ISO/IEC 19770 is a family of international standards for IT asset management (ITAM), published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The standards are developed by Working Group 21 of Subcommittee 7 (software and systems engineering) of the joint technical committee ISO/IEC JTC 1.[1] The committee describes the family as addressing ITAM from two perspectives: a management system, specified in Part 1, and data structures that allow ITAM information to be exchanged between stakeholders.[1]
The family began as a standard for software asset management in 2006 and was retitled for IT asset management with the third edition of Part 1 in 2017, when its scope was widened to all types of IT asset.[2][4] Its data standards include software identification (SWID) tags, which are the subject of guidance from the US National Institute of Standards and Technology.[7][15]
History
Part 1 editions
| Edition | Reference | Published | Title | Status (iso.org) |
|---|---|---|---|---|
| 1 | ISO/IEC 19770-1:2006 | 2006-05 | Software asset management, Part 1: Processes | Withdrawn[2] |
| 2 | ISO/IEC 19770-1:2012 | 2012-06 | Software asset management, Part 1: Processes and tiered assessment of conformance | Withdrawn[3] |
| 3 | ISO/IEC 19770-1:2017 | 2017-12 | IT asset management, Part 1: IT asset management systems: Requirements | Published; confirmed 2024; Amendment 1:2024[4] |
The first edition (May 2006, 25 pages) was designed to let an organization prove that it performed SAM to a standard sufficient to satisfy corporate governance requirements and to support IT service management. It was intended to align closely to, and support, ISO/IEC 20000, the service management standard, and presented SAM as a means of managing business risk and controlling cost.[2]
The second edition (June 2012, 80 pages) established a baseline for an integrated set of SAM processes divided into tiers, so that organizations could implement, assess and be recognized for SAM incrementally. It applied to all software and related assets, executable and non-executable, and to all technological environments, stating that it was as relevant to virtualized applications, on-premises software and software as a service as to older environments.[3]
The third edition (December 2017, 37 pages) replaced the process model with requirements for an “IT asset management system” (ITAMS) within the context of the organization, applicable to all types of IT assets and all sizes of organization. It is written as a discipline-specific extension of ISO 55001:2014, the asset management system standard, adding requirements specific to IT assets; conformance to ISO/IEC 19770-1 does not imply conformance to ISO 55001.[4] The edition was last reviewed and confirmed in 2024, and an amendment on climate action changes was published in 2024.[4]
Data standards and supporting parts
The first data standard, ISO/IEC 19770-2 on software identification tags, was published in November 2009 under the “Software asset management” title and revised in October 2015 under the “IT asset management” title.[6][7] The entitlement schema (Part 3) followed in April 2016 and resource utilization measurement (Part 4) in September 2017.[8][9] The vocabulary (Part 5) was first published in 2013 and revised in 2015.[10] Later additions cover mapping of industry practices (Part 8, 2020), certification bodies (Part 11, 2021), hardware identification tags (Part 6, 2024) and implementation guidance (Technical Specification 19770-10, 2025).[12][14][11][13]
Scope and definitions
Parts of the family
The following parts are listed as published in the ISO catalogue as of 2026-09-26. Part numbers not listed (such as 7 and 9) were not found as published documents in the catalogue during research for this article.
| Part | Title (short) | Current edition | Published | Catalogue status |
|---|---|---|---|---|
| 19770-1 | IT asset management systems: Requirements | Edition 3 | 2017-12 | Published; confirmed 2024; Amd 1:2024[4] |
| 19770-2 | Software identification tag | Edition 2 | 2015-10 (corrected 2017-03) | Published; under review[7] |
| 19770-3 | Entitlement schema | Edition 1 | 2016-04 | Published; confirmed 2022[8] |
| 19770-4 | Resource utilization measurement | Edition 1 | 2017-09 | Published; confirmed 2022[9] |
| 19770-5 | Overview and vocabulary | Edition 2 | 2015-08 | Published; to be revised (ISO/IEC PRF 19770-5 under development)[10] |
| 19770-6 | Hardware identification tag | Edition 1 | 2024-01 | Published[11] |
| 19770-8 | Guidelines for mapping of industry practices to/from the ISO/IEC 19770 family | Edition 1 | 2020-01 | Published; confirmed 2026[12] |
| TS 19770-10 | Guidance for implementing ITAM | Edition 1 | 2025-06 | Published (Technical Specification)[13] |
| 19770-11 | Requirements for bodies providing audit and certification of ITAM systems | Edition 1 | 2021-06 | Published; to be revised (ISO/IEC AWI 19770-11 under development)[14] |
Part 1: IT asset management systems
Part 1 specifies requirements for an IT asset management system. It can be applied to all IT asset types and, in whole or in part, to other asset types; it notes that its suitability for embedded software and firmware has not been determined, and that it is not intended for managing information as an asset in its own right. It does not specify financial, accounting or technical requirements for particular asset types. Internal and external parties can use it to assess an organization’s ability to meet its own ITAM requirements.[4]
The SC 7 committee describes the 2017 edition as a management system standard that follows the Plan-Do-Check-Act cycle, specifies 15 ITAM process areas, and suggests implementation in three tiers: Trustworthy Data, Life Cycle Integration and Optimization. It is designed to be aligned and integrated with other management system standards, such as ISO/IEC 27001 and ISO/IEC 20000-1.[5]
Part 2: Software identification tags
Part 2 specifies software identification (SWID) tags to optimize the identification and management of software. It distinguishes tag producers (platform providers, software providers and tag tool providers) from tag consumers (organizations that buy and use software, and providers of discovery and processing tools for security, compliance and logistics). It does not prescribe the ITAM processes needed to reconcile entitlements with tags.[7] The 2009 first edition had used a similar model of platform providers, software providers, tag providers, tag tool providers and software consumers.[6] The US National Institute of Standards and Technology published guidelines in 2016 for creating interoperable SWID tags based on the standard, covering uses in both software asset management and information security.[15]
Part 3: Entitlement schema
Part 3 establishes terms and definitions for software entitlements, which it treats as the subset of software licenses concerned with usage rights, and a transport format for encapsulating entitlements and their associated metrics. Its stated benefits include easier demonstration of proof of ownership, cost optimization and easier license compliance management, and it anticipates that a common entitlement structure may encourage industry normalization of entitlement names. It states that the original licensing documentation remains definitive for legal purposes and takes precedence over the entitlement encapsulation.[8] The relationship between entitlements and license metrics is described in software licensing models.
