LICENSEWARE

ISO/IEC 19770

This article is about the ISO/IEC 19770 family of international standards for IT asset management. For the disciplines themselves, see Software asset management and IT asset management.

On This Page

ISO/IEC 19770 is a family of international standards for IT asset management (ITAM), published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The standards are developed by Working Group 21 of Subcommittee 7 (software and systems engineering) of the joint technical committee ISO/IEC JTC 1.[1] The committee describes the family as addressing ITAM from two perspectives: a management system, specified in Part 1, and data structures that allow ITAM information to be exchanged between stakeholders.[1]

The family began as a standard for software asset management in 2006 and was retitled for IT asset management with the third edition of Part 1 in 2017, when its scope was widened to all types of IT asset.[2][4] Its data standards include software identification (SWID) tags, which are the subject of guidance from the US National Institute of Standards and Technology.[7][15]

History

Part 1 editions

Edition Reference Published Title Status (iso.org) 
1 ISO/IEC 19770-1:2006 2006-05 Software asset management, Part 1: Processes Withdrawn[2] 
2 ISO/IEC 19770-1:2012 2012-06 Software asset management, Part 1: Processes and tiered assessment of conformance Withdrawn[3] 
3 ISO/IEC 19770-1:2017 2017-12 IT asset management, Part 1: IT asset management systems: Requirements Published; confirmed 2024; Amendment 1:2024[4] 

The first edition (May 2006, 25 pages) was designed to let an organization prove that it performed SAM to a standard sufficient to satisfy corporate governance requirements and to support IT service management. It was intended to align closely to, and support, ISO/IEC 20000, the service management standard, and presented SAM as a means of managing business risk and controlling cost.[2]

The second edition (June 2012, 80 pages) established a baseline for an integrated set of SAM processes divided into tiers, so that organizations could implement, assess and be recognized for SAM incrementally. It applied to all software and related assets, executable and non-executable, and to all technological environments, stating that it was as relevant to virtualized applications, on-premises software and software as a service as to older environments.[3]

The third edition (December 2017, 37 pages) replaced the process model with requirements for an “IT asset management system” (ITAMS) within the context of the organization, applicable to all types of IT assets and all sizes of organization. It is written as a discipline-specific extension of ISO 55001:2014, the asset management system standard, adding requirements specific to IT assets; conformance to ISO/IEC 19770-1 does not imply conformance to ISO 55001.[4] The edition was last reviewed and confirmed in 2024, and an amendment on climate action changes was published in 2024.[4]

Data standards and supporting parts

The first data standard, ISO/IEC 19770-2 on software identification tags, was published in November 2009 under the “Software asset management” title and revised in October 2015 under the “IT asset management” title.[6][7] The entitlement schema (Part 3) followed in April 2016 and resource utilization measurement (Part 4) in September 2017.[8][9] The vocabulary (Part 5) was first published in 2013 and revised in 2015.[10] Later additions cover mapping of industry practices (Part 8, 2020), certification bodies (Part 11, 2021), hardware identification tags (Part 6, 2024) and implementation guidance (Technical Specification 19770-10, 2025).[12][14][11][13]

Scope and definitions

Parts of the family

The following parts are listed as published in the ISO catalogue as of 2026-09-26. Part numbers not listed (such as 7 and 9) were not found as published documents in the catalogue during research for this article.

Part Title (short) Current edition Published Catalogue status 
19770-1 IT asset management systems: Requirements Edition 3 2017-12 Published; confirmed 2024; Amd 1:2024[4] 
19770-2 Software identification tag Edition 2 2015-10 (corrected 2017-03) Published; under review[7] 
19770-3 Entitlement schema Edition 1 2016-04 Published; confirmed 2022[8] 
19770-4 Resource utilization measurement Edition 1 2017-09 Published; confirmed 2022[9] 
19770-5 Overview and vocabulary Edition 2 2015-08 Published; to be revised (ISO/IEC PRF 19770-5 under development)[10] 
19770-6 Hardware identification tag Edition 1 2024-01 Published[11] 
19770-8 Guidelines for mapping of industry practices to/from the ISO/IEC 19770 family Edition 1 2020-01 Published; confirmed 2026[12] 
TS 19770-10 Guidance for implementing ITAM Edition 1 2025-06 Published (Technical Specification)[13] 
19770-11 Requirements for bodies providing audit and certification of ITAM systems Edition 1 2021-06 Published; to be revised (ISO/IEC AWI 19770-11 under development)[14] 

Part 1: IT asset management systems

Part 1 specifies requirements for an IT asset management system. It can be applied to all IT asset types and, in whole or in part, to other asset types; it notes that its suitability for embedded software and firmware has not been determined, and that it is not intended for managing information as an asset in its own right. It does not specify financial, accounting or technical requirements for particular asset types. Internal and external parties can use it to assess an organization’s ability to meet its own ITAM requirements.[4]

