ISO 20000 Service Management System (SMS) Questions and Answers — Questions and Answers
Question 1: A service provider is implementing a Service Management System (SMS) according to ISO/IEC 20000-1. As part of the 'CHECK' phase of the Plan-Do-Check-Act (PDCA) cycle, which of the following activities is most representative?
- Implementing a new service continuity plan.
- Establishing the scope and policies for the SMS.
- Reviewing service reports against Service Level Agreement (SLA) targets. (Correct answer)
- Assigning new roles and responsibilities for the incident management process.
Correct answer: Reviewing service reports against Service Level Agreement (SLA) targets.
The 'CHECK' phase of the PDCA cycle involves monitoring, measuring, and reviewing the SMS and services against policies, objectives, and service requirements. Reviewing service reports to compare performance against agreed SLA targets is a core activity of this phase. Establishing scope is 'PLAN', implementing plans is 'DO', and assigning roles could be part of 'PLAN' or 'DO'.
Question 2: An organization wants to demonstrate its capability to consistently design, transition, deliver, and improve services that fulfill service requirements. Which part of the ISO/IEC 20000 standard specifies the requirements for a Service Management System (SMS) to achieve this?
- ISO/IEC 20000-2
- ISO/IEC 20000-1 (Correct answer)
- ISO/IEC 20000-3
- ISO/IEC 20000-10
Correct answer: ISO/IEC 20000-1
ISO/IEC 20000-1 is the part of the standard that specifies the mandatory requirements for an organization to establish, implement, maintain, and continually improve a Service Management System (SMS). Organizations can be formally audited and certified against this part. ISO/IEC 20000-2 provides guidance on the application of an SMS, and other parts provide further guidance or relate to other frameworks.
Question 3: A financial services company is defining its Service Continuity and Availability Management plans as part of its ISO 20000-compliant SMS. Which of the following is a mandatory requirement for this process group?
- Guaranteeing 100% availability for all services.
- Testing the service continuity plan only after a major incident has occurred.
- Implementing the most expensive technology for disaster recovery.
- Assessing and documenting risks to the continuity and availability of services. (Correct answer)
Correct answer: Assessing and documenting risks to the continuity and availability of services.
According to ISO/IEC 20000-1, the service provider is required to assess and document the risks to service continuity and availability. Based on this risk assessment, requirements are agreed upon and plans are created, maintained, and tested. Guaranteeing 100% availability is often unrealistic, plans must be tested proactively, and solutions should be risk-based, not necessarily the most expensive.
Question 4: Within the context of an ISO 20000 Service Management System, what is the primary purpose of the Information Security Management process?
- To manage the physical security of the data center.
- To ensure all employees receive annual cybersecurity awareness training.
- To effectively manage information security risks and implement controls within the scope of the SMS. (Correct answer)
- To select and deploy antivirus software on all company workstations.
Correct answer: To effectively manage information security risks and implement controls within the scope of the SMS.
The Information Security Management process within ISO 20000 is focused on managing information security holistically within the scope of the services being delivered. This involves establishing a policy, assessing risks, and implementing necessary controls to protect the confidentiality, integrity, and availability of information. While physical security, training, and antivirus software are potential controls, the primary purpose is the overall management of security based on risk.
Question 5: A company has successfully implemented an SMS and achieved ISO 20000 certification. To maintain this certification, the company must demonstrate a commitment to continual improvement. Which of the following activities BEST demonstrates this principle?
- Maintaining the same service level targets year after year.
- Conducting a management review of the SMS only when a major nonconformity is found.
- Analyzing trends in service performance and identifying opportunities for enhancement. (Correct answer)
- Keeping all service management processes and documentation unchanged after the initial audit.
Correct answer: Analyzing trends in service performance and identifying opportunities for enhancement.
Continual improvement is a core principle of ISO 20000, driven by the PDCA cycle. Analyzing trends, reviewing performance, and proactively identifying opportunities for improvement are key activities that demonstrate an ongoing commitment to enhancing the SMS and service delivery. The other options suggest a static or reactive approach, which is contrary to the principle of continual improvement.
Question 6: Which of the following is a key output of the Service Level Management process in an ISO 20000-compliant SMS?
- A list of all IT assets and their configurations.
- The root cause analysis of a major problem.
- A Service Level Agreement (SLA) agreed upon with the customer.
- A schedule of all planned infrastructure changes for the next quarter. (Correct answer)
Correct answer: A schedule of all planned infrastructure changes for the next quarter.
The Service Level Management process is responsible for negotiating and agreeing on achievable service level targets with customers and documenting them in Service Level Agreements (SLAs). It also involves monitoring and reporting on service performance against these targets. A list of assets belongs to Configuration Management, root cause analysis to Problem Management, and change schedules to Change Management.
A service provider is implementing a Service Management System (SMS) according to ISO/IEC 20000-1.
As part of the 'CHECK' phase of the Plan-Do-Check-Act (PDCA) cycle, which of the following activities is most representative?