ISO/IEC 38500:2008
Subscribe to updates

Corporate governance of information technology

(Not available in French)

This standard has been revised by: ISO/IEC 38500:2015


ISO/IEC 38500:2008 provides guiding principles for directors of organizations (including owners, board members, directors, partners, senior executives, or similar) on the effective, efficient, and acceptable use of Information Technology (IT) within their organizations.

ISO/IEC 38500:2008 applies to the governance of management processes (and decisions) relating to the information and communication services used by an organization. These processes could be controlled by IT specialists within the organization or external service providers, or by business units within the organization.

It also provides guidance to those advising, informing, or assisting directors.

They include:

  • senior managers;
  • members of groups monitoring the resources within the organization;
  • external business or technical specialists, such as legal or accounting specialists, retail associations, or professional bodies;
  • vendors of hardware, software, communications and other IT products;
  • internal and external service providers (including consultants);
  • IT auditors.


  • Document published on: 2008-06
    Edition: 1 (Monolingual) ICS: 35.080
    Status: Withdrawn Stage: 95.99 (2015-02-11)
    TC/SC: ISO/IEC JTC 1 Number of Pages:
  • Revised by: ISO/IEC 38500:2015

  • No corrigenda or amendments available

Got a question?

Check out our FAQs

Email Customer Care
or call us on +41 22 749 08 88
09:00 – 12:00, 14:00 – 17:00 (UTC+1).