Information technology -- IT asset management

This document defines requirements, guidelines, formats and approaches for use when producing a mapping document that defines how industry practices map to/from the ISO/IEC 19770 series. This edition is focused solely on mappings to/from both the second edition of ISO/IEC 19770-1 that was published in 2012, or the third edition of ISO/IEC 19770-1 that was published in 2017. However, the title of this document is deliberately more general as it is expected that future editions of this document also include mapping frameworks related to other parts of the ISO/IEC 19770 series. In this document where reference is made to ISO/IEC 19770-1 without the specification of an edition number or a publication year, then the text applies to all editions of ISO/IEC 19770-1.

Technologies de l'information -- Gestion de biens de logiciel

General Information

Status
Published
Publication Date
05-Jan-2020
Current Stage
6060 - International Standard published
Start Date
03-Dec-2019
Completion Date
06-Jan-2020
Ref Project

Buy Standard

Standard
ISO/IEC 19770-8:2020 - Information technology -- IT asset management
English language
17 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (sample)

INTERNATIONAL ISO/IEC
STANDARD 19770-8
First edition
2020-01
Information technology — IT asset
management —
Part 8:
Guidelines for mapping of industry
practices to/from the ISO/IEC 19770
family of standards
Reference number
ISO/IEC 19770-8:2020(E)
ISO/IEC 2020
---------------------- Page: 1 ----------------------
ISO/IEC 19770-8:2020(E)
COPYRIGHT PROTECTED DOCUMENT
© ISO/IEC 2020

All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may

be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting

on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address

below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Fax: +41 22 749 09 47
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii © ISO/IEC 2020 – All rights reserved
---------------------- Page: 2 ----------------------
ISO/IEC 19770-8:2020(E)
Contents Page

Foreword ........................................................................................................................................................................................................................................iv

Introduction ..................................................................................................................................................................................................................................v

1 Scope ................................................................................................................................................................................................................................. 1

2 Normative references ...................................................................................................................................................................................... 1

3 Terms and definitions ..................................................................................................................................................................................... 1

4 Guidance for creating mappings .......................................................................................................................................................... 2

5 Mapping structure requirements ....................................................................................................................................................... 3

5.1 Overview ...................................................................................................................................................................................................... 3

5.2 Bi-directional mapping .................................................................................................................................................................... 3

5.3 Objective, description and structure of each source document ................................................................... 3

5.4 Background information about the source documents and their requirements ........................... 3

5.5 Electronic version of tables .......................................................................................................................................................... 4

5.6 High-level mapping ............................................................................................................................................................................. 4

5.7 Detailed mapping .................................................................................................................................................................................. 4

5.8 Required level of mapping detail ............................................................................................................................................ 4

Annex A (normative) Mapping templates to/from ISO/IEC 19770-1:2017 .................................................................6

Annex B (normative) Mapping templates to/from ISO/IEC 19770-1:2012 ................................................................. 9

Annex C (informative) Interactions with JTC 1/SC 7/WG 21 ....................................................................................................15

Bibliography .............................................................................................................................................................................................................................17

© ISO/IEC 2020 – All rights reserved iii
---------------------- Page: 3 ----------------------
ISO/IEC 19770-8:2020(E)
Foreword

ISO (the International Organization for Standardization) and IEC (the International Electrotechnical

Commission) form the specialized system for worldwide standardization. National bodies that

are members of ISO or IEC participate in the development of International Standards through

technical committees established by the respective organization to deal with particular fields of

technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other

international organizations, governmental and non-governmental, in liaison with ISO and IEC, also

take part in the work.

The procedures used to develop this document and those intended for its further maintenance are

described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for

the different types of document should be noted. This document was drafted in accordance with the

editorial rules of the ISO/IEC Directives, Part 2 (see www .iso .org/ directives).

Attention is drawn to the possibility that some of the elements of this document may be the subject

of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent

rights. Details of any patent rights identified during the development of the document will be in the

Introduction and/or on the ISO list of patent declarations received (see www .iso .org/ patents) or the IEC

list of patent declarations received (see http:// patents .iec .ch).

Any trade name used in this document is information given for the convenience of users and does not

constitute an endorsement.

For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and

expressions related to conformity assessment, as well as information about ISO's adherence to the

World Trade Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www .iso .org/

iso/ foreword .html.

This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,

Subcommittee SC 7, Software and systems engineering.
A list of all parts in the ISO/IEC 19770 series can be found on the ISO website.

Any feedback or questions on this document should be directed to the user’s national standards body. A

complete listing of these bodies can be found at www .iso .org/ members .html.
iv © ISO/IEC 2020 – All rights reserved
---------------------- Page: 4 ----------------------
ISO/IEC 19770-8:2020(E)
Introduction

This document defines formats and gives requirements and guidelines on the creation of documents

describing the relationships between ISO/IEC 19770-1 and industry practices. The documents are

referred to as “mapping documents” throughout the rest of this document.

