IT Governance
DETAIL

ISO/IEC 19770-1:2017 – Information technology – IT asset management – Part 1: IT asset management systems – Requirements

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

ISO/IEC 19770-1:2017 specifies the requirements for the establishment, implementation, maintenance, and improvement of a management system for IT asset management (ITAM), referred to as an IT asset management system (ITAMS). It is a discipline-specific extension of ISO 55001:2014, the asset management system standard, adding the controls that IT assets and especially software require: control over software modification, duplication, and distribution, audit trails of authorizations and changes, licensing compliance, mixed ownership in cloud and bring-your-own-device settings, and reconciliation with financial systems.

The third edition was published in December 2017 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), prepared by ISO/IEC JTC 1/SC 7 with contributions from SC 27 (IT security), SC 40 (IT service management and governance), and ISO/TC 251 (asset management). It cancels and replaces the 2012 second edition, which it technically revised into a management system standard using the harmonized structure shared with ISO/IEC 27001 and ISO/IEC 20000-1, and it is voluntary and certifiable. Amendment 1:2024 adds the climate action wording common to ISO management system standards.

Organizations implement it by defining the scope of the ITAMS and the IT assets it covers, setting ITAM policy, objectives, and roles, assessing and treating IT asset risks, and operating the process areas in Annex A. Annex B groups process objectives into three optional tiers, trustworthy data, life cycle integration, and optimization, so that organizations can build the system in stages and be assessed against a defined tier.

Why it Matters

Software licensing exposure, unmanaged cloud subscriptions, and unknown hardware are among the most common sources of cost overruns and security gaps in IT. ISO/IEC 19770-1:2017 gives organizations a certifiable management system for IT assets that starts with trustworthy data and integrates with the ISO management systems they already run.

Key benefits include:

  • Control license and subscription cost

Requirements for entitlement records, reconciliation, and controls over duplication and distribution reduce under-licensing penalties and over-licensing waste.

  • Improve security through asset knowledge

Accurate, current IT asset data supports vulnerability management, patching, and the asset controls in ISO/IEC 27001 and ISO/IEC 27002.

  • Integrate with other management systems

The harmonized structure lets the ITAMS share context, leadership, planning, support, and improvement clauses with ISO/IEC 27001, ISO/IEC 20000-1, and ISO 9001.

  • Implement in stages

Three tiers, trustworthy data, life cycle integration, and optimization, give a defined path from basic inventory to optimized asset value.

  • Demonstrate conformance

Organizations can be assessed and certified against the standard, giving customers, auditors, and software publishers assurance of licensing compliance.

How it Works

ISO/IEC 19770-1:2017 follows the harmonized management system structure. Clause 1 gives the purpose, field of application, and limitations, Clauses 2 and 3 the normative references and terms, and Clauses 4 to 10 the requirements: context of the organization and ITAMS scope, leadership and policy, planning including IT asset risk assessment and treatment and ITAM objectives, support, operation, performance evaluation, and improvement. Annex A specifies the ITAM process areas, Annex B describes the optional tiers, and Annex C explains the characteristics of IT assets that drive the additional requirements beyond ISO 55001.

Implementation typically begins with a scope statement covering the asset types, locations, and organizational units in the ITAMS, followed by ITAM policy, roles, and objectives approved by leadership. Teams then build trustworthy data through discovery, inventory, and entitlement reconciliation, define processes for each Annex A area such as acquisition, deployment, license management, and disposal, assess and treat IT asset risks, measure performance, run internal audits and management review, and correct nonconformities, before seeking certification by an accredited body.

Within SmartSuite, teams hold the Clause 4 to 10 requirements and the Annex A process areas as a control library, keep the IT asset register, entitlements, and reconciliations as linked records, and run risk treatment, internal audits, and corrective actions with owners and due dates. Dashboards show tier progress, license position, and audit readiness for management review and certification.

Key Elements

  • Context and scope of the ITAMS

Determination of internal and external issues, stakeholder needs, and the IT assets, locations, and units the system covers.

  • Leadership, policy, and roles

Top management commitment, an ITAM policy, and defined responsibilities and authorities for IT asset management.

  • Planning and IT asset risk

IT asset risk assessment and treatment, ITAM objectives, operation process specifications, and plans to achieve them.

  • IT-specific controls beyond ISO 55001

Controls over software modification, duplication, and distribution, audit trails, licensing compliance, mixed ownership such as cloud and BYOD, and reconciliation with financial systems.