The SC 7 committee describes the 2017 edition as a management system standard that follows the Plan-Do-Check-Act cycle, specifies 15 ITAM process areas, and suggests implementation in three tiers: Trustworthy Data, Life Cycle Integration and Optimization. It is designed to be aligned and integrated with other management system standards, such as ISO/IEC 27001 and ISO/IEC 20000-1.[5]

Part 2: Software identification tags

Part 2 specifies software identification (SWID) tags to optimize the identification and management of software. It distinguishes tag producers (platform providers, software providers and tag tool providers) from tag consumers (organizations that buy and use software, and providers of discovery and processing tools for security, compliance and logistics). It does not prescribe the ITAM processes needed to reconcile entitlements with tags.[7] The 2009 first edition had used a similar model of platform providers, software providers, tag providers, tag tool providers and software consumers.[6] The US National Institute of Standards and Technology published guidelines in 2016 for creating interoperable SWID tags based on the standard, covering uses in both software asset management and information security.[15]

Part 3: Entitlement schema

Part 3 establishes terms and definitions for software entitlements, which it treats as the subset of software licenses concerned with usage rights, and a transport format for encapsulating entitlements and their associated metrics. Its stated benefits include easier demonstration of proof of ownership, cost optimization and easier license compliance management, and it anticipates that a common entitlement structure may encourage industry normalization of entitlement names. It states that the original licensing documentation remains definitive for legal purposes and takes precedence over the entitlement encapsulation.[8] The relationship between entitlements and license metrics is described in software licensing models.

Part 4: Resource utilization measurement

Part 4 establishes an information structure for resource utilization measurement (RUM) data to facilitate ITAM. It applies to all types of organization.[9] Such data provides the measured usage against which capacity-based and consumption-based entitlements can be reconciled.

Part 5: Overview and vocabulary

Part 5 gives an overview of the family, an introduction to ITAM and SAM, a brief description of the foundation principles on which SAM is based, and consistent terms and definitions for the whole family.[10] The SC 7 committee described it in 2019 as the only freely available ITAM standard; the ISO catalogue lists it at no charge.[1][10]

Part 6: Hardware identification tags

Part 6 provides a transport format for hardware identification (HWID) tags, applying to hardware the approach that Part 2 takes for software. It deals only with the identification of hardware devices and components and leaves ITAM processes, software tags, entitlements and resource utilization to Parts 1 to 4.[11]

Part 8: Mapping of industry practices

Part 8 defines requirements, guidelines and formats for documents that map industry practices to or from the family. Its first edition covers mappings to the 2012 and 2017 editions of Part 1, with a deliberately general title in anticipation of mappings for other parts.[12]

Part 10: Implementation guidance

ISO/IEC TS 19770-10:2025 is a technical specification giving guidance for implementing ITAM. It covers management system processes not described in detail in Part 1, cross-cutting functional processes (change, data, license, security, relationship and contract, financial, service level and other risk management), and the life cycle processes of Part 1: specification, development, acquisition, release, deployment, operation and retirement.[13]

Part 11: Certification bodies

Part 11 sets requirements and guidance for bodies that audit and certify ITAM systems against Part 1, in addition to the general requirements of ISO/IEC 17021-1. It does not change the requirements of Part 1, and can also be used by accreditation bodies.[14]

How it is used

Organizations use the family in several ways:

  • As a management framework. Part 1 can be used to design an ITAM or SAM program and to assess it internally or externally, with third-party certification possible under the rules of Part 11.[4][14]
  • As a reference vocabulary. Part 5 supplies common terms, and is freely available.[10]
  • As data formats for tools. Parts 2, 3, 4 and 6 give software publishers, platform providers and tool vendors common structures for identification, entitlement and usage data, so that discovery and reconciliation can be automated.[7][8][9][11]
  • As a mapping target. Part 8 lets other frameworks be expressed in terms of Part 1.[12]

Public-sector guidance draws on the same concepts without always citing the standard. United States federal policy in 2016 called for tooling that automates hardware and software discovery, inventory normalization, and reconciliation of contracts, purchases and product use rights, capabilities that correspond to the processes and data the family standardizes.[17]

Standards and frameworks

The family relates to several other management system standards:

Standard Relationship 
ISO 55001:2014 (asset management systems) ISO/IEC 19770-1:2017 is a discipline-specific extension of it, with changes.[4] 
ISO/IEC 20000-1 (service management systems) The 2006 edition of Part 1 was designed to support ISO/IEC 20000; the 2017 edition is designed to integrate with ISO/IEC 20000-1.[2][5] ISO/IEC 20000-1:2018 specifies requirements for a service management system.[16] 
ISO/IEC 27001 (information security management systems) The committee cites it as the management system standard with which Part 1 was designed to be implemented jointly.[1] 
ISO/IEC 17021-1 (conformity assessment bodies) Part 11 adds ITAM-specific requirements to it for certification bodies.[14] 

Relationship to other disciplines

The family is the principal standards reference for software asset management and IT asset management. Its entitlement schema touches on software licenses and their metrics, but it does not define license terms: it defers to the licensing documentation as legally definitive.[8] NIST describes SWID tags as supporting applications in information security management as well as software asset management.[15]

