ISO/IEC 20000-1:2018
The certifiable ISO/IEC service management system standard: context, leadership, planning including the service management plan, support including knowledge, and the operation of the SMS through the service portfolio, relationships and agreements, supply and demand, design, build and transition, resolution and fulfilment and service assurance, with performance evaluation, service reporting and improvement. Built from the held front matter, the clauses JIPDEC quotes, the ISO/IEC 20000-2 purpose statements the project editor reproduces and the harmonized text held in ISO/IEC 27001:2022; the body text is not held.
ISO/IEC 20000-1:2018 is a compliance framework from International (ISO/IEC JTC 1/SC 40); adopted nationally (JIS Q 20000-1, EN ISO/IEC 20000-1 and others) with 7 domains and 56 controls that map to 178 other frameworks. The largest domains are Clause 8: Operation of the service management system – ISO/IEC 20000-1:2018 (29 controls), Clause 7: Support of the service management system – ISO/IEC 20000-1:2018 (9 controls), Clause 4: Context of the organization – ISO/IEC 20000-1:2018 (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Clause 10: Improvement – ISO/IEC 20000-1:2018
| Code | Title |
|---|---|
| iso-iec-20000-1-2018::10.1 | 10.1 Nonconformity and corrective action |
| iso-iec-20000-1-2018::10.2 | 10.2 Continual improvement |
Clause 4: Context of the organization – ISO/IEC 20000-1:2018
| Code | Title |
|---|---|
| iso-iec-20000-1-2018::4.1 | 4.1 Understanding the organization and its context |
| iso-iec-20000-1-2018::4.2 | 4.2 Understanding the needs and expectations of interested parties |
| iso-iec-20000-1-2018::4.3 | 4.3 Determining the scope of the service management system |
| iso-iec-20000-1-2018::4.4 | 4.4 Service management system |
Clause 5: Leadership – ISO/IEC 20000-1:2018
| Code | Title |
|---|---|
| iso-iec-20000-1-2018::5.1 | 5.1 Leadership and commitment |
| iso-iec-20000-1-2018::5.2.1 | 5.2.1 Establish the service management policy |
| iso-iec-20000-1-2018::5.2.2 | 5.2.2 Communicate the service management policy |
| iso-iec-20000-1-2018::5.3 | 5.3 Organizational roles, responsibilities and authorities |
Clause 6: Planning – ISO/IEC 20000-1:2018
| Code | Title |
|---|---|
| iso-iec-20000-1-2018::6.1 | 6.1 Actions to address risks and opportunities |
| iso-iec-20000-1-2018::6.2.1 | 6.2.1 Establish objectives |
| iso-iec-20000-1-2018::6.2.2 | 6.2.2 Plan to achieve objectives |
| iso-iec-20000-1-2018::6.3 | 6.3 Plan the service management system |
Clause 7: Support of the service management system – ISO/IEC 20000-1:2018
| Code | Title |
|---|---|
| iso-iec-20000-1-2018::7.1 | 7.1 Resources |
| iso-iec-20000-1-2018::7.2 | 7.2 Competence |
| iso-iec-20000-1-2018::7.3 | 7.3 Awareness |
| iso-iec-20000-1-2018::7.4 | 7.4 Communication |
| iso-iec-20000-1-2018::7.5.1 | 7.5.1 Documented information: general |
| iso-iec-20000-1-2018::7.5.2 | 7.5.2 Creating and updating documented information |
| iso-iec-20000-1-2018::7.5.3 | 7.5.3 Control of documented information |
| iso-iec-20000-1-2018::7.5.4 | 7.5.4 Service management system documented information |
| iso-iec-20000-1-2018::7.6 | 7.6 Knowledge |
Clause 8: Operation of the service management system – ISO/IEC 20000-1:2018
| Code | Title |
|---|---|
| iso-iec-20000-1-2018::8.1 | 8.1 Operational planning and control |
| iso-iec-20000-1-2018::8.2.1 | 8.2.1 Service delivery |
| iso-iec-20000-1-2018::8.2.2 | 8.2.2 Plan the services |
| iso-iec-20000-1-2018::8.2.3 | 8.2.3 Control of parties involved in the service life cycle |
| iso-iec-20000-1-2018::8.2.4 | 8.2.4 Service catalogue management |
| iso-iec-20000-1-2018::8.2.5 | 8.2.5 Asset management |
| iso-iec-20000-1-2018::8.2.6 | 8.2.6 Configuration management |
| iso-iec-20000-1-2018::8.3.2 | 8.3.2 Business relationship management |
| iso-iec-20000-1-2018::8.3.3 | 8.3.3 Service level management |
| iso-iec-20000-1-2018::8.3.4.1 | 8.3.4.1 Management of external suppliers |