Part 4: Resource utilization measurement
Part 4 establishes an information structure for resource utilization measurement (RUM) data to facilitate ITAM. It applies to all types of organization.[9] Such data provides the measured usage against which capacity-based and consumption-based entitlements can be reconciled.
Part 5: Overview and vocabulary
Part 5 gives an overview of the family, an introduction to ITAM and SAM, a brief description of the foundation principles on which SAM is based, and consistent terms and definitions for the whole family.[10] The SC 7 committee described it in 2019 as the only freely available ITAM standard; the ISO catalogue lists it at no charge.[1][10]
Part 6: Hardware identification tags
Part 6 provides a transport format for hardware identification (HWID) tags, applying to hardware the approach that Part 2 takes for software. It deals only with the identification of hardware devices and components and leaves ITAM processes, software tags, entitlements and resource utilization to Parts 1 to 4.[11]
Part 8: Mapping of industry practices
Part 8 defines requirements, guidelines and formats for documents that map industry practices to or from the family. Its first edition covers mappings to the 2012 and 2017 editions of Part 1, with a deliberately general title in anticipation of mappings for other parts.[12]
Part 10: Implementation guidance
ISO/IEC TS 19770-10:2025 is a technical specification giving guidance for implementing ITAM. It covers management system processes not described in detail in Part 1, cross-cutting functional processes (change, data, license, security, relationship and contract, financial, service level and other risk management), and the life cycle processes of Part 1: specification, development, acquisition, release, deployment, operation and retirement.[13]
Part 11: Certification bodies
Part 11 sets requirements and guidance for bodies that audit and certify ITAM systems against Part 1, in addition to the general requirements of ISO/IEC 17021-1. It does not change the requirements of Part 1, and can also be used by accreditation bodies.[14]
How it is used
Organizations use the family in several ways:
- As a management framework. Part 1 can be used to design an ITAM or SAM program and to assess it internally or externally, with third-party certification possible under the rules of Part 11.[4][14]
- As a reference vocabulary. Part 5 supplies common terms, and is freely available.[10]
- As data formats for tools. Parts 2, 3, 4 and 6 give software publishers, platform providers and tool vendors common structures for identification, entitlement and usage data, so that discovery and reconciliation can be automated.[7][8][9][11]
- As a mapping target. Part 8 lets other frameworks be expressed in terms of Part 1.[12]
Public-sector guidance draws on the same concepts without always citing the standard. United States federal policy in 2016 called for tooling that automates hardware and software discovery, inventory normalization, and reconciliation of contracts, purchases and product use rights, capabilities that correspond to the processes and data the family standardizes.[17]
Standards and frameworks
The family relates to several other management system standards:
| Standard | Relationship |
|---|---|
| ISO 55001:2014 (asset management systems) | ISO/IEC 19770-1:2017 is a discipline-specific extension of it, with changes.[4] |
| ISO/IEC 20000-1 (service management systems) | The 2006 edition of Part 1 was designed to support ISO/IEC 20000; the 2017 edition is designed to integrate with ISO/IEC 20000-1.[2][5] ISO/IEC 20000-1:2018 specifies requirements for a service management system.[16] |
| ISO/IEC 27001 (information security management systems) | The committee cites it as the management system standard with which Part 1 was designed to be implemented jointly.[1] |
| ISO/IEC 17021-1 (conformity assessment bodies) | Part 11 adds ITAM-specific requirements to it for certification bodies.[14] |
Relationship to other disciplines
The family is the principal standards reference for software asset management and IT asset management. Its entitlement schema touches on software licenses and their metrics, but it does not define license terms: it defers to the licensing documentation as legally definitive.[8] NIST describes SWID tags as supporting applications in information security management as well as software asset management.[15]
Criticism and challenges
Access to the full text is a practical constraint: the ISO catalogue lists a purchase price for most parts, while Part 5 is the only part the SC 7 committee has described as freely available.[1][10] The data standards deliberately stop short of process: Part 2 does not prescribe the ITAM processes needed to reconcile entitlements with software identification tags, and Part 3 does not consider product activation mechanisms and states that it should not be implemented where it conflicts with an organization’s policies or national law and the conflict cannot be resolved.[7][8] The value of the tag and entitlement formats therefore depends on how widely publishers, platforms and tools implement them. Several parts are marked for revision in the ISO catalogue, including Part 5 and Part 11.[10][14]
Out of scope
This article summarizes the published catalogue information for each part; it does not reproduce the text of the standards, which are copyrighted. Draft parts are mentioned only where the ISO catalogue lists them. Vendor license terms, which the standards do not define, are covered in the vendor articles and in software licensing models.