Criticism and challenges

Access to the full text is a practical constraint: the ISO catalogue lists a purchase price for most parts, while Part 5 is the only part the SC 7 committee has described as freely available.[1][10] The data standards deliberately stop short of process: Part 2 does not prescribe the ITAM processes needed to reconcile entitlements with software identification tags, and Part 3 does not consider product activation mechanisms and states that it should not be implemented where it conflicts with an organization’s policies or national law and the conflict cannot be resolved.[7][8] The value of the tag and entitlement formats therefore depends on how widely publishers, platforms and tools implement them. Several parts are marked for revision in the ISO catalogue, including Part 5 and Part 11.[10][14]

Out of scope

This article summarizes the published catalogue information for each part; it does not reproduce the text of the standards, which are copyrighted. Draft parts are mentioned only where the ISO catalogue lists them. Vendor license terms, which the standards do not define, are covered in the vendor articles and in software licensing models.

References

  1. IT Asset Management Standards (ISO/IEC 19770) Business Case & OverviewISO/IEC JTC 1/SC 7 news item, 2019-04-24.Effective 2019-04-24. Retrieved 2026-09-26.
  2. ISO/IEC 19770-1:2006 Information technology: Software asset management, Part 1: ProcessesISO catalogue page. Edition 1, 2006-05; withdrawn.Effective 2006-05-01. Retrieved 2026-09-26.
  3. ISO/IEC 19770-1:2012 Information technology: Software asset management, Part 1: Processes and tiered assessment of conformanceISO catalogue page. Edition 2, 2012-06; withdrawn.Effective 2012-06-01. Retrieved 2026-09-26.
  4. ISO/IEC 19770-1:2017 Information technology: IT asset management, Part 1: IT asset management systems, RequirementsISO catalogue page. Edition 3, 2017-12; confirmed 2024; Amd 1:2024.Effective 2017-12-01. Retrieved 2026-09-26.
  5. ISO/IEC 19770-1:2017 (JTC 1/SC 7 flagship standards page)ISO/IEC JTC 1/SC 7 committee site.Retrieved 2026-09-26.
  6. ISO/IEC 19770-2:2009 Information technology: Software asset management, Part 2: Software identification tagISO catalogue page. Edition 1, 2009-11; withdrawn.Effective 2009-11-01. Retrieved 2026-09-26.
  7. ISO/IEC 19770-2:2015 Information technology: IT asset management, Part 2: Software identification tagISO catalogue page. Edition 2, 2015-10; corrected version 2017-03.Effective 2015-10-01. Retrieved 2026-09-26.
  8. ISO/IEC 19770-3:2016 Information technology: IT asset management, Part 3: Entitlement schemaISO catalogue page. Edition 1, 2016-04.Effective 2016-04-01. Retrieved 2026-09-26.
  9. ISO/IEC 19770-4:2017 Information technology: IT asset management, Part 4: Resource utilization measurementISO catalogue page. Edition 1, 2017-09.Effective 2017-09-01. Retrieved 2026-09-26.
  10. ISO/IEC 19770-5:2015 Information technology: IT asset management, Part 5: Overview and vocabularyISO catalogue page. Edition 2, 2015-08; to be revised.Effective 2015-08-01. Retrieved 2026-09-26.
  11. ISO/IEC 19770-6:2024 Information technology: IT asset management, Part 6: Hardware identification tagISO catalogue page. Edition 1, 2024-01.Effective 2024-01-01. Retrieved 2026-09-26.
  12. ISO/IEC 19770-8:2020 Information technology: IT asset management, Part 8: Guidelines for mapping of industry practices to/from the ISO/IEC 19770 family of standardsISO catalogue page. Edition 1, 2020-01; confirmed 2026.Effective 2020-01-01. Retrieved 2026-09-26.
  13. ISO/IEC TS 19770-10:2025 Information technology: IT asset management, Part 10: Guidance for implementing ITAMISO catalogue page. Technical Specification, Edition 1, 2025-06.Effective 2025-06-01. Retrieved 2026-09-26.
  14. ISO/IEC 19770-11:2021 Information technology: IT asset management, Part 11: Requirements for bodies providing audit and certification of IT asset management systemsISO catalogue page. Edition 1, 2021-06; to be revised.Effective 2021-06-01. Retrieved 2026-09-26.
  15. Guidelines for the Creation of Interoperable Software Identification (SWID) Tags (NIST IR 8060)NIST; April 2016.Effective 2016-04-01. Retrieved 2026-09-26.
  16. ISO/IEC 20000-1:2018 Information technology: Service management, Part 1: Service management system requirementsISO catalogue page. Edition 3, 2018-09.Effective 2018-09-01. Retrieved 2026-09-26.
  17. OMB M-16-12, Category Management Policy 16-1: Improving the Acquisition and Management of Common Information Technology: Software LicensingUS Office of Management and Budget memorandum, 2016-06-02.Effective 2016-06-02. Retrieved 2026-09-26.

See also

Esc