  • Support, operation, evaluation, and improvement

Resources, competence, awareness, communication, documented information, operational control, monitoring, internal audit, management review, and corrective action.

  • Annex A process areas

The ITAM process areas the organization is expected to operate, from acquisition through deployment, management, and retirement.

  • Annex B tiers

Optional groupings of process objectives into trustworthy data, life cycle integration, and optimization for staged implementation and assessment.

Framework Scope

ISO/IEC 19770-1:2017 applies to all types of IT assets, including hardware, executable software such as applications and operating systems, and non-executable software such as fonts and configuration information, across all technological environments from on-premises to virtualized and software-as-a-service. It can be adopted by organizations of any type and size and can be used by internal and external parties to assess an organization's ability to meet its own ITAM requirements. It does not specify financial, accounting, or technical requirements for particular asset types, does not detail process methods or procedures, and is not intended for managing information assets independent of hardware and software.

Framework Objectives

The standard aims to give organizations a management system that establishes, maintains, and improves control over their IT assets throughout the asset life cycle.

Specify requirements for an IT asset management system within the context of the organization.

Extend ISO 55001 with the additional requirements that software and other IT assets demand.

Ensure trustworthy data on IT assets as the foundation for licensing, security, and financial control.

Integrate IT asset management with the organization's other management systems and life cycle processes.

Manage IT asset risks and licensing compliance through defined objectives, processes, and audit trails.

Enable staged implementation and assessment through defined tiers and support certification.

Framework in Context

ISO/IEC 19770-1:2017 is the management system standard of the ISO/IEC 19770 series, whose vocabulary is defined in ISO/IEC 19770-5:2015 and whose data standards include software identification tags (ISO/IEC 19770-2) and entitlement schemas (ISO/IEC 19770-3). It extends ISO 55001:2014 and shares the harmonized structure of ISO/IEC 27001:2022, ISO/IEC 20000-1, and ISO 9001, with which it is designed to be implemented jointly. Its asset inventory and licensing controls support the asset management controls of ISO/IEC 27002:2022, the IT asset management practice of ITIL 4, the managed assets objective of COBIT 2019, and supplier controls in ISO/IEC 27036.

Common Framework Mappings

ISO/IEC 19770-1:2017 is commonly mapped to the management system standards and IT frameworks with which an ITAMS is integrated, so that asset data and controls can evidence security, service management, and governance requirements at the same time.

Mapped frameworks include:

ISO/IEC 19770-5:2015

ISO 55001

ISO/IEC 20000-1

ISO 27001:2022

ISO 27002:2022

ISO 9001:2026

ITIL 4

COBIT 2019

ISO/IEC 27036

At a Glance
ISO/IEC 19770-1:2017 – Information technology – IT asset management – Part 1: IT asset management systems – Requirements
  • Classification
    Category
    IT Governance
    Domain
    IT Governance
    Framework Family
    ISO Management Systems
  • Regulatory Context
    Type
    Standard
    Legal Instrument
    Standard
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    Global
    Region Detail
    International
    Publisher
    International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), ISO/IEC JTC 1/SC 7
  • Versioning
    Version
    Third edition (2017-12), with Amendment 1:2024
    Effective Date
    December 2017
    Issue Date
    December 2017 (Amendment 1 published 2024)
  • Adoption
    Adoption Model
    Certification
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: No

ISO/IEC 19770-1:2017 is a copyrighted standard purchased from ISO or a national standards body, and the text is not included with the platform.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
ISO/IEC 19770-1:2017 catalogue page
The ISO catalogue entry for Part 1, with status, edition, committee, amendment, and purchase and preview options.
ISO/IEC 19770-1:2017 preview on the Online Browsing Platform
ISO's read-only preview of the standard's foreword, introduction, scope, and terms.
ISO/IEC JTC 1/SC 7 flagship standard: ISO/IEC 19770-1:2017
The responsible ISO committee's description of the standard, its process areas, tiers, and joint use with ISO/IEC 27001 and ISO/IEC 20000-1.
ISO/IEC 19770-1:2017 document preview (iTeh Standards)
A sample of the published text showing the foreword, introduction, and Clause 1 scope, field of application, and limitations.
SMARTSUITE

How SmartSuite Supports ISO/IEC 19770-1

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For ISO/IEC 19770-1, SmartSuite holds the Clause 4 to 10 requirements and Annex A process areas as a control library, keeps the IT asset register, entitlements, and reconciliations as linked records, and tracks tier progress, risk treatment, and audit findings to closure.

