This note is intended to serve as a contribution to a discussion within ISO/IEC JTC 1/SC 40 (“IT Service Management and IT Governance”), the objective of which is to determine possible future work based on a mapping between the OASIS “Transformational Government Framework” Standard and the ISO 38500-series of deliverables covering “Governance of Information Technology”.

The result of such mapping could lead to the OASIS TGF TC recommending the existing (or a future) version of the TGF Standard to JTC 1 as a “PAS” submission or identifying requirements for a new work item, within the OASIS TGF TC (with an objective of future submission to JTC 1) or directly within JTC 1/SC 40 itself (with the TGF TC providing input via OASIS liaisons and nominated experts to the SC 40 working group designated to work on this).


1        Introduction

This note is intended to serve as a contribution to a discussion between OASIS and the Joint Technical Committee 1 of ISO and IEC (ISO-IEC/JTC 1), the objective of which is to determine possible future work based on a mapping between the OASIS “Transformational Government Framework” Standard and the ISO 38500-series of deliverables covering “Governance of Information Technology”.

The result of such mapping could lead to the OASIS TGF TC recommending the existing (or a future) version of the TGF Standard to JTC 1 as a “PAS” submission or identifying requirements for a new work item, within the OASIS TGF TC or within JTC 1/SC 40, the specific sub-committee within JTC 1 that is responsible for the domain of IT Service Management and IT Governance.

1.1 References (non-normative)


Transformational Government Framework Version 2, edited by John Borras, Peter F Brown, and Chris Parker. 01 May 2014. OASIS Committee Specification 01.

[ISO 38500]

Information Technology – governance of IT – For the Organization, edited by John Graham, 2014, ISO/IEC FDIS 38500

[ISO 38501]

Information Technology –Corporate Governance of IT Implementation Guide, edited by Max Blecher, 2014, ISO/IEC DTS 38501

[ISO 38502]

Information Technology – Governance of IT – Framework and Model, edited by Max Shanahan, 2014, ISO/IEC TR 38502

2                 “Governance of IT” and “Transformational Government”

2.1 Work in ISO/IEC JTC 1

JTC 1/SC 40 is a relatively new entity within the ISO/IEC JTC 1 system, created from the merger of three existing strands of work covering: Governance of IT; IT Service Management; and Business Process Outsourcing. Within SC 40, these areas are covered by three working groups, respectively WGs 1, 2, and 3.

Among the core responsibilities of SC 40/WG 1 is to “lead the development of standards, tools, frameworks, best practices and related documents on the governance of information technology” including maintenance of a series of deliverables knows as the ISO “38500 Series”. Three of these documents (an International Standard, a Technical Specification, and a Technical Report) establish a principles-based approach to the governance of IT, including the core standard itself (ISO-IEC 38500); an implementation guide (ISO-IEC TS 38501); and a framework and model (ISO-IEC TR 38502).

2.2 Work in OASIS

The Transformational Government Framework (TGF) is a practical “how to” standard for the design and implementation of an effective program of technology-enabled change at national, state or local government level. At the heart of the TGF lies the idea that governments need to transform the way they operate, traditionally organized around functionally-oriented service providers operating as unconnected vertical silos rather than built around user needs.

The OASIS “Transformational Government Framework” Technical Committee (TC) has been responsible for a series of deliverables including the eponymous framework itself (already approved as an OASIS Standard and, in a second version, approved as a Committee Specification), a primer, a separate executive summary as well as several toolkits and guidelines for use of the TGF’s principles.

2.3 Why map TGF to ISO 38500?

Both the OASIS TGF and the ISO-IEC 38500 Standards are high-level, principles-based advisory standards. They are concerned with what information technologies can offer but focus on the role of policy-making and governing bodies in determining how and where such technologies are introduced and deployed.

The interest expressed in mapping the standards against each other is a first step in understanding the overlaps and gaps that such a mapping would reveal and in such a way that would help both the OASIS TGF TC and JTC 1/SC 40 identify potential future work in the domain.

3        Mapping TGF to ISO 38500

3.1 ISO 38500 and “Principles of IT Governance”

The ISO Standard was first developed as an Australian Standard, AS 8015-2005 and later jointly revised by Standards Australia and New Zealand and approved by ISO/IEC JTC 1, through its “fast track” process as ISO/IEC 38500:2008 and updated in 2010.

It provides “a framework of principles for Directors to use when evaluating, directing and monitoring the use of information technology in their organizations” [ISO 38500]. The six principles “express preferred behaviour to guide decision making.”

It is centrally concerned by the governance of information technology.

3.2 OASIS TGF and “Guiding Principles”

The OASIS TGF on the other hand is concerned more broadly with the governance of change. Its scope however covers the public sector and more specifically with enabling the transformation of public sector services and the role played by information technologies in enabling such change. It is concerned with ensuring the management of information technology as a strategic asset.

The “Transformational Government Framework” is structured as a series of “patterns” within a TGF “Pattern Language”. Each Pattern provides high-level guidance for policy makers on how to approach and respond to specific issues covered within the framework.

The TGF framework covers Guiding Principles, Goals (“Benefits Realisation”), Critical Success Factors, and guidance on the three main governance and delivery processes (business management, service management, and technology and digital assets management) and there are a series of Patterns covering each area.

3.3 Mapping of Principles

Even without a detailed mapping of the entire Standards, an initial, cursory examination of the two shows already a high degree of overlap of the principles covered in both: The ISO Standard talks about “Responsibility” while the OASIS Standard talks about “Leadership”; Similarly for: “Strategy” (“Roadmap for Transformation”), “Acquisition” (“Supplier Partnerships” and “Technology Management”), “Performance” (“Critical Success Factors”), and “Human Behaviour” (“Stakeholder Empowerment”).

This is not to imply that the terms – nor the intended scope of their use – are identical: only to suggest that there is sufficient commonality of purpose that a formal mapping and enquiry into future collaboration ought to be undertaken. For copyright and intellectual property reasons it is not possible to pursue this exercise in more detail until both parties agree on a common approach and can make the content of their respective Standards available to each party on explicitly agreed terms.

4        The TGF Pattern Language: A Structure for IT Governance Principles?

The mapping of the ISO and OASIS Standards may also reveal a commonality in the structure of principles-based standards and guidance. The OASIS TGF is explicitly structured using the paradigm of a “Pattern Language” with consistent internal structure for each pattern; relationship between the patterns; and process for developing new patterns.

SC 40/WG 1 is currently examining a proposal for a new work item on the structure of principles-based standards and the TGF Pattern Language – suitably extended and modified could present a useful model for that group to use in the elaboration of that new work.

Appendix B.           Structure of the OASIS TGF

The following diagram provides a high level overview of the structure of the TGF and the individual “Patterns” that make it up:

