as legal or accounting specialists, retail or industrial associations, or professional bodies,

    - internal and external service providers (including consultants), and

    - auditors.

    While this document looks at the governance of data and its use within an organization, guidance on the implementation arrangement for the effective governance of IT in general is found in ISO/IEC/TS 38501. The constructs in ISO/IEC/TS 38501 can help to identify internal and external factors relating to the governance of IT and help to define beneficial outcomes and identify evidence of success.

    ISO/IEC 38505-1:2017 applies to the governance of the current and future use of data that is created, collected, stored or controlled by IT systems, and impacts the management processes and decisions relating to data.

    ISO/IEC 38505-1:2017 defines the governance of data as a subset or domain of the governance of IT, which itself is a subset or domain of organizational, or in the case of a corporation, corporate governance.

    ISO/IEC 38505-1:2017 is applicable to all organizations, including public and private companies, government entities, and not-for-profit organizations. This document is applicable to organizations of all sizes from the smallest to the largest, regardless of the extent of their dependence on data.

    General Product Information - (Show below) - (Hide below)

    Committee ISO/IEC JTC 1/SC 40
    Document Type Standard
    Publisher International Organization for Standardization
    Status Current

    Standards Referenced By This Book - (Show below) - (Hide below)

    BS ISO/IEC 19944:2017 Information technology. Cloud computing. Cloud services and devices: Data flow, data categories and data use
    ISO/IEC 19944:2017 Information technology Cloud computing Cloud services and devices: Data flow, data categories and data use
    ISO/IEC TR 38505-2:2018 Information technology — Governance of IT — Governance of data — Part 2: Implications of ISO/IEC 38505-1 for data management
    16/30313038 DC : 0 BS ISO/IEC 19944 - INFORMATION TECHNOLOGY - CLOUD COMPUTING - CLOUD SERVICES AND DEVICES: DATA FLOW, DATA CATEGORIES AND DATA USE

    Standards Referencing This Book - (Show below) - (Hide below)

    ISO/IEC 27017:2015 Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services
    ISO/IEC 38500:2015 Information technology — Governance of IT for the organization
    ISO 31000:2009 Risk management Principles and guidelines
    ISO/IEC TR 38502:2014 Information technology Governance of IT Framework and model
    ISO/IEC 27002:2013 Information technology Security techniques Code of practice for information security controls
    ISO/IEC 27018:2014 Information technology Security techniques Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors
    SA/SNZ TR ISO/IEC 38505.2:2019 Information technology - Governance of IT - Governance of data Implications of ISO/IEC 38505-1 for data management
    ISO/IEC TS 38501:2015 Information technology — Governance of IT — Implementation guide
    ISO/TR 31004:2013 Risk management — Guidance for the implementation of ISO 31000
    ISO/IEC 27000:2016 Information technology Security techniques Information security management systems Overview and vocabulary
    ISO/IEC 17788:2014 Information technology — Cloud computing — Overview and vocabulary
    ISO/IEC 29100:2011 Information technology — Security techniques — Privacy framework
    • Access your standards online with a subscription

      Features

      • Simple online access to standards, technical information and regulations
      • Critical updates of standards and customisable alerts and notifications
      • Multi - user online standards collection: secure, flexibile and cost effective