IT principles

Reading COBIT 5 inspires me to revive a project of mine: Direct, a policy framework for IT. As part of that exercise, I want to collect a generic set of fundamental IT principles, akin to the list of generic IT objectives in COBIT 4 and 5.

So what are the axioms that underpin the operation of an IT business or business unit?

How does IT survive with no policy framework?

As far as I can tell there is no such thing as a policy framework for IT. ISO38500 bangs on about the need for policies. ITIL and COBIT mention legions of policies. But I can find nothing that gives us a comprehensive list of necessary policies, let alone describes what a policy structure looks like and what the priorities are.

