Operations · Service Management
ITSM
IT Service Management: the practices that deliver, support and improve IT services with defined processes, roles and records.
FoundationalUpdated 2026-09-01
Overview
ITSM organises work into recognisable practices, incident, request, problem, change, asset, configuration, knowledge and service level management. ITIL is the best known framework, but the practices matter more than adherence to any particular vocabulary.
The purpose is predictability: consistent intake, clear ownership, traceable decisions and a record that supports learning. Over engineered process is a real failure mode; the test is whether the process reduces confusion or adds ceremony.
How it works
- 01Intake is standardised through a service catalogue and request forms so tickets arrive with the information needed to act.
- 02Priority combines impact and urgency, driving response targets and escalation.
- 03Records link to each other, incidents to problems, changes to incidents, assets to configuration items, which is how patterns become visible.
- 04Service level targets and reporting create an agreed definition of acceptable performance.
Reference table
| Practice | Trigger | Objective | Success measure |
|---|---|---|---|
| Incident management | Something is broken | Restore service quickly | Time to restore |
| Request fulfilment | Someone needs something standard | Deliver predictably | Time to fulfil, satisfaction |
| Problem management | Recurring or unexplained incidents | Remove the underlying cause | Repeat incident reduction |
| Change enablement | A planned modification | Change safely with minimal disruption | Change success rate |
| Asset management | Acquisition and lifecycle events | Know what you own and its state | Inventory accuracy |
| Configuration management | Environment changes | Understand relationships and dependencies | CMDB accuracy and usefulness |
| Knowledge management | Resolved issues, new services | Reuse what has been learned | Self service and first contact resolution |
Security considerations
- Restrict who can close, edit or delete records; ticketing systems are audit evidence.
- Keep sensitive data out of ticket bodies and attachments, and control external access to the portal.
- Verify identity before performing account resets, service desk social engineering is a common intrusion route.
Common misconfigurations
- Change process so heavy that teams route work around it.
- Priority set by whoever complains loudest rather than by defined impact.
- Knowledge articles never updated, so the service desk stops trusting them.
