// Information Security
ISO/IEC 20000 IT Service Management Compliance Software
International standard for IT Service Management System.
Framework at a glance
Short name
ISO 20000
Version
—
Category
Information Security
Controls
35
What ISO 20000 covers
35 controls across 31 domains — every one tracked, owned and evidenced in Cyber Horizon.
Scope
2 controls- 4.1 Understanding ITSM context
- 4.3 Scope of SMS
Stakeholders
1 controls- 4.2 Interested parties
Governance
2 controls- 5.1 Leadership commitment
- 5.3 Roles and responsibilities
Policy
1 controls- 5.2 Service management policy
Risk
1 controls- 6.1 Risk and opportunity management
Objectives
1 controls- 6.2 Objectives
Resources
1 controls- 7.1 Resources
Training
1 controls- 7.2 Competence
Portfolio
1 controls- 8.2 Service portfolio
Relationships
1 controls- 8.3 Relationship and agreement management
Customer
1 controls- 8.3.1 Business relationship management
SLAs
1 controls- 8.3.2 Service level management
Vendors
1 controls- 8.3.3 Supplier management
Capacity
2 controls- 8.4 Supply and demand
- 8.4.2 Capacity management
Financial
1 controls- 8.4.1 Budgeting and accounting
Demand
1 controls- 8.4.3 Demand management
Development
1 controls- 8.5 Design and transition
Change Management
1 controls- 8.5.1 Change management
Planning
1 controls- 8.5.2 Service design and transition
CMDB
1 controls- 8.5.3 Configuration management
Incidents
2 controls- 8.6 Resolution and fulfilment
- 8.6.1 Incident management
Requests
1 controls- 8.6.2 Service request management
Problems
1 controls- 8.6.3 Problem management
Quality
1 controls- 8.7 Service assurance
Availability
1 controls- 8.7.1 Service availability management
Continuity
1 controls- 8.7.2 Service continuity management
Security
1 controls- 8.7.3 Information security management
Monitoring
1 controls- 9.1 Monitoring and measurement
Audit
1 controls- 9.2 Internal audit
Corrective Action
1 controls- 10.1 Nonconformity and corrective action
Improvement
1 controls- 10.2 Continual improvement
How Cyber Horizon automates ISO 20000
Every ISO 20000 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is ISO/IEC 20000 IT Service Management?
International standard for IT Service Management System.
How many controls does ISO/IEC 20000 IT Service Management have?
ISO/IEC 20000 IT Service Management has 35 controls in Cyber Horizon's catalogue, organised across 31 domains.
How does Cyber Horizon help with ISO/IEC 20000 IT Service Management?
Cyber Horizon maps ISO/IEC 20000 IT Service Management into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 20000 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Information Security frameworks
See ISO 20000 mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 20000 in Cyber Horizon.