ITAMS Requirements Library

Hold every clause requirement and Annex A process area as a structured record with owner, implementation status, and tier.

Ownership, Cadence, and Accountability

Assign asset owners and process owners, schedule reconciliations, internal audits, and management reviews, and track them to completion.

Evidence Collection and Audit Trail

Record inventories, entitlement documents, reconciliations, authorizations, and changes to IT assets with timestamps and reviewers.

Internal Audit and Conformance Testing

Plan audits against the requirements and tiers, document findings and nonconformities, and follow corrective actions to closure.

Risk and Vendor Alignment

Connect IT asset risks, software publishers, and contracts to the assets, licenses, and process areas they affect.

Certification and Management Reporting

Generate views of license position, tier progress, open nonconformities, and audit readiness for management review and certification bodies.

Related frameworks

ISO/IEC 19770-5:2015

ISO/IEC 19770-5:2015 is the overview and vocabulary part of the ISO/IEC 19770 IT asset management series, defining the terms and principles that the other parts share.

ISO/IEC 20000-1

ISO/IEC 20000 is an international standard for establishing and improving IT service management to ensure reliable, business-aligned service delivery.

ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

ISO 9001:2026

ISO 9001:2026 sets requirements for a quality management system that helps organizations consistently deliver products and services that meet customer and regulatory requirements.

ITIL 4

ITIL 4 is a service management framework that helps organizations align IT services with business goals and improve service delivery.

COBIT 2019

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.

ISO 27000

ISO/IEC 27000 provides foundational concepts and terminology for establishing and operating an information security management system.

ONBOARDING FAQS

Frequently Asked Questions For ISO/IEC 19770-1

What is ISO/IEC 19770-1:2017?

ISO/IEC 19770-1:2017 is the international standard that specifies requirements for an IT asset management system (ITAMS): a management system for establishing, implementing, maintaining, and improving IT asset management. It is the third edition of Part 1 of the ISO/IEC 19770 series and the part organizations implement and can be certified against.

How does ISO/IEC 19770-1 relate to ISO 55001?

It is a discipline-specific extension of ISO 55001:2014, the asset management system standard, with changes. It adds the requirements that IT assets and particularly software need, such as controls over software duplication and distribution, audit trails, licensing compliance, mixed ownership in cloud and BYOD environments, and reconciliation with financial systems. Conformance to ISO/IEC 19770-1 does not imply conformance to ISO 55001.

What are the three tiers in ISO/IEC 19770-1?

Annex B optionally groups process objectives into three tiers: trustworthy data, which establishes accurate inventory and entitlement information and is the most important tier for most organizations; life cycle integration, which embeds ITAM in acquisition, deployment, change, and disposal processes; and optimization, which uses the data to optimize cost, risk, and value.

What changed between the 2012 and 2017 editions of ISO/IEC 19770-1?

The 2012 second edition defined SAM processes and a tiered assessment of conformance. The 2017 third edition cancels and replaces it and was technically revised into a management system standard using the harmonized structure of Clauses 4 to 10, so that it can be integrated with ISO/IEC 27001, ISO/IEC 20000-1, and ISO 9001 and certified in the same way.

Which assets does ISO/IEC 19770-1 cover?

All IT assets: hardware, executable software such as applications and operating systems, and non-executable software such as fonts and configuration information, in every environment from on-premises to virtualized and software-as-a-service. It does not cover information as an asset independent of hardware and software, and it does not set financial or technical requirements for specific asset types.

Can an organization be certified to ISO/IEC 19770-1?

Yes. As a management system standard, ISO/IEC 19770-1:2017 can be audited by an accredited certification body, and the standard states that it can be used by internal and external parties to assess an organization's ability to meet its own IT asset management requirements. Certification is voluntary.

How does ISO/IEC 19770-1 fit with ISO/IEC 27001 and ITIL 4?

ISO/IEC JTC 1 designed it to be implemented jointly with ISO/IEC 27001 and ISO/IEC 20000-1, sharing the harmonized clause structure, and its asset inventory and licensing controls support the asset management controls of ISO/IEC 27002. ITIL 4's IT asset management practice describes the same activities as guidance rather than requirements.

Operationalize ISO/IEC 19770-1:2017 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.