A company is experiencing frequent service outages due to unauthorized changes to the production environment. Which ITIL practice would be most effective in preventing these issues?
Trap 1: Incident management
Incident management focuses on minimizing the negative impact of incidents by restoring normal service operation as quickly as possible. Its primary objective is reactive, addressing unplanned interruptions or reductions in service quality. While crucial for service restoration, it does not proactively control or prevent unauthorized changes that could cause such outages in the first place, making it unsuitable for the stated problem of preventing outages due to unauthorized changes.
Trap 2: Problem management
Problem management aims to reduce the likelihood and impact of incidents by identifying and resolving the root causes of actual and potential incidents. While it might identify that unauthorized changes are a root cause of frequent outages, its role is to analyze and recommend solutions, not to directly govern or control the implementation of changes themselves. It provides insights that inform change enablement, but does not execute the change control function.
Trap 3: Service desk
The service desk serves as the single point of contact between the service provider and its users, primarily handling incident resolution, service requests, and communication. Its focus is on user support and facilitating service access, not on the governance or control of infrastructure and service changes. While a service desk might log change requests, it does not possess the authority or processes to assess, authorize, or prevent unauthorized changes from being implemented.
- A
Incident management
Why wrong: Incident management focuses on minimizing the negative impact of incidents by restoring normal service operation as quickly as possible. Its primary objective is reactive, addressing unplanned interruptions or reductions in service quality. While crucial for service restoration, it does not proactively control or prevent unauthorized changes that could cause such outages in the first place, making it unsuitable for the stated problem of preventing outages due to unauthorized changes.
- B
Change enablement
Change enablement is the practice of ensuring that all changes to services, products, and organizational components are assessed, authorized, and implemented in a controlled manner. Its purpose is to maximize the number of successful service and product changes by reducing the risk of negative impact, including service outages caused by unauthorized or poorly managed modifications. By establishing clear procedures for change requests, evaluation, approval, and deployment, it directly addresses the prevention of issues stemming from uncontrolled alterations.
- C
Problem management
Why wrong: Problem management aims to reduce the likelihood and impact of incidents by identifying and resolving the root causes of actual and potential incidents. While it might identify that unauthorized changes are a root cause of frequent outages, its role is to analyze and recommend solutions, not to directly govern or control the implementation of changes themselves. It provides insights that inform change enablement, but does not execute the change control function.
- D
Service desk
Why wrong: The service desk serves as the single point of contact between the service provider and its users, primarily handling incident resolution, service requests, and communication. Its focus is on user support and facilitating service access, not on the governance or control of infrastructure and service changes. While a service desk might log change requests, it does not possess the authority or processes to assess, authorize, or prevent unauthorized changes from being implemented.