The intention of this document is that the formats defined are applicable to a wide range of industry

practices, including both those published by standards bodies, industry organizations or software

publishers, and those defined in a unique manner within organizations.

The formats defined in this document support “bidirectional mappings”, where both the industry

practice can be mapped to ISO/IEC 19770-1, and ISO/IEC 19770-1 can be mapped to the industry

practice. It is expected that many mappings incorporate both aspects for clarity and convenience.

To the extent this document refers to ISO/IEC 19770-1:2012 it supports and builds on, the information

contained in Annex C of that standard. ISO/IEC 19770-1:2012, Annex C contains mapping information

to and from industry best practice guidance that referenced the following sources:

1) International Association of IT Asset Managers (IAITAM) Best Practice Library;

2) Two documents from the Association of SAM Assessment and Certification (SAMAC) based in Japan;

3) The Information Systems Audit and Control Association (ISACA) Control Objectives for Information

and Related Technology CobiT 4.1® framework, used with permission of ISACA/ITGI [www .isaca

.org] ©1996-2007 ITGI.

Having this information available no doubt simplifies the learning curve in the adoption of

ISO/IEC 19770-1 and enhances its visibility. However, experience with this information highlighted

several issues with distributing this information in an annex to ISO/IEC 19770-1, namely:

1) the authors of the source information release revisions and updates in a very different manner, and

on a very different schedule, from the update cycle of International Standards;

2) much of the source information is protected as Intellectual Property with copyright, trademarks

or sometimes even patents. Getting the permission to quote this information in an International

Standard is often tedious, time-consuming and difficult;

3) including references and URLs to external resources in an International Standard is at best

unstable, and at worst open to abuse.

This document seeks to ameliorate these issues by taking a different approach, by merely defining

formats, guidance and other resources for the creation of these “mappings documents”, and relying on

the authors of the source information or a related party to create the mappings documents themselves —

which then generally remain under their change control. The document also provides guidance on how

the originators and authors should interact with JTC 1/SC 7/WG 21 during this process if they choose

to do so — such an interaction is not mandatory for using the information in this document. However,

guidance on a number of optional styles of interaction is given, and such an interaction is encouraged.

© ISO/IEC 2020 – All rights reserved v
---------------------- Page: 5 ----------------------
INTERNATIONAL STANDARD ISO/IEC 19770-8:2020(E)
Information technology — IT asset management —
Part 8:
Guidelines for mapping of industry practices to/from the
ISO/IEC 19770 family of standards
1 Scope

This document defines requirements, guidelines, formats and approaches for use when producing a

mapping document that defines how industry practices map to/from the ISO/IEC 19770 series.

This edition is focused solely on mappings to/from both the second edition of ISO/IEC 19770-1 that was

published in 2012, or the third edition of ISO/IEC 19770-1 that was published in 2017. However, the title

of this document is deliberately more general as it is expected that future editions of this document also

include mapping frameworks related to other parts of the ISO/IEC 19770 series.

In this document where reference is made to ISO/IEC 19770-1 without the specification of an edition

number or a publication year, then the text applies to all editions of ISO/IEC 19770-1.

2 Normative references

The following documents are referred to in the text in such a way that some or all of their content

constitutes requirements of this document. For dated references, only the edition cited applies. For

undated references, the latest edition of the referenced document (including any amendments) applies.

ISO/IEC 19770-5, Information technology — IT asset management — Part 5: Overview and vocabulary

3 Terms and definitions

For the purposes of this document, the terms and definitions given in ISO/IEC 19770-5 and the

following apply.

ISO and IEC maintain terminological databases for use in standardization at the following addresses:

— ISO Online browsing platform: available at http:// www .iso .org/ obp
— IEC Electropedia: available at http:// www .electropedia .org/ org
3.1
mapping document
document that relates ISO/IEC 19770-1 and an existing industry practice

Note 1 to entry: The formats in this document support both mapping the industry practice to ISO/IEC 19770-1:2012

or ISO/IEC 19770-1:2017, and mapping ISO/IEC 19770-1:2012 or ISO/IEC 19770-1:2017 to the industry practice. It

is expected that many mappings incorporate both aspects for clarity and convenience.

3.2
source document
ISO/IEC 19770-1 or document defining an existing industry practice
© ISO/IEC 2020 – All rights reserved 1
---------------------- Page: 6 ----------------------
ISO/IEC 19770-8:2020(E)
4 Guidance for creating mappings

While each mapping is by definition created with a specific purpose in mind, the following is some

general guidance on creating a mapping to a specific industry practice:

1) Be clear about the scope to be addressed by the mapping, and document both the present scope and

how and by whom the mapping will be maintained.

2) Take an incremental approach to the creation of the mapping: begin with items that are the simplest

and/or most important for the organization involved, and items that are at the highest level and/or

provide immediate improvements. Aim to expand the scope over time.

