ISO 20000 Certification Change Management 5 — Questions and Answers
Question 1: A change to a critical database is being planned. ISO 20000 requires that this change be tested. In which environment should testing occur BEFORE deployment to production?
- A test or non-production environment that mirrors production (Correct answer)
- The production environment during off-peak hours
- The development workstation of the requester
- Any available spare server
Correct answer: A test or non-production environment that mirrors production
ISO 20000 requires testing in a controlled, non-production environment that represents production conditions to minimize risk.
Question 2: Which of the following BEST describes the relationship between change management and release management in ISO 20000?
- Change management authorizes changes; release management plans and deploys them (Correct answer)
- Release management authorizes changes; change management deploys them
- They are the same process with different names
- Release management replaces change management for software updates
Correct answer: Change management authorizes changes; release management plans and deploys them
ISO 20000 treats change management as the authorization gate and release management as the deployment mechanism, and they work in sequence.
Question 3: An ISO 20000-compliant organization notices that the number of unauthorized changes is increasing. What is the MOST appropriate corrective action?
- Review and strengthen the change management procedure and enforcement controls (Correct answer)
- Hire additional IT staff to handle more changes
- Remove low-priority changes from the backlog
- Extend the change freeze period
Correct answer: Review and strengthen the change management procedure and enforcement controls
Increasing unauthorized changes indicate a process control failure; strengthening the procedure and its enforcement is the root-cause corrective action.
Question 4: Under ISO 20000, which document defines the criteria and authority levels for approving changes of different risk levels?
- Change management policy (Correct answer)
- Service level agreement
- Supplier contract
- Incident escalation matrix
Correct answer: Change management policy
The change management policy establishes who can authorize changes at each risk level and the criteria for categorization.
Question 5: A service provider must demonstrate continual improvement of its change management process. Which ISO 20000 activity supports this?
- Regular review of change management KPIs and trend analysis to identify improvements (Correct answer)
- Increasing the number of standard changes pre-approved
- Reducing the number of CAB members to speed decisions
- Outsourcing the change approval process to a supplier
Correct answer: Regular review of change management KPIs and trend analysis to identify improvements
Continual improvement requires measuring performance through KPIs and using trend analysis to identify and act on opportunities to improve the process.
Question 6: ISO 20000 requires that all changes be logged. What is the MINIMUM information that should be captured in a change record at initiation?
- Description of the change, requester, reason, and initial risk assessment (Correct answer)
- Final approval signature and deployment date
- Post-implementation review findings
- Configuration items affected after deployment
Correct answer: Description of the change, requester, reason, and initial risk assessment
At initiation, a change record must capture enough information to assess and evaluate the change, including what it is, why it is needed, who requested it, and an initial risk assessment.
Question 7: Which scenario represents a violation of ISO 20000 change management requirements?
- A technician deploys a server patch directly to production without raising a change request (Correct answer)
- A CAB meeting is held to review a high-risk change before approval
- An emergency change is documented after implementation
- A standard change is implemented using a pre-approved procedure
Correct answer: A technician deploys a server patch directly to production without raising a change request
Deploying without a change request bypasses the authorization and tracking requirements of ISO 20000 change management, making it a clear violation.
A change to a critical database is being planned.
ISO 20000 requires that this change be tested.
In which environment should testing occur BEFORE deployment to production?