ISO
International standards-setting organization across industries
The International Organization for Standardization (ISO) is an independent, non-governmental international body that develops and publishes voluntary technical, industrial, and commercial standards. Founded in the mid-twentieth century and…
Definition
The International Organization for Standardization (ISO) is an independent, non-governmental international body that develops and publishes voluntary technical, industrial, and commercial standards. Founded in the mid-twentieth century and headquartered in Geneva, it draws on national standards bodies from member countries around the world to reach consensus on specifications ranging from quality management systems and information security to character encodings and file formats. Its standards are identified by number, such as ISO 9001 for quality management or ISO 9660 for optical disc file systems.
Overview
ISO exists to give industries and governments a shared, internationally recognized way to agree on specifications so that products, processes, and management systems can be understood and trusted across borders. Before broad international standardization, national technical requirements often diverged enough that products certified in one country needed separate testing or redesign to be sold in another, and organizational practices such as quality assurance had no common external benchmark; ISO's role is to negotiate a single specification that participating countries' national bodies can adopt or reference directly. Mechanically, ISO standards are developed by technical committees composed of experts nominated through national standards bodies, which negotiate a draft through stages of committee review, public and member comment, and formal voting before a standard is published under a numbered designation. Standards are periodically reviewed and revised, and organizations seeking certification against a management-system standard, such as ISO 27001 for information security, undergo an external audit by an accredited certification body rather than simply self-declaring compliance. ISO's scope is broader than sibling standards bodies: it covers essentially any industry, from manufacturing tolerances to management practices to data formats, whereas the IEC focuses specifically on electrotechnical standards and IEEE originates largely from the electrical and electronics engineering profession. Where IEC and ISO overlap, particularly in information technology, they run a joint technical committee to produce shared standards rather than duplicating effort, and character-encoding and file-system standards such as those touching computing frequently carry both organizations' influence. In practice, software and IT organizations most often encounter ISO standards through security and quality certifications, such as ISO 27001 for information security management, through data and character-set standards, and through file-format specifications like ISO 9660, which defines the file system used on CDs and DVDs. Certification against relevant ISO standards is frequently a procurement requirement for vendors selling into regulated industries or to enterprise and government customers. ISO's standards are voluntary and carry no legal force on their own; their practical weight comes from being referenced in contracts, regulations, or procurement requirements by parties who choose to require them. The certification process for management-system standards can also be costly and time-consuming for smaller organizations, and because standards are negotiated across many national interests, they can end up more general or slower to update than a single company's internal specification would be. ISO also maintains widely used technical standards beyond management systems, including character-set and file-system specifications such as ISO 9660 and country and currency code standards referenced throughout software internationalization. These lower-level technical standards tend to be more stable over long periods than management-system standards, since they define fixed data formats rather than evolving organizational practices, but both categories share the same consensus-driven committee process for development and revision.
Key Features
- publishes numbered voluntary standards across virtually all industries
- standards developed through national technical committee consensus
- management-system standards require external audit for certification
- runs a joint technical committee with IEC for information technology
- widely referenced standards include ISO 27001 and ISO 9660
- headquartered in Geneva with member bodies from many countries