3) Be clear about the high-level purpose of creating the mapping. The purpose can include the

following:

a) to aid in creating an optimized IT asset management scheme that for business reasons has to

follow other industry guidance as well as ISO/IEC 19770-1;

b) to serve as a basis for benchmarking an existing IT asset management scheme against other

schemes;

c) to highlight areas that may not be addressed by an existing asset management scheme and/or

industry best practice guidance that may be relevant to the goals of the organization;

d) to define a customized subset of ISO/IEC 19770-1 that is aligned with the existing industry

best practice guidance in order for the two documents together to serve as the basis for a new

asset management scheme that is customized to the needs of a specific organization or part of

an organization, or sector;

e) to document an existing management scheme based on the industry best practice for

communication with suppliers and/or customers using the terminology and definition with

which they may already have some familiarity;

f) to simplify the learning curve for the adoption of ISO/IEC 19770-1 with the industry and/or a

specific organization;

g) to provide a marketing advantage for the organization in relation to its peers.

4) Identify the goals of the industry best practice guidance that may be enhanced by the existence of

the mapping, such as:
a) IT governance, through simplified benchmarking;

b) risk management and quality management, through the use of tools designed to support

ISO/IEC 19770-1;

c) user training and education, through the use of existing materials based on ISO/IEC 19770-1.

5) Identify the uses to which the information generated by an existing management scheme aligned

with the industry best practice guidance may be enhanced by the existence of the mapping, such as:

a) activities invoking external parties such as license compliance audits;
b) financial and resource management;
c) service-level definition and management.

6) Provide support for the existing organizational and/or legal structures that support the industry

practice, such as:

a) networks of partner organizations that administer, implement, support or enforce the industry

practice;
2 © ISO/IEC 2020 – All rights reserved
---------------------- Page: 7 ----------------------
ISO/IEC 19770-8:2020(E)

b) training programmes and materials, and accreditation & certification schemes, related to the

industry practice.
5 Mapping structure requirements
5.1 Overview

It is assumed that the intended user of the mapping document (be they in the corporate world,

academia, or elsewhere) already has access to the original source documents being mapped (i.e. both

ISO/IEC 19770-1 and the industry practice). It is not the objective of the mapping document to substitute

for the need of the user to reference both source documents. Rather, the only objective of the mapping

document is to address the specific question of which elements in one source are mapped against which

elements in the other source.

In development of mapping in accordance with this document it could be desirable to interact with

the ISO/IEC Working Group which originated ISO/IEC 19770-1. Annex C provide guidelines for such

interactions.

The mapping document is a working tool for the user. As such it should be formatted and worded for the

maximum ease of use. Specific mapping requirements are provided in the following subclauses.

5.2 Bi-directional mapping

Many-to-many relationships are expected between the various elements of ISO/IEC 19770-1 and the

various elements of the industry practice. To maximize clarity and usefulness to the user, any mapping

of the industry practice against ISO/IEC 19770-1 should be bi-directional, i.e. include both of the

following components:

a) a full listing of all elements in ISO/IEC 19770-1 in their original order, and next to each element a

listing of those corresponding elements (one or more) in the industry practice;

b) a full listing of all elements in the industry practice in their original order, and next to each element

a listing of those corresponding elements (one or more) in ISO/IEC 19770-1.

Only the combination of the above two mappings may fully address the various use cases relevant to

the user.
5.3 Objective, description and structure of each source document

The mapping document shall include an overview of each of the mapped source documents, including

the objective, scope, approach and organization.
5.4 Background information about the source documents and their requirements
The following information shall be included in the mapping document:

a) information required of a software asset management scheme by ISO/IEC 19770-1, including the

scope, governance, tier supported, etc.;

b) information about the industry practice, including the governing body, version/edition, release

date, copyright information, release process for new/updated versions, applicable URLs, etc.

c) information about the organization/individual preparing the mapping, including the identification

of the governing body (if not an individual), relationship of the organization preparing the mapping

to any of the source documents, release date of the mapping, release process for future updates of

the mapping, applicable URLs, etc.

A list of other mappings available between each source document and other standards/industry

practices should be included where known. For example, if the mapping is against COBIT, the mapping

© ISO/IEC 2020 – All rights reserved 3
---------------------- Page: 8 ----------------------
ISO/IEC 19770-8:2020(E)

document shall list all the other standards and/or industry practices known to have a mapping to

COBIT available.
5.5 Electronic version of tables

All tables in this document shall also be made available in an editable electronic format and shall be

available through a publicly-accessible URL at http:// standards .iso .org/ iso -iec/ 19770/ -8/ ed -1.

5.6 High-level mapping

An overview of the main concepts in each source document shall be included and contrasted (as

applicable).

A discussion of each of the main sections/areas in each source document shall be included and

contrasted (as applicable).
See also the guidance in item 3) of Clau
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.