Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

IT Standards

IT Standards are the agreed specifications, protocols, and practices that let information technology systems work together reliably and securely. They span data formats, communication protocols, security controls, and management frameworks, giving organizations a shared baseline for building and governing technology.

IT Standards are the agreed specifications, protocols, and practices that let information technology systems interoperate, stay secure, and be governed consistently. They are set by bodies like ISO, IETF, W3C, and NIST, as well as by industry consortia, and they cover everything from data formats and network protocols to security controls and management frameworks. Together they form the shared baseline that keeps independently built systems working with one another.

  • Interoperability - Common formats and protocols so systems from different vendors exchange data without custom glue.
  • Security and Compliance - Frameworks like ISO 27001 and NIST that define auditable baselines for protecting systems and data.
  • Governance Frameworks - Management standards such as ITIL and COBIT that structure how technology is run and measured.
  • Multiple Authorities - Maintained by a mix of formal standards bodies and industry groups, each with its own scope and process.

In API operations, IT standards are exactly what governance turns into enforceable rules — naming conventions, versioning policy, security requirements, and format choices encoded as OpenAPI contracts and Spectral rulesets that a pipeline can check automatically. This is where an abstract standard becomes something machine-checkable across an estate, and increasingly something an AI agent can read and apply. Treating IT standards as living, testable rules rather than shelfware is the difference between governance that scales and documentation nobody follows.

Referenced on the API Evangelist blog

Where this standard shows up across sixteen years of my writing at apievangelist.com — how it fits into API design, governance, and the agentic turn.