ISO/IEC TR 38504:2016
(Main)Governance of information technology - Guidance for principles-based standards in the governance of information technology
Governance of information technology - Guidance for principles-based standards in the governance of information technology
ISO/IEC TR 38504:2016 provides guidance on the information required to support principles-based standards in the area of governance and management of information technology. Guidance includes general recommendations, identification of elements and advice for their formulation. It does not describe the detail of specific principles or how they are aggregated into specific guidance to fulfil business objectives and achieve business outcomes from the use of IT.
Gouvernance des technologies de l'information — Lignes directrices pour des normes fondées sur des principes relatives à la gouvernance des technologies de l'information
General Information
- Status
- Published
- Publication Date
- 11-Sep-2016
- Technical Committee
- ISO/IEC JTC 1/SC 40 - IT service management and IT governance
- Drafting Committee
- ISO/IEC JTC 1/SC 40/WG 1 - Governance of InformationTechnology
- Current Stage
- 9093 - International Standard confirmed
- Start Date
- 25-Aug-2023
- Completion Date
- 30-Oct-2025
Overview
ISO/IEC TR 38504:2016 - "Governance of information technology - Guidance for principles-based standards in the governance of information technology" - is a technical report that provides guidance on the information needed to support principles-based standards for IT governance. It is non-prescriptive: it does not define specific principles or implementation techniques but describes the elements, format and rationale authors should include when developing or applying principles-based governance standards. The aim is to promote clarity, consistency and traceability between governance principles and desired business outcomes.
Key topics
- Purpose and scope: Guidance for principles-based governance standards applicable to organizations of all sizes and sectors.
- Principles-based approach: Emphasizes outcome-focused, non-prescriptive guidance that allows flexible implementation across different organizational structures.
- General recommendations: Standards should be readable by governing bodies and executives, anchored in accepted governance concepts (e.g., OECD), and align with the Evaluate‑Direct‑Monitor model in ISO/IEC 38500.
- Information elements for each principle: Recommended elements include:
- Name of the principle (short, 1–3 words)
- Statement of the principle
- Rationale explaining why the principle matters
- Relationships with other principles
- Implications for governance and management
- Desired outcomes tied to the principle
- Governance behaviours expected from leaders and managers
- Relationship to business outcomes: Guidance on articulating how governance behaviours, management behaviours, IT enablers and organizational factors can lead to strategic business outcomes, recognizing variability by organization.
Applications
- Standards developers and editors: Use this TR to design consistent, clear descriptions of governance principles when drafting standards or technical reports.
- Governance and IT practitioners: Apply the recommended information elements to interpret principles, align governance behaviours and assess governance effectiveness.
- Governing bodies and executives: Use the framework to evaluate IT governance decisions, policies and oversight roles without being constrained to specific processes.
- Policy authors and auditors: Leverage the structured principle descriptions to map governance expectations to organizational policies and measurement criteria.
Related standards
- ISO/IEC 38500 - Corporate governance of IT (principles and model such as Evaluate‑Direct‑Monitor)
- ISO/IEC TR 38502 and ISO/IEC TS 38501 - Complementary guidance and management system considerations
- Developed under ISO/IEC JTC 1/SC 40 (IT service management and IT governance)
By following ISO/IEC TR 38504:2016, organizations and standards writers can produce principles-based IT governance guidance that is clear, outcome-oriented and adaptable - improving alignment between governance principles and business results.
ISO/IEC TR 38504:2016 - Governance of information technology -- Guidance for principles-based standards in the governance of information technology
ISO/IEC TR 38504:2016 - Governance of information technology -- Guidance for principles-based standards in the governance of information technology
Frequently Asked Questions
ISO/IEC TR 38504:2016 is a technical report published by the International Organization for Standardization (ISO). Its full title is "Governance of information technology - Guidance for principles-based standards in the governance of information technology". This standard covers: ISO/IEC TR 38504:2016 provides guidance on the information required to support principles-based standards in the area of governance and management of information technology. Guidance includes general recommendations, identification of elements and advice for their formulation. It does not describe the detail of specific principles or how they are aggregated into specific guidance to fulfil business objectives and achieve business outcomes from the use of IT.
