ISO/IEC 19770-5:2015 – Information technology – IT asset management – Part 5: Overview and vocabulary

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
ISO/IEC 19770-5:2015 is the overview and vocabulary standard for the ISO/IEC 19770 family of IT asset management (ITAM) and software asset management (SAM) standards. It gives an overview of the family, introduces ITAM and SAM, describes the foundation principles and approaches on which SAM is based, and defines the terms used consistently across the other parts. Its second edition, published in 2015, cancels and replaces the 2013 first edition.
It is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) and prepared by ISO/IEC JTC 1/SC 7, Software and systems engineering. It is not a requirements standard and carries no certification; it applies to all types of organization, including commercial enterprises, government agencies, and non-profit organizations, and ISO/IEC JTC 1 describes it as the freely available entry point to the series.
Organizations use it as the reference glossary and orientation for an ITAM program: to align definitions of asset, IT asset, software asset, license, and entitlement across procurement, IT, finance, and security, to understand how ISO/IEC 19770-1 (the management system requirements) and the information structure parts such as ISO/IEC 19770-2 and 19770-3 fit together, and to explain the business case for managing software assets to leadership before implementing the requirements parts.
Why it Matters
IT asset management fails most often on definitions: what counts as an asset, what a license actually entitles, and which team owns the data. ISO/IEC 19770-5:2015 settles those definitions for the whole ISO/IEC 19770 series and explains why software assets need managing, so that an ITAM program starts from a shared vocabulary and a clear business case.
Key benefits include:
- Establish a common vocabulary
Terms such as asset, IT asset, software asset, entitlement, and reconciliation are defined once and reused by every part of the series and by ISO/IEC 19770-1 conformance work.
- Explain the business case
Clause 4 sets out the direct benefits, cost control, and risk management and mitigation reasons for managing software assets.
- Show how the family fits together
Clause 5 maps the process standard, the information structure standards, and the guidance technical reports so organizations know which part they need.
- Align with other management systems
The standard describes how SAM principles relate to ISO 9001, ISO/IEC 20000, ISO/IEC 27000, and ISO 55000.
- Provide a free starting point
ISO/IEC JTC 1 describes Part 5 as the freely available ITAM standard, which lowers the barrier to adopting the series.
How it Works
ISO/IEC 19770-5:2015 has five clauses and a bibliography. Clause 1 is the scope, Clause 2 the normative references (ISO 55000:2014 and RFC 3986), and Clause 3 the terms and definitions, many sourced from ISO 55000 and ISO/IEC/IEEE 24765. Clause 4 introduces ITAM and SAM, explains the need to manage software assets, states the foundation principles, relates them to the principles of ISO 9001, ISO/IEC 20000, ISO/IEC 27000, and ISO 55000, and sets out principles for process definitions and information structures and critical success factors. Clause 5 gives an overview of the family: the standards specifying processes, the technical reports that guide them, the standards specifying information structures, and the overview standards.
Organizations apply it by adopting its definitions in ITAM policy, asset registers, license records, and contracts, by using Clause 4 to brief leadership on benefits, cost control, and risk, and by using Clause 5 to select which parts of the series to implement, typically ISO/IEC 19770-1 for the management system and ISO/IEC 19770-2 software identification tags and ISO/IEC 19770-3 entitlement schemas for data interoperability with tools and publishers.
Within SmartSuite, teams hold the ISO/IEC 19770-5 vocabulary as the reference data model for IT asset, license, and entitlement records, link each term to the fields and processes that use it, and keep the family overview alongside their ISO/IEC 19770-1 control library so that every process area and data structure is traceable to a defined term.
Key Elements
- Overview of the ISO/IEC 19770 family
A description of each part of the series, grouped into process standards, information structure standards, guidance technical reports, and overview standards.
- Introduction to ITAM and SAM
An explanation of IT asset management and software asset management and why software assets have characteristics that need specific controls.
- Need to manage software assets
Direct benefits, cost control, and risk management and mitigation as the reasons for a SAM program.
- Foundation principles
The principles on which SAM processes and information structures are based, and how they relate to ISO 9001, ISO/IEC 20000, ISO/IEC 27000, and ISO 55000.
- Principles of process and information structure definitions
Rules for defining SAM processes and data structures and for evaluating conformance of those definitions.
- Critical success factors
The conditions the standard identifies for a SAM program to succeed.
- Terms and definitions
The shared vocabulary for the series, including asset, application, entitlement, and related terms.
Framework Scope
ISO/IEC 19770-5:2015 applies to all types of organization, including commercial enterprises, government agencies, and non-profit organizations. It covers the concepts, principles, and vocabulary of IT asset management and software asset management and gives an overview of the ISO/IEC 19770 series; it does not itself specify requirements, processes, or data schemas, which are left to the other parts.
Framework Objectives
The standard aims to give every user of the ISO/IEC 19770 series the same understanding of what IT asset management is, why it matters, and how the parts of the series work together.
Provide an overview of the ISO/IEC 19770 family of standards and how its parts relate.
Introduce IT asset management and software asset management and the case for managing software assets.
Describe the foundation principles and approaches on which software asset management is based.
Provide consistent terms and definitions for use throughout the series.
Explain how SAM principles align with ISO 9001, ISO/IEC 20000, ISO/IEC 27000, and ISO 55000.
Set out principles and conformance evaluation for SAM process definitions and information structures.
Framework in Context
ISO/IEC 19770-5:2015 plays the same role for the ISO/IEC 19770 series that ISO/IEC 27000 plays for the information security standards and ISO 55000 plays for asset management, and it normatively references ISO 55000:2014. It underpins ISO/IEC 19770-1:2017, the ITAM management system requirements, and relates its principles to ISO 9001, ISO/IEC 20000-1, and ISO/IEC 27001; the IT asset management practice of ITIL 4 uses the same vocabulary.
Common Framework Mappings
ISO/IEC 19770-5:2015 is commonly mapped to the standards whose vocabulary and principles it aligns with, so that ITAM programs can share definitions with quality, service management, security, and asset management systems.
Mapped frameworks include:
ISO/IEC 19770-1:2017
ISO 55000
ISO 27000
ISO/IEC 20000-1
ISO 9001:2026
ITIL 4
- ClassificationCategoryIT GovernanceDomainIT GovernanceFramework FamilyISO Management Systems
- Regulatory ContextTypeStandardLegal InstrumentStandardSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionGlobalRegion DetailInternationalPublisherInternational Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), ISO/IEC JTC 1/SC 7
- VersioningVersionSecond edition (2015)Effective Date2015Issue Date2015 (replaces the 2013 first edition)
- AdoptionAdoption ModelVoluntaryImplementation ComplexityLow
- Official ReferenceOpen Link in New TabSource
License included / downloadable: No
ISO/IEC 19770-5:2015 is published by ISO and IEC; ISO/IEC JTC 1 describes it as freely available, and copies are otherwise obtained from ISO or national standards bodies, and the text is not included with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports ISO/IEC 19770-5
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For ISO/IEC 19770-5, SmartSuite holds the standard's vocabulary as the reference data model for IT asset, license, and entitlement records and links each defined term to the ITAM processes, fields, and evidence that use it.
ITAM Vocabulary and Family Library
Hold each defined term, foundation principle, and part of the ISO/IEC 19770 series as a structured record linked to the processes that use it.
Ownership, Cadence, and Accountability
Assign owners for asset classes, license records, and vocabulary maintenance, with review dates as the series is updated.
Evidence Collection and Audit Trail
Record where each term and principle is applied in policies, registers, and contracts, with timestamps and reviewers.
Definition and Data Quality Testing
Check asset and license records against the standard's definitions and track inconsistencies to correction.
Risk and Vendor Alignment
Connect software publishers, contracts, and entitlement risks to the assets and terms they concern.
Program Reporting
Generate views of vocabulary adoption, asset data quality, and readiness for ISO/IEC 19770-1 implementation for leadership.
Related frameworks

