ISO/IEC 38500:2024
Principles for the governance of IT – ISO/IEC 38500:2024

ISO/IEC 38500:2024 5.3.2: Value generation: governance implications for use of IT

What the value generation principle means for the governance of IT: starting from value generation objectives that have been set and made known to the relevant stakeholders, the organization decides how IT will support and deliver its value generation model; technological developments are identified regularly and judged for their effect on that model, looking at opportunities as well as risks.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 18 controls across 8 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC TR 24028:2020 · 5 controls

  • 8.1 General: vulnerabilities, threats and challenges
  • 8.3.1 AI specific privacy threats: general
  • 9.11.1 Compliance
  • 9.3.1 Explainability: general
  • 9.4.1 Controllability: general

ISO/IEC 23894:2023 · 4 controls

COBIT 2019 · 3 controls

  • EDM02.01 EDM02.01 Establish the target investment mix
  • EDM02.02 EDM02.02 Evaluate value optimization
  • EDM02.03 EDM02.03 Direct value optimization

ISO/IEC 42001:2023 · 2 controls

  • 7.2 Competence
  • 9.2 Internal audit

BCBS 239 · 1 control

  • BCBS239-P1 Governance
  • CAT-D1-1 Governance

ISO 37001:2016 · 1 control

  • 5.1.1 5.1.1 Governing body

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Principles for the governance of IT – ISO/IEC 38500:2024

Query this from an agent

The graph holds this control, the 18 it maps to, and the evidence behind each claim, over MCP and REST.