| iso-iec-20000-1-2018::8.3.4.2 | 8.3.4.2 Management of internal suppliers and customers acting as a supplier |
| iso-iec-20000-1-2018::8.4.1 | 8.4.1 Budgeting and accounting for services |
| iso-iec-20000-1-2018::8.4.2 | 8.4.2 Demand management |
| iso-iec-20000-1-2018::8.4.3 | 8.4.3 Capacity management |
| iso-iec-20000-1-2018::8.5.1.1 | 8.5.1.1 Change management policy |
| iso-iec-20000-1-2018::8.5.1.2 | 8.5.1.2 Change management initiation |
| iso-iec-20000-1-2018::8.5.1.3 | 8.5.1.3 Change management activities |
| iso-iec-20000-1-2018::8.5.2.1 | 8.5.2.1 Plan new or changed services |
| iso-iec-20000-1-2018::8.5.2.2 | 8.5.2.2 Design |
| iso-iec-20000-1-2018::8.5.2.3 | 8.5.2.3 Build and transition |
| iso-iec-20000-1-2018::8.5.3 | 8.5.3 Release and deployment management |
| iso-iec-20000-1-2018::8.6.1 | 8.6.1 Incident management |
| iso-iec-20000-1-2018::8.6.2 | 8.6.2 Service request management |
| iso-iec-20000-1-2018::8.6.3 | 8.6.3 Problem management |
| iso-iec-20000-1-2018::8.7.1 | 8.7.1 Service availability management |
| iso-iec-20000-1-2018::8.7.2 | 8.7.2 Service continuity management |
| iso-iec-20000-1-2018::8.7.3.1 | 8.7.3.1 Information security policy |
| iso-iec-20000-1-2018::8.7.3.2 | 8.7.3.2 Information security controls |
| iso-iec-20000-1-2018::8.7.3.3 | 8.7.3.3 Information security incidents |
Clause 9: Performance evaluation – ISO/IEC 20000-1:2018
| Code | Title |
|---|---|
| iso-iec-20000-1-2018::9.1 | 9.1 Monitoring, measurement, analysis and evaluation |
| iso-iec-20000-1-2018::9.2 | 9.2 Internal audit |
| iso-iec-20000-1-2018::9.3 | 9.3 Management review |
| iso-iec-20000-1-2018::9.4 | 9.4 Service reporting |
Your Compliance Coverage
If you comply with ISO/IEC 20000-1:2018, you already cover:
NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
6%
5 controls mapped
Compare →ITIL 4
6%
5 controls mapped
Compare →NIST Privacy Framework
5%
4 controls mapped
Compare →+ 175 more: MTCS (Singapore) (5%), Annex 11 to EU GMP - Computerised Systems (5%)
See all 178 mapped frameworks ↓Maps to 178 other frameworks
Coverage is not the same as your position
This page shows what ISO/IEC 20000-1:2018 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is ISO/IEC 20000-1:2018 and who does it apply to?
ISO/IEC 20000-1:2018 is a compliance framework from International (ISO/IEC JTC 1/SC 40); adopted nationally (JIS Q 20000-1, EN ISO/IEC 20000-1 and others) with 7 domains and 56 controls. The certifiable ISO/IEC service management system standard: context, leadership, planning including the service management plan, support including knowledge, and the operation of the SMS through the service portfolio, relationships and agreements, supply and demand, design, build and transition, resolution and fulfilment and service assurance, with performance evaluation, service reporting and improvement. Built from the held front matter, the clauses JIPDEC quotes, the ISO/IEC 20000-2 purpose statements the project editor reproduces and the harmonized text held in ISO/IEC 27001:2022; the body text is not held. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 20000-1:2018 actually require?
ISO/IEC 20000-1:2018 has 56 controls organised across 7 domains. The largest domains are Clause 8: Operation of the service management system – ISO/IEC 20000-1:2018 (29 controls), Clause 7: Support of the service management system – ISO/IEC 20000-1:2018 (9 controls), Clause 4: Context of the organization – ISO/IEC 20000-1:2018 (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 20000-1:2018 do I already cover?
ISO/IEC 20000-1:2018 maps to 178 other compliance frameworks. The top mapping partners are NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security (6% coverage), ITIL 4 (6% coverage), NIST Privacy Framework (5% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 20000-1:2018?
Start your ISO/IEC 20000-1:2018 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 20000-1:2018 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 56 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required