Skip to content
Cyber Horizon
All frameworks

// Information Security

ISO/IEC 20000 IT Service Management Compliance Software

International standard for IT Service Management System.

Framework at a glance

Short name

ISO 20000

Version

Category

Information Security

Controls

35

What ISO 20000 covers

35 controls across 31 domains — every one tracked, owned and evidenced in Cyber Horizon.

Scope

2 controls
  • 4.1 Understanding ITSM context
  • 4.3 Scope of SMS

Stakeholders

1 controls
  • 4.2 Interested parties

Governance

2 controls
  • 5.1 Leadership commitment
  • 5.3 Roles and responsibilities

Policy

1 controls
  • 5.2 Service management policy

Risk

1 controls
  • 6.1 Risk and opportunity management

Objectives

1 controls
  • 6.2 Objectives

Resources

1 controls
  • 7.1 Resources

Training

1 controls
  • 7.2 Competence

Portfolio

1 controls
  • 8.2 Service portfolio

Relationships

1 controls
  • 8.3 Relationship and agreement management

Customer

1 controls
  • 8.3.1 Business relationship management

SLAs

1 controls
  • 8.3.2 Service level management

Vendors

1 controls
  • 8.3.3 Supplier management

Capacity

2 controls
  • 8.4 Supply and demand
  • 8.4.2 Capacity management

Financial

1 controls
  • 8.4.1 Budgeting and accounting

Demand

1 controls
  • 8.4.3 Demand management

Development

1 controls
  • 8.5 Design and transition

Change Management

1 controls
  • 8.5.1 Change management

Planning

1 controls
  • 8.5.2 Service design and transition

CMDB

1 controls
  • 8.5.3 Configuration management

Incidents

2 controls
  • 8.6 Resolution and fulfilment
  • 8.6.1 Incident management

Requests

1 controls
  • 8.6.2 Service request management

Problems

1 controls
  • 8.6.3 Problem management

Quality

1 controls
  • 8.7 Service assurance

Availability

1 controls
  • 8.7.1 Service availability management

Continuity

1 controls
  • 8.7.2 Service continuity management

Security

1 controls
  • 8.7.3 Information security management

Monitoring

1 controls
  • 9.1 Monitoring and measurement

Audit

1 controls
  • 9.2 Internal audit

Corrective Action

1 controls
  • 10.1 Nonconformity and corrective action

Improvement

1 controls
  • 10.2 Continual improvement

How Cyber Horizon automates ISO 20000

Every ISO 20000 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is ISO/IEC 20000 IT Service Management?

International standard for IT Service Management System.

How many controls does ISO/IEC 20000 IT Service Management have?

ISO/IEC 20000 IT Service Management has 35 controls in Cyber Horizon's catalogue, organised across 31 domains.

How does Cyber Horizon help with ISO/IEC 20000 IT Service Management?

Cyber Horizon maps ISO/IEC 20000 IT Service Management into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 20000 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See ISO 20000 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 20000 in Cyber Horizon.