ISO/IEC 38500:2024
Model for the governance of IT – ISO/IEC 38500:2024

ISO/IEC 38500:2024 6.3: Management of IT practice

Management achieves the objectives the governing body has set by taking decisions inside the limits the governing body has laid down: it carries out the use of IT within that direction, and its performance and conformance information flows back to the governing body's monitoring. Governance and management stay distinct; the governing body does not manage, and management does not take the governing body's decisions.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 13 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 55001:2014 · 2 controls

  • 8.2 Management of change
  • 9.3 Management review

ISO/IEC 42001:2023 · 2 controls

  • 4.4 AI management system
  • 9.3 Management review

COBIT 2019 · 1 control

  • APO01.03 APO01.03 Implement management processes (to support the achievement of governance and management objectives)

ISO 13485:2016 · 1 control

  • 5.6 Management review

ISO 14001:2015 · 1 control

  • 9.3 Management review

ISO 14004:2016 · 1 control

  • 9.3 Management review

ISO 22000:2018 · 1 control

  • 9.3 Management review

ISO 22301:2019 · 1 control

  • 9.3 Management review

ISO 37001:2016 · 1 control

  • 9.3 9.3 Management review

ISO 37301:2021 · 1 control

  • 9.3 Management review

ISO 45001:2018 · 1 control

  • 9.3 Management review

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Model for the governance of IT – ISO/IEC 38500:2024

Query this from an agent

The graph holds this control, the 13 it maps to, and the evidence behind each claim, over MCP and REST.