MI Solutions
Insights/Operating model and governance
Operating model and governance

ISO/IEC 19770 Explained: The International Standard for ITAM

What the ISO/IEC 19770 family of IT asset management standards covers, part by part, and how organizations use it without full certification.

By the MI Solutions SAM team9 min read2 exhibits

ISO/IEC 19770 is the family of international standards for IT asset management. It defines what a well-run ITAM system looks like and provides data standards that make software easier to identify and license. Few mid-sized organizations seek formal certification, but the standard is a useful reference for designing a program and a common language with auditors and partners.

The main parts

Exhibit 1
The ISO/IEC 19770 family at a glanceMain parts and what each covers1PART 1ITAM systemRequirements for an ITasset management system2PART 2SWID tagsStandard softwareidentification data3PART 3EntitlementsSchema for licenserights and limits4PART 5OverviewOverview and vocabularyof ITAM
01Part 1: IT asset management systems

Requirements for establishing, implementing, maintaining and improving an ITAM system, in the style of other ISO management system standards. The current edition dates from 2017.

02Part 2: Software identification tags

SWID tags: structured data that identifies installed software authoritatively, making recognition and normalization more reliable. See software normalization.

03Part 3: Entitlement schema

Terms and a format for describing software entitlements, such as license rights and limits, in a machine-readable way. See software entitlements.

04Part 5: Overview and vocabulary

An overview of the family and definitions of common terms.

What a management system means in practice

Part 1 is a management system standard. It does not prescribe a tool; it asks whether the organization has the elements that make ITAM work and keep improving:

  1. Context and scope

    Which assets, entities and locations the system covers, and why.

  2. Leadership and policy

    An approved policy, roles and accountability.

  3. Planning

    Objectives, risks and how they will be addressed.

  4. Support and operation

    Resources, competence, processes and records.

  5. Performance evaluation

    Measures, internal audit and management review.

  6. Improvement

    Corrective action and continual improvement.

How organizations use it

Exhibit 2
Most organizations use the standard as a reference, not forcertificationTypical uses of ISO/IEC 19770, ranked by how common they are among mid-sized organizations,illustrative012345Design reference forpolicy and roles5Shared vocabulary withpartners4Maturity benchmark4Data standard forrecognition (SWID)3Formal certification1Illustrative ranking, 1 (rare) to 5 (common).
01As a design reference

For policies, roles and processes.

02As a maturity benchmark

See SAM maturity model.

03As a shared vocabulary

With vendors, auditors and partners.

04For certification

In a smaller number of organizations where customers or regulators value it.

How MI One helps

Frequently asked questions

Do we need ISO 19770 certification?

Rarely, for mid-sized organizations. Using it as a reference is usually enough.

Is ISO 19770 only about software?

The family covers IT assets broadly, though much of it focuses on software.

Where can we get the standard?

The standards are published by ISO and national standards bodies, usually for a fee.


Sources

See where your software budget goes

Bring your five largest vendors to a 30-minute call. Our SAM experts will show you where the savings usually hide, and how fast MI One can surface them.