Add your promotional text...
The OIKON IT Framework
For more than two decades, IT governance has been decomposed into dozens of overlapping frameworks — ITIL for service management, COBIT forgovernance, ISO 27001 for security, ISO 31000 for risk, CMMI for development quality.
Each brings its own vocabulary, its own policies, its own certification industry, and its own overhead.
The result is governance that is complex to imiplement, expensive to maintain, difficult to audit, and may become disconnected and misaligned with the from the actual work of delivering IT services and achieving the business objectives.
Value begins with recognising what you already have.
The OIKON Framework - Developed by Jonathon Thomson Better Process Solutions (Vic) 2025
Licensed under Creative Commons Attribution 4.0 International (CC BY 4.0)
The OIKON IT Framework
returns to first principles.
OIKON is named after the ancient Greek oikos (οἶκος) — the household, the estate, the things you own and are responsible for managing.
Every management science traces back to this idea: oikonomia (themanagement of the household) gave us economics; oikologia (the study of the household environment) gave us ecology.
OIKON applies the same foundational logic to IT governance. An organisation's IT estate is its digital household. The framework governs it as such: knowing what you have, managing it through its lifecycle, responding to things that happen to it, and protecting its value.
It is a unified IT governance model that replaces dozens of overlapping policies and frameworks with five foundational policies, a complete asset ontology, and a single coherent operating logic.


Where stewardship becomes capability.
What is OIKON?
The Core Insight
OIKON organises every IT governance concern into one of two categories:
Assets — the things you have, operate, control, and are responsible for.
Events — the things that happen to those assets.
Assets include not just infrastructure and applications, but data, information, knowledge, service capabilities, and third-party capabilities. All governed by the same lifecycle logic.
Events include not just incidents and outages, but service requests, change requests, risk signals, security alerts, and both human and automated or AI-initiated actions. All assessed against defined tolerances.
Within tolerance: standard process.
Outside tolerance: escalation
This is not a simplification. It is a more precise and more complete model than any domain-specific framework achieves.


Stewardship as Strategy
1. Everything is an asset.
Infrastructure, applications, data, information, knowledge, service capabilities, and third-party capabilities are all assets. They have a lifecycle, a classification, a value, and a risk profile. Nothing that IT manages falls outside the asset universe.
The Five Axioms
Improving reliability, reducing operational noise, and strengthening service delivery.
2. Events happen to assets.
Everything that occurs in IT operations is an event — a system alert, a service request, a change, a security signal, an AI action. Events are the fundamental unit of IT operations.Write your text here...
3. Tolerance determines response.
Every asset class carries a defined tolerance envelope. Events within tolerance follow standard processes. Events outside tolerance are incidents, triggering escalated response proportionate to the breach.
4. Risk is a continuous service, not a periodic review.
Risk management is not a quarterly governance calendar event. It is a responsive operational service, triggered by events and periodically confirmed by schedule. Inherent risk profiles for each asset class provide the baseline — making risk-informed governance available from the moment an asset is registered.
5. Change is a service and a process applied to assets.
Change requests are events. Application development is the change process applied to application assets. Release is the fulfilment mechanism of an approved change. Service requests are pre-approved event types. All are specialisations of a single change event model.


Five Policies. Not Fifty.
The OIKON Framework produces five governance policies — sufficient to cover every IT management domain — supported by approximately thirty Standards that carry the operational detail.
IT-GOV-01 - IT Governance Framework Policy
IT-GOV-02 - IT Strategy & Investment Policy
IT-AST-01 - IT Asset Management Policy
IT-EVT-01 - IT Event & Incident Management Policy
IT-ARC-01 - Enterprise IT Architecture & Technology Policy
Existing security frameworks — ISO 27001, the Essential Eight, the Victorian Protective Data Security Framework — operate as a security overlay on top of the five core policies. They are not replaced. They are correctly positioned as security-specific governance within a complete IT governance architecture.
Strengthening security posture through governance, structure, and clarity.
How OIKON Relates to Existing Standards
OIKON does not compete with existing standards. It provides the governance architecture within which they operate.
ITIL 4 and ISO 20000 — Service management practices (incident management, problem management, change management, service catalogue) are correctly positioned as event processes and asset governance within OIKON. They become Standards and Procedures rather than standalone policy domains.
ISO 31000 — Risk management operates as a continuous service within OIKON's governance framework, triggered by events rather than governed by a periodic review calendar.
ISO 27001 / Essential Eight / VDPSF — Information security frameworks apply as a security overlay on the OIKON asset universe and event flow. They are not replaced; they are integrated.
COBIT 2019 — All COBIT management objectives map to one of OIKON's five policy domains. OIKON provides the unifying framework within which COBIT objectives are governed.
CMMI v2.0 — Development quality practices map to OIKON's event model (development as a change process on application assets) and its asset governance (application lifecycle management).


Why It Works
Traditional IT governance frameworks were designed in an era when changes took months to years to implement, and when periodic risk reviews were adequate. That world no longer exists.
OIKON was developed over ten years of practice in IT governance, process optimisation, and risk management across public sector, regulated enterprise, and SME environments. It reflects how IT operations actually work, not how they were modelled in the 1990s and 2000s.
The framework is self-referential: the risk management process is itself a service asset. The event logs are knowledge assets. The policies are knowledge assets with lifecycle governance. The model governs IT using the same constructs it uses to govern itself.
Delivering structured, predictable, and well‑governed change.


Open Framework, Clear Attribution
The OIKON Framework is published under Creative Commons Attribution 4.0 International (CC BY 4.0).
It may be used, implemented, adapted, and built upon for any purpose, including commercially provided that attribution is given to the original author. © Jonathon Thomson, Better Process Solutions (Vic), 2025. Licensed under CC BY 4.0.
Cite as: Jonathon Thomson (2025). The OIKON Framework. Better Process Solutions (Vic). https://bpsvic.com.au/oikon-framework
Implement OIKON in Your Organisation Better Process Solutions (Vic) provides advisory, implementation, and assurance services for the OIKON Framework — including policy development, Standards design, and governance architecture for public sector and regulated enterprise clients.
Subscribe
Keep up to date with the latest updates on business processes, technology opportunities, and regulatory updates
email@bpsv.com.au
© 2025 Better Process Solutions (Vic). All rights reserved.
Let's see what we can do for you