ISO/IEC TR 38504:2016 provides guidance on the information required to support principles-based standards in the area of governance and management of information technology. Guidance includes general recommendations, identification of elements and advice for their formulation. It does not describe the detail of specific principles or how they are aggregated into specific guidance to fulfil business objectives and achieve business outcomes from the use of IT.
ISO/IEC TR 38504:2016 is classified under the following ICS (International Classification for Standards) categories: 35.020 - Information technology (IT) in general. The ICS classification helps identify the subject area and facilitates finding related standards.
You can purchase ISO/IEC TR 38504:2016 directly from iTeh Standards. The document is available in PDF format and is delivered instantly after payment. Add the standard to your cart and complete the secure checkout process. iTeh Standards is an authorized distributor of ISO standards.
Standards Content (Sample)
TECHNICAL ISO/IEC TR
REPORT 38504
First edition
Governance of information
technology — Guidance for principles-
based standards in the governance of
information technology
Gouvernance des technologies de l’information — Lignes directrices
pour des normes fondées sur des principes relatives à la gouvernance
des technologies de l’information
PROOF/ÉPREUVE
Reference number
©
ISO/IEC 2016
© ISO/IEC 2016, Published in Switzerland
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form
or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior
written permission. Permission can be requested from either ISO at the address below or ISO’s member body in the country of
the requester.
ISO copyright office
Ch. de Blandonnet 8 • CP 401
CH-1214 Vernier, Geneva, Switzerland
Tel. +41 22 749 01 11
Fax +41 22 749 09 47
copyright@iso.org
www.iso.org
ii © ISO/IEC 2016 – All rights reserved
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Governance standards for information technology . 1
4.1 Purpose and focus of governance standards for information technology . 1
4.2 General recommendations for governance standards for information technology . 2
5 Principles-based guidance for governance of information technology .2
5.1 Use of principles-based standards . 2
5.2 System of governance . . 2
5.3 Set of principles . 2
5.4 Relationship between the adoption of principles and business outcomes. 2
6 Information required for each governance principle . 4
6.1 Information elements. 4
6.2 Name of the principle . 4
6.3 The statement of the principle . 4
6.4 Rationale for the principle . 5
6.5 Relationship with other principles . 5
6.6 Implications . 5
6.7 Desired outcomes . 5
6.8 Governance behaviours . 6
Bibliography . 8
© ISO/IEC 2016 – All rights reserved PROOF/ÉPREUVE iii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international
organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the
work. In the field of information technology, ISO and IEC have established a joint technical committee,
ISO/IEC JTC 1.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular the different approval criteria needed for
the different types of document should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject
of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent
rights. Details of any patent rights identified during the development of the document will be in the
Introduction and/or on the ISO list of patent declarations received (see www.iso.org/patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation on the meaning of ISO specific terms and expressions related to conformity assessment,
as well as information about ISO’s adherence to the World Trade Organization (WTO) principles in the
Technical Barriers to Trade (TBT) see the following URL: www.iso.org/iso/foreword.html.
The committee responsible for this document is ISO/IEC JTC 1, Information technology, SC 40, IT service
management and IT governance.
iv PROOF/ÉPREUVE © ISO/IEC 2016 – All rights reserved
Introduction
This document has been developed to give guidance on the information required to support principles-
based standards in the area of governance and management of information technology.
A principles-based approach to standardization is aimed at providing non-prescriptive guidance that is
applicable to all organizations, including public and private companies, government entities and not-for-
profit organizations of all sizes from the smallest to the largest, regardless of the extent of their use of IT.
The benefit of a principles-based standard is that it can identify the outcomes of applying the principles
without specifying explicit methodologies, structures, processes and techniques needed to achieve the
outcomes.
Within the International Standards arena, the definition of guidance in the area of governance of
information technology falls within the scope of ISO/IEC JTC 1/SC 40. The existing International
Standards in this area are ISO/IEC 38500, ISO/IEC TS 38501 and ISO/IEC TR 38502.
Experience with principles-based standards in the area of governance of IT has indicated that there
is a need to establish a common understanding of proposed principles and the expected outcomes of
applying the recommended principles as a basis for consensus. This requires a clear statement of the
rationale for the principles, the expected governance behaviours associated with the principle together
with the expected outcomes from their adoption.
