Overview
ISO/IEC 19770-5:2015 - Information technology - IT asset management - Part 5: Overview and vocabulary - provides a clear, organization‑agnostic introduction to the ISO/IEC 19770 family of standards for IT asset management (ITAM) and software asset management (SAM). It defines consistent terms and definitions, describes foundational principles and approaches for SAM, and explains how the SAM standards align with other management standards. The standard is applicable to all types of organizations (commercial, government, non‑profit).
Key topics and technical focus
- Overview of the ISO/IEC 19770 family: scope and structure of the SAM standards (process and information‑structure parts).
- ITAM and SAM introduction: rationale for managing software assets, direct benefits, cost control, and risk mitigation.
- Consistent vocabulary: definitions for core terms (asset, asset management, configuration item/CI, baseline, bundle, CMDB, computing device, application, etc.) to ensure interoperability across tools and processes.
- Foundation principles and process guidance: principles that guide SAM process definitions and how to evaluate process definition conformance.
- Information structures: principles for defining data models and evaluating information‑structure conformance to support automation, interoperability, and security.
- Relationships to other ISO standards: alignment and cross‑references with ISO 9001, ISO/IEC 20000, ISO/IEC 27000, ISO 55000, promoting integration with existing management systems.
- Critical success factors: elements that influence successful SAM program implementation and governance.
Practical applications and who uses it
- IT managers and SAM program owners - to adopt a common vocabulary and foundational principles that make internal processes consistent and auditable.
- Procurement, licensing, and compliance teams - to understand asset definitions and terminology used for entitlements, bundles, baselines, and CMDB records.
- Security and risk teams - to link software asset data with vulnerability management and exposure mitigation strategies.
- Tool vendors and integrators - to design interoperable data models and conformant information structures for automation and reporting.
- Auditors and assessors - to evaluate process and information‑structure conformance across the SAM lifecycle.
Benefits
- Improves clarity across teams by standardizing SAM terminology
- Enables integration of SAM with ISO management systems (quality, service, security, asset management)
- Supports automation and data interoperability for inventory, entitlement reconciliation, and risk reduction
Related standards
- ISO/IEC 19770 family (Parts 1, 2, 3, etc.) - processes, tags, entitlement schema, and information‑structure standards
- ISO 55000 (asset management) and ISO/IEC 27000 (information security management) - referenced for alignment and shared principles
Keywords: ISO/IEC 19770-5:2015, IT asset management, ITAM, software asset management, SAM, SAM vocabulary, ISO 19770, software asset standards, CMDB, information structures.