Security, incidents, problems and requests
The definitions the rest of the paper is built on — incident, problem, known error, workaround and service request — and the routing test that decides which practice a described situation belongs to.
Lesson 2 of 3 in objective 6. Purpose and key terms of 15 ITIL practices, part of ITIL 4 Foundation.
Incident and problem, and the words that decide them
An incident is an interruption nobody planned, or a fall in the quality of a service. Both halves count, and the second is the one candidates forget when sorting a scenario: a service that has gone slow has had an incident just as surely as one that has stopped.
A problem is a cause, or a POTENTIAL cause, of one or more incidents. That second word carries real weight and is worth more than one mark across a paper: a problem can be identified before any incident has happened at all, which is why problem management includes proactive work and why "a problem is what caused an incident" is an incomplete answer offered as a distractor.
Known error and workaround
A known error is what a problem becomes once it has been analysed and still has no permanent fix. The trigger for the reclassification is the ANALYSIS, not any repair and not the existence of a workaround — a problem becomes a known error the moment it is understood, whether or not anything has been done about it.
A workaround is a way of holding down the damage an incident or a problem is doing while no permanent resolution exists yet. It is an action or a solution rather than a record. In the standard scenario — the cause is understood, no permanent fix exists, and restarting a service every morning keeps people working — the analysed problem is the known error and the morning restart is the workaround. Getting both labels onto the right halves is the whole question.
Problem management, information security, and requests
Problem management exists to make incidents both less likely and less damaging, by finding the causes behind them — actual and potential alike — and by keeping workarounds and known errors under active management. Note that managing workarounds and known errors is part of the PURPOSE, not an incidental activity — a purpose statement that stops at "find root causes" is missing half of it.
Information security management protects the information the organisation needs to conduct its business — keeping it from being disclosed, altered or lost, and available when it should be. When a question asks for a single practice to own confidentiality, integrity and availability of business data, this is it.
Service request management handles pre-defined, user-initiated requests that are a normal, agreed part of service delivery. A user asking for an additional licensed application that the organisation already offers is a request, not an incident: nothing has failed, and the thing being asked for was agreed in advance. That "agreed in advance" test is the one that separates requests from everything else.
Worth carrying in
- Incident
- An interruption nobody planned, OR degraded quality. Both count.
- Problem
- A cause, or a POTENTIAL cause, of one or more incidents.
- Known error
- An analysed problem still awaiting a permanent fix. Analysis is the trigger.
- Workaround
- Reduces or removes impact while no full resolution exists. An action, not a record.
- Problem management
- Fewer and smaller incidents, by finding causes and managing workarounds and known errors.
- Information security management
- Protects business information from disclosure, alteration and loss.
- Service request management
- Pre-defined, user-initiated requests that are normal service delivery.
What the exam does with this
- An incident includes degradation, not only outage. "Noticeably slower than usual" is an incident.
- The word POTENTIAL in the problem definition is examined. A problem can exist before any incident has.
- A known error is created by analysis, not by a fix or by a workaround being found.
- Pre-defined and agreed in advance is what makes something a service request. Nothing has failed.
- Objective
- 6. Purpose and key terms of 15 ITIL practices
- Share of the exam
- 12.5% (the whole objective)
- Questions in this lesson
- 5
- Signed for by a person
- 0
Partly checked. None of the 5 questions here has been read against the cited source by a person. 5 questions have been checked against their cited clause by an automated pass — which is not the same thing, and is not a signature.
Only questions a person has signed for are used in mock exams here. That is the whole difference between the two kinds of checking above.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
Drill this lesson
A lesson is one sitting: the trainer draws