In order for future standards and revisions of current standards to select the appropriate forms
of principle description and apply them in a consistent fashion, it is desired to develop a common
characterization of all of these forms of principle description. This document presents guidelines for the
general recommendations of principles-based governance standards and the description of principles
in terms of their format, content and level of prescription.
The intended audience for this document are the editors, working group members, reviewers and
other participants in the development of principles-based standards and technical reports as well
as governance of IT practitioners. An additional audience may be experts developing organizational
policies and standards. It is intended that they will select the elements suitable for their project from
those described in this document. It is further intended that, having selected the appropriate elements,
users of this document will apply them in a manner consistent with the guidance provided by this
document.
© ISO/IEC 2016 – All rights reserved PROOF/ÉPREUVE v
TECHNICAL REPORT ISO/IEC TR 38504:2016(E)
Governance of information technology — Guidance
for principles-based standards in the governance of
information technology
1 Scope
This document provides guidance on the information required to support principles-based standards
in the area of governance and management of information technology.
Guidance includes general recommendations, identification of elements and advice for their formulation.
It does not describe the detail of specific principles or how they are aggregated into specific guidance to
fulfil business objectives and achieve business outcomes from the use of IT.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 38500 and
ISO/IEC TR 38502 apply.
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
— IEC Electropedia: available at http://www.electropedia.org/
— ISO Online browsing platform: available at http://www.iso.org/obp
3.1
governance behaviour
actions of individuals and groups as part of an organization’s governance system
4 Governance standards for information technology
4.1 Purpose and focus of governance standards for information technology
A governance standard provides guidance on the system of directing and controlling for an organization
with respect to the business outcomes from the use of information technology.
Governance standards for IT may provide guidance on the role of the governing body within an
organization and its interactions with managers or what is required of a governance framework for IT
or all of these. Governance standards for information technology can either focus on all or part of the
use of information technology within an organization.
Guidance may include consideration of business strategy and IT strategy. It may also explore links
between governance behaviour, policy setting, management behaviour and business objectives and
outcomes.
The audience for such standards will include members of the governing body of organizations and the
executive managers responsible for high level oversight of the organizations.
© ISO/IEC 2016 – All rights reserved PROOF/ÉPREUVE 1
4.2 General recommendations for governance standards for information technology
Governance standards for information technology
a) should be anchored in accepted fundamental concepts of governance, such as those of the
Organisation for Economic Co-operation and Development (OECD), and describe governance of
information technology as a subset of organizational governance;
b) should be written in a way that is readable by the target audience including the governing body and
executive managers;
c) should clearly describe the domain that they address, particularly when they involve a subset of the
domain of information technology;
d) should be principles based;
e) should conform to the model for governance of IT using Evaluate-Direct-Monitor as described in
ISO/IEC 38500;
f) should distinguish between the responsibilities and accountabilities of the governing body and
those of managers as outlined in ISO/IEC TR 38502;
g) should be able to be applied on a consistent basis without prescribing particular organizational
structures or processes;
h) unless otherwise specified, should be applicable to all sizes and types of organization.
5 Principles-based guidance for governance of information technology
5.1 Use of principles-based standards
The benefit of a principles-based standard is that such a standard can identify the value and outcomes
...
TECHNICAL ISO/IEC TR
REPORT 38504
First edition
2016-09-15
Governance of information
technology — Guidance for principles-
based standards in the governance of
information technology
Gouvernance des technologies de l’information — Lignes directrices
pour des normes fondées sur des principes relatives à la gouvernance
des technologies de l’information
Reference number
©
ISO/IEC 2016
© ISO/IEC 2016, Published in Switzerland
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form
or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior
written permission. Permission can be requested from either ISO at the address below or ISO’s member body in the country of
the requester.
