ISO 20000 Certification ISO 20000 Service Delivery Processes 1 — Questions and Answers
Question 1: What is the primary purpose of availability management within ISO 20000 service delivery processes?
- To restore services as quickly as possible following a major outage
- To plan, monitor, measure, and improve agreed service availability to meet business requirements (Correct answer)
- To document all unplanned outages and assign responsibility for each failure
- To establish financial penalties when availability targets are breached
Correct answer: To plan, monitor, measure, and improve agreed service availability to meet business requirements
Availability management in ISO 20000 is a proactive process focused on planning, monitoring, and continually improving service availability so that agreed targets defined in SLAs can be consistently met.
Question 2: Under ISO 20000, which statement best describes a key requirement of information security management as part of service delivery?
- All security incidents must be reported to external regulators within 24 hours
- Security controls must be selected and implemented based on the results of a risk assessment (Correct answer)
- Encryption must be applied to all service-related data regardless of its classification level
- Independent third-party security audits must be conducted on a monthly basis
Correct answer: Security controls must be selected and implemented based on the results of a risk assessment
ISO 20000 requires that security controls be proportionate and justified by risk assessment results, ensuring a risk-based rather than blanket approach to information security within service delivery.
Question 3: In ISO 20000, what must an organization establish as part of budgeting and accounting for IT services?
- A publicly accessible breakdown of all IT service costs for customer transparency
- A mandatory charge-back model that bills business units for every IT service consumed
- Policies and procedures for budgeting, cost allocation, and financial control of IT services (Correct answer)
- An externally certified financial management team to oversee all IT expenditure
Correct answer: Policies and procedures for budgeting, cost allocation, and financial control of IT services
ISO 20000 requires organizations to establish documented policies and procedures for budgeting and accounting so that costs are tracked, allocated, and managed — but does not mandate a specific charge-back or external certification model.
Question 4: According to ISO 20000, what should formally trigger a review of an existing Service Level Agreement (SLA)?
- Only when a customer lodges a formal complaint about service performance
- Significant changes to services or business requirements, or at pre-defined planned intervals (Correct answer)
- Whenever any single minor incident causes a measurable drop in service metrics
- Exclusively during the organization's annual ISO 20000 recertification audit
Correct answer: Significant changes to services or business requirements, or at pre-defined planned intervals
ISO 20000 requires SLAs to be reviewed when there are material changes to the service or business needs, and also at planned intervals, ensuring agreements remain current and reflective of actual service capabilities.
Question 5: How does ISO 20000 specify that service continuity plans must be tested?
- Continuously through automated monitoring tools integrated into the ITSM platform
- At planned intervals defined by the organization to verify their effectiveness (Correct answer)
- Only when an actual disaster or major service failure occurs
- Annually on a fixed date set by the certification body
Correct answer: At planned intervals defined by the organization to verify their effectiveness
ISO 20000 requires testing of service continuity plans at planned intervals, leaving organizations to define their own appropriate frequency and test types — the standard does not prescribe a fixed annual schedule or restrict testing to real events.
Question 6: In ISO 20000, how does capacity management support service level management within service delivery processes?
- Capacity management operates as a standalone process with no formal connection to service levels
- Capacity management provides input and analysis to ensure that service level targets can realistically be met (Correct answer)
- Service level management absorbs capacity management responsibilities for organizations with fewer than 50 staff
- Capacity data feeds exclusively into service continuity plans and has no bearing on SLA commitments
Correct answer: Capacity management provides input and analysis to ensure that service level targets can realistically be met
ISO 20000 positions capacity management as a key enabler of service level management — capacity data, forecasting, and planning directly inform whether service level targets are achievable and sustainable over time.
What is the primary purpose of availability management within ISO 20000 service delivery processes?