Free ISO 20000 Control and Support Processes Questions and Answers — Questions and Answers
Question 1: According to ISO 20000-1, when managing documented information for the Service Management System (SMS), which of the following controls is explicitly required for its creation and updating?
- Peer review by at least two other departments.
- Approval for adequacy and suitability. (Correct answer)
- Storage exclusively in a cloud-based version control system.
- A mandatory retention period of seven years for all documents.
Correct answer: Approval for adequacy and suitability.
ISO 20000-1, clause 7.5.2, specifies that when creating and updating documented information, the organization must ensure appropriate identification, description, format, and 'review and approval for suitability and adequacy'. The other options are specific implementation choices or best practices, but not explicit requirements of the standard.
Question 2: A critical server requires an emergency security patch to address a newly discovered vulnerability. The standard change management process requires a 5-day review period. Following ISO 20000 principles, what is the most appropriate action for the Change Manager to take?
- Reject the change because it does not follow the standard review period.
- Implement the change immediately and document it retrospectively, bypassing all approvals.
- Follow a specific, documented procedure for emergency changes that allows for expedited assessment and approval. (Correct answer)
- Wait for the next scheduled Change Advisory Board (CAB) meeting to discuss the patch.
Correct answer: Follow a specific, documented procedure for emergency changes that allows for expedited assessment and approval.
ISO 20000 requires organizations to have a defined change management process, which must include procedures for handling emergency changes. These changes require rapid assessment and approval to restore service or prevent an incident, but they must still follow a controlled, albeit expedited, process. Simply bypassing all controls or delaying the change would be non-compliant.
Question 3: An organization is defining its configuration management process in line with ISO 20000. When determining which assets should be classified as Configuration Items (CIs), what is the most important criterion to consider?
- The physical location of the asset within the data center.
- The total purchase cost of the asset.
- The asset's necessity for the delivery of one or more IT services. (Correct answer)
- The age of the asset and its depreciation schedule.
Correct answer: The asset's necessity for the delivery of one or more IT services.
The primary purpose of configuration management in a service management context is to manage the components necessary for service delivery. Therefore, an asset is designated as a CI because it is a component of a service and needs to be controlled to deliver that service effectively. Cost, location, and age can be attributes of a CI, but the fundamental criterion for its inclusion is its role in service delivery.
Question 4: Which of the following is a primary objective of the Release and Deployment Management process as defined within the ISO 20000 framework?
- To invent and develop new features for services.
- To negotiate and agree upon Service Level Agreements (SLAs).
- To investigate the root cause of incidents that occur after a release.
- To build, test, and deliver new or changed services into the live environment while protecting its integrity. (Correct answer)
Correct answer: To build, test, and deliver new or changed services into the live environment while protecting its integrity.
The core purpose of Release and Deployment Management is to provide a structured approach for moving new or changed hardware, software, documentation, and other components into the live environment. This includes building, testing, and deploying the release package in a controlled manner to ensure the integrity and availability of existing services are not compromised. Problem Management investigates root causes, SLM negotiates SLAs, and service design/strategy handles new features.
Question 5: A service provider is pursuing ISO 20000 certification. An internal audit finds that while service desk staff are technically skilled, they are unaware of the organization's service management policy and how their individual roles contribute to achieving the service management objectives. This finding represents a non-conformance with which support process requirement?
- Management of documented information.
- Competence, awareness, and communication. (Correct answer)
- Budgeting and accounting for services.
- Control of parties involved in the service lifecycle.
Correct answer: Competence, awareness, and communication.
ISO 20000-1, clauses 7.2 (Competence) and 7.3 (Awareness), require that the organization determines the necessary competence for personnel and ensures they are aware of the service management policy, their contribution to the SMS's effectiveness, and the implications of not conforming. The scenario directly describes a lack of awareness, which falls under these requirements.
Question 6: According to ISO 20000-1, when a customer is responsible for operating a part of a service (e.g., managing user access on their own systems), what is the service provider's responsibility regarding that process?
- The service provider has no responsibility as the process is operated by the customer.
- To ensure that the customer-operated process is controlled and integrated with the provider's own Service Management System. (Correct answer)
- To document the customer's process and formally accept all associated risks without oversight.
- To perform a mandatory annual audit of the customer's internal control environment.
Correct answer: To ensure that the customer-operated process is controlled and integrated with the provider's own Service Management System.
ISO 20000-1, clause 8.3 'Control of parties involved in the service lifecycle,' requires the organization to control processes or parts of processes that are operated by other parties, including customers. The service provider must ensure these external processes meet its own SMS requirements, are managed, and are integrated appropriately. Ignoring the process or just accepting the risk is not sufficient. A mandatory annual audit is not prescribed by the standard, although some form of monitoring is required.
According to ISO 20000-1, when managing documented information for the Service Management System (SMS), which of the following controls is explicitly required for its creation and updating?