ISO 38500
From Wikipedia, the free encyclopedia
| This article is orphaned as few or no other articles link to it. Please help introduce links in articles on related topics. (June 2008) |
ISO/IEC 38500:2008 [1], Corporate governance of information technology, provides a framework for effective governance of IT to assist those at the highest level of organizations to understand and fulfill their legal, regulatory, and ethical obligations in respect of their organizations’ use of IT.
ISO/IEC 38500 is applicable to organizations from all sizes, including public and private companies, government entities, and not-for-profit organizations. This standard provides guiding principles for directors of organizations on the effective, efficient, and acceptable use of Information Technology (IT) within their organizations.
The framework comprises definitions, principles and a model. It sets out six principles for good corporate governance of IT:
- Responsibility;
- Strategy;
- Acquisition;
- Performance;
- Conformance;
- Human behaviour.
It also provides guidance to those advising, informing, or assisting directors.
| This article is uncategorized. Please categorize this article to list it with similar articles. (June 2008) |

