ISO 20000 Certification Change Management 4 — Questions and Answers
Question 1: ISO 20000-1 requires that the change management process address changes to which scope?
- All services, infrastructure, and supporting components within the SMS (Correct answer)
- Only production hardware and servers
- Externally-sourced software only
- Financial and contractual documents only
Correct answer: All services, infrastructure, and supporting components within the SMS
ISO 20000 change management covers all components of the service management system (SMS) including services, tools, and supporting infrastructure.
Question 2: An organization identifies that multiple failed changes originated from the same root cause. Which ISO 20000 process should be engaged to address the underlying issue?
- Problem management (Correct answer)
- Incident management
- Release management
- Service continuity management
Correct answer: Problem management
Problem management investigates root causes of repeated failures, including those triggered by changes, to prevent recurrence.
Question 3: Which element MUST a standard change have before it can be implemented without going through the full change authorization process?
- Pre-approval based on a documented, low-risk procedure (Correct answer)
- Approval from the CTO for each instance
- A full risk assessment completed at submission
- A CAB meeting scheduled within 48 hours
Correct answer: Pre-approval based on a documented, low-risk procedure
Standard changes are pre-approved because they follow a documented, tested procedure with known low risk, eliminating the need for case-by-case authorization.
Question 4: ISO 20000 requires change records to be retained. What is the PRIMARY reason for keeping historical change records?
- To support trend analysis, audits, and future change decisions (Correct answer)
- To satisfy financial reporting requirements
- To automatically populate the service catalog
- To generate incident tickets for past failures
Correct answer: To support trend analysis, audits, and future change decisions
Historical change records enable trend analysis to detect recurring issues, support audits, and inform better future change decisions.
Question 5: During an ISO 20000 audit, an assessor asks for evidence that changes are evaluated before authorization. Which artifact BEST satisfies this requirement?
- Completed change records showing risk assessment and approval signatures (Correct answer)
- A list of all CIs in the CMDB
- Incident logs from the past quarter
- The service level agreement with the customer
Correct answer: Completed change records showing risk assessment and approval signatures
Completed change records with risk assessments and approval evidence directly demonstrate the evaluation and authorization steps required by ISO 20000.
Question 6: What distinguishes an emergency change from a normal change in ISO 20000?
- It requires expedited authorization due to an immediate threat to service (Correct answer)
- It does not require a change record
- It bypasses testing entirely
- It is approved only by the service desk
Correct answer: It requires expedited authorization due to an immediate threat to service
Emergency changes follow an accelerated authorization path because an immediate risk to service exists, but they still require a change record.
Question 7: ISO 20000 change management requires communication of upcoming changes. Who are the PRIMARY recipients of this communication?
- Stakeholders and affected parties, including customers and users (Correct answer)
- Only internal IT staff
- Regulators and government bodies
- The service provider's board of directors
Correct answer: Stakeholders and affected parties, including customers and users
ISO 20000 requires communicating planned changes to all affected stakeholders, which includes customers and end users who may be impacted.
ISO 20000-1 requires that the change management process address changes to which scope?