ISO/IEC 19770-1:2017 specifies the requirements for an IT asset management system (ITAMS), extending ISO 55001 with controls for software, licensing, and IT asset data.

ISO/IEC 20000 is an international standard for establishing and improving IT service management to ensure reliable, business-aligned service delivery.

ISO/IEC 27000 provides foundational concepts and terminology for establishing and operating an information security management system.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO 9001:2026 sets requirements for a quality management system that helps organizations consistently deliver products and services that meet customer and regulatory requirements.
Frequently Asked Questions For ISO/IEC 19770-5
ISO/IEC 19770-5:2015 is the overview and vocabulary part of the ISO/IEC 19770 series of IT asset management standards. It introduces IT asset management and software asset management, explains the principles behind them, gives an overview of the other parts of the series, and defines the terms those parts use.
No. It is an overview and vocabulary standard and contains no requirements. The requirements for an IT asset management system are in ISO/IEC 19770-1:2017, which is the part organizations implement and can be certified against.
It is published by ISO and IEC and prepared by their joint technical committee ISO/IEC JTC 1, Subcommittee SC 7, Software and systems engineering. It applies to all types of organization, including commercial enterprises, government agencies, and non-profit organizations.
Part 5 provides the vocabulary, principles, and family overview; Part 1 specifies the management system requirements. The terms defined in Part 5 are used throughout Part 1, and Clause 5 of Part 5 explains where Part 1 sits among the process, information structure, and guidance parts of the series.
The second edition cancels and replaces the 2013 first edition and was technically revised. Among other changes, the definition of asset was aligned with the published ISO 55000:2014 text rather than a development draft, and the family overview was updated to reflect the parts published or under preparation at the time.
ISO/IEC JTC 1 describes Part 5 as the only freely available ITAM standard in the series. Availability should be confirmed on the ISO website; other parts of the series, including ISO/IEC 19770-1, are purchased from ISO or a national standards body.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