ISO copyright office
Ch. de Blandonnet 8 • CP 401
CH-1214 Vernier, Geneva, Switzerland
Tel. +41 22 749 01 11
Fax +41 22 749 09 47
copyright@iso.org
www.iso.org
ii © ISO/IEC 2016 – All rights reserved
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Governance standards for information technology . 1
4.1 Purpose and focus of governance standards for information technology . 1
4.2 General recommendations for governance standards for information technology . 2
5 Principles-based guidance for governance of information technology .2
5.1 Use of principles-based standards . 2
5.2 System of governance . . 2
5.3 Set of principles . 2
5.4 Relationship between the adoption of principles and business outcomes. 2
6 Information required for each governance principle . 4
6.1 Information elements. 4
6.2 Name of the principle . 4
6.3 The statement of the principle . 4
6.4 Rationale for the principle . 5
6.5 Relationship with other principles . 5
6.6 Implications . 5
6.7 Desired outcomes . 5
6.8 Governance behaviours . 6
Bibliography . 8
© ISO/IEC 2016 – All rights reserved iii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international
organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the
work. In the field of information technology, ISO and IEC have established a joint technical committee,
ISO/IEC JTC 1.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular the different approval criteria needed for
the different types of document should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject
of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent
rights. Details of any patent rights identified during the development of the document will be in the
Introduction and/or on the ISO list of patent declarations received (see www.iso.org/patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation on the meaning of ISO specific terms and expressions related to conformity assessment,
as well as information about ISO’s adherence to the World Trade Organization (WTO) principles in the
Technical Barriers to Trade (TBT) see the following URL: www.iso.org/iso/foreword.html.
The committee responsible for this document is ISO/IEC JTC 1, Information technology, SC 40, IT service
management and IT governance.
iv © ISO/IEC 2016 – All rights reserved
Introduction
This document has been developed to give guidance on the information required to support principles-
based standards in the area of governance and management of information technology.
A principles-based approach to standardization is aimed at providing non-prescriptive guidance that is
applicable to all organizations, including public and private companies, government entities and not-for-
profit organizations of all sizes from the smallest to the largest, regardless of the extent of their use of IT.
The benefit of a principles-based standard is that it can identify the outcomes of applying the principles
without specifying explicit methodologies, structures, processes and techniques needed to achieve the
outcomes.
Within the International Standards arena, the definition of guidance in the area of governance of
information technology falls within the scope of ISO/IEC JTC 1/SC 40. The existing International
Standards in this area are ISO/IEC 38500, ISO/IEC TS 38501 and ISO/IEC TR 38502.
Experience with principles-based standards in the area of governance of IT has indicated that there
is a need to establish a common understanding of proposed principles and the expected outcomes of
applying the recommended principles as a basis for consensus. This requires a clear statement of the
rationale for the principles, the expected governance behaviours associated with the principle together
with the expected outcomes from their adoption.
In order for future standards and revisions of current standards to select the appropriate forms
of principle description and apply them in a consistent fashion, it is desired to develop a common
characterization of all of these forms of principle description. This document presents guidelines for the
general recommendations of principles-based governance standards and the description of principles
in terms of their format, content and level of prescription.
The intended audience for this document are the editors, working group members, reviewers and
other participants in the development of principles-based standards and technical reports as well
as governance of IT practitioners. An additional audience may be experts developing organizational
policies and standards. It is intended that they will select the elements suitable for their project from
those described in this document. It is further intended that, having selected the appropriate elements,
users of this document will apply them in a manner consistent with the guidance provided by this
document.
© ISO/IEC 2016 – All rights reserved v
TECHNICAL REPORT ISO/IEC TR 38504:2016(E)
Governance of information technology — Guidance
for principles-based standards in the governance of
information technology
1 Scope
This document provides guidance on the information required to support principles-based standards
in the area of governance and management of information technology.
Guidance includes general recommendations, identification of elements and advice for their formulation.
It does not describe the detail of specific principles or how they are aggregated into specific guidance to
fulfil business objectives and achieve business outcomes from the use of IT.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 38500 and
ISO/IEC TR 38502 apply.
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
— IEC Electropedia: available at http://www.electropedia.org/
— ISO Online browsing platform: available at http://www.iso.org/obp
3.1
governance behaviour
actions of individuals and groups as part of an organization’s governance system
4 Governance standards for information technology
4.1 Purpose and focus of governance standards for information technology
A governance standard provides guidance on the system of directing and controlling for an organization
with respect to the business outcomes from the use of information technology.
Governance standards for IT may provide guidance on the role of the governing body within an
organization and its interactions with managers or what is required of a governance framework for IT
or all of these. Governance standards for information technology can either focus on all or part of the
use of information technology within an organization.
Guidance may include consideration of business strategy and IT strategy. It may also explore links
between governance behaviour, policy setting, management behaviour and business objectives and
outcomes.
