IT Service Management Frameworks for Operations
Understand major ITSM frameworks including ITIL and how they guide IT operations. Essential knowledge for CISA exam preparation.
Overview of IT Service Management
IT Service Management (ITSM) encompasses the policies, processes, and procedures that organizations use to design, deliver, manage, and improve IT services. For CISA candidates, understanding ITSM frameworks is important because they provide the structure against which IT operations are audited.
ITIL Framework
The Information Technology Infrastructure Library (ITIL) is the most widely adopted ITSM framework. It provides a comprehensive set of best practices organized around the IT service lifecycle:
- Service Strategy: Defines how IT services align with business objectives. Key processes include service portfolio management and financial management for IT services.
- Service Design: Covers the design of new or changed services. Processes include service level management, capacity management, availability management, and IT service continuity management.
- Service Transition: Manages the deployment of new or changed services into production. Key processes include change management, release management, and configuration management.
- Service Operation: Focuses on day-to-day management of IT services. Includes incident management, problem management, event management, and request fulfillment.
- Continual Service Improvement: Drives ongoing improvements to IT services and processes using measurement and analysis.
Other ITSM Frameworks
While ITIL is dominant, other frameworks contribute to IT service management:
- COBIT: Developed by ISACA, COBIT provides a governance framework that helps organizations align IT with business goals. It is particularly relevant for auditors because it defines control objectives for IT processes.
- ISO/IEC 20000: An international standard for IT service management that specifies requirements for establishing, implementing, maintaining, and improving a service management system.
- MOF (Microsoft Operations Framework): Provides guidance for achieving reliability, availability, and manageability of IT solutions built on Microsoft technologies.
Service Level Agreements
A critical component of ITSM is the Service Level Agreement (SLA). SLAs define the expected level of service between the IT provider and the business. Key elements include availability targets, response times, resolution times, and performance metrics. Auditors should verify that SLAs are documented, measurable, monitored, and reported on regularly.
Audit Implications
IS auditors evaluate whether ITSM processes are documented, consistently followed, and aligned with business requirements. Key audit areas include change management effectiveness, incident response times versus SLA targets, and the maturity of problem management processes.
CISA Exam Tips
For the CISA exam, focus on understanding the purpose of each ITIL lifecycle stage and how key processes relate to IT operations. Know that COBIT is ISACA's own framework and emphasizes governance and control objectives. Questions may ask you to identify which ITSM process is most appropriate for a given scenario or to evaluate whether an organization's ITSM practices are adequate.