In the modern corporate landscape, data is often described as the "new oil." However, unlike oil, data is intangible, fluid, and incredibly difficult to govern. While most organizations have heard of ISO 27001 (Information Security) or ISO 27701 (Privacy), there is a critical standard that often flies under the radar: ISO 38505.
Official versions of these standards are copyrighted and must typically be purchased through recognized national or international standards bodies. You can find official copies at: ISO Official Site ISO/IEC 38505-1 ISO/IEC TS 38505-3 BSI Knowledge BS ISO/IEC 38505-1 ANSI Webstore Standard Previews iso 38505 pdf
Value: Identifies the business worth of the data to prioritize protection resources. Unlocking Data Governance: A Deep Dive into ISO
The standard is built upon six core principles that guide the governing body’s decision-making process: Responsibility – Assign accountability for data
. It extends the general IT governance principles of ISO/IEC 38500 to specifically address data as a strategic organizational asset. Sogeti Labs Core Standard Components
The standard provides a framework for the governance of IT-enabled investment, which includes:
ISO’s public scope for ISO/IEC 38505-1 outlines: