This document discusses two ISO standards: ISO/IEC 27014:2013, which provides guidance on governance of information security, and ISO/IEC 38500:2008, which provides guidance on governance of information technology. It notes some key differences between the two standards, such as ISO 27014 focusing specifically on information security while ISO 38500 focuses more broadly on IT governance. It also discusses the development process for ISO 27014 and some of the challenges faced in creating the standard over five years of work.