The audience for such standards will include members of the governing body of organizations and the
executive managers responsible for high level oversight of the organizations.
© ISO/IEC 2016 – All rights reserved 1
4.2 General recommendations for governance standards for information technology
Governance standards for information technology
a) should be anchored in accepted fundamental concepts of governance, such as those of the
Organisation for Economic Co-operation and Development (OECD), and describe governance of
information technology as a subset of organizational governance;
b) should be written in a way that is readable by the target audience including the governing body and
executive managers;
c) should clearly describe the domain that they address, particularly when they involve a subset of the
domain of information technology;
d) should be principles based;
e) should conform to the model for governance of IT using Evaluate-Direct-Monitor as described in
ISO/IEC 38500;
f) should distinguish between the responsibilities and accountabilities of the governing body and
those of managers as outlined in ISO/IEC TR 38502;
g) should be able to be applied on a consistent basis without prescribing particular organizational
structures or processes;
h) unless otherwise specified, should be applicable to all sizes and types of organization.
5 Principles-based guidance for governance of information technology
5.1 Use of principles-based standards
The benefit of a principles-based standard is that such a standard can identif
...
ISO/IEC TR 38504:2016 is a document that provides guidance on the information needed to support principles-based standards in the governance and management of information technology. It offers general recommendations, identifies elements, and provides advice for their formulation. However, it does not go into the specifics of particular principles or how they are combined to achieve business objectives and outcomes in relation to the use of IT.
ISO/IEC TR 38504:2016 is a standard that offers guidance on the information needed to support principles-based standards in the governance and management of information technology. It provides general recommendations, identifies elements, and offers advice on their formulation. However, it does not provide detailed descriptions of specific principles or explain how they should be combined to meet business objectives and achieve desired outcomes with IT.
ISO/IEC TR 38504:2016은 정보 기술의 운영과 관리에서 원칙 기반 표준을 지원하기 위해 필요한 정보에 대한 지침을 제공합니다. 이 지침은 일반적인 권장 사항, 요소의 식별 및 이를 구성하기 위한 조언을 포함하고 있습니다. 그러나 특정 원칙의 세부 사항이나 이를 결합하여 사업 목표를 달성하고 IT를 통해 비즈니스 결과를 얻기 위한 구체적인 지침들에 대해서는 설명하지 않습니다.
기사 제목: ISO/IEC TR 38504:2016 - 정보기술의 지배에 대한 안내 - 정보기술 지배의 원칙 기반 표준에 대한 안내 기사 내용: ISO/IEC TR 38504:2016은 정보기술의 지배와 관리 분야에서 원칙 기반 표준을 지원하기 위해 필요한 정보에 대한 안내를 제공합니다. 이 안내에는 일반적인 권장사항, 원소의 식별 및 그들의 구성을 위한 조언이 포함되어 있습니다. 그러나 이 문서는 구체적인 원칙의 세부 내용이나 IT 사용을 통해 비즈니스 목표를 달성하고 비즈니스 결과를 얻기 위해 원칙이 어떻게 조합되는지를 설명하지 않습니다.
ISO/IEC TR 38504:2016は、情報技術のガバナンスと管理における原則ベースの標準をサポートするために必要な情報に関するガイドラインを提供します。このガイドラインには、一般的な推奨事項、要素の識別、およびその作り方に関するアドバイスが含まれています。ただし、具体的な原則の詳細やそれらをどのように組み合わせてビジネス目標を達成し、ITを利用してビジネスの成果を得るための具体的なガイダンスについては説明されていません。
記事タイトル:ISO/IEC TR 38504:2016 - 情報技術のガバナンスに関するガイダンス - 情報技術のガバナンスにおける原則ベースの標準へのガイダンス 記事内容:ISO/IEC TR 38504:2016は、情報技術のガバナンスと管理における原則ベースの標準を支援するための必要な情報についてのガイダンスを提供します。ガイダンスには一般的な推奨事項、要素の識別およびその形成に関するアドバイスが含まれます。ただし、具体的な原則の詳細やそれらがITの利用によってビジネス目標を達成しビジネス成果を得るためにどのように組み合わされるかについては説明されていません。














Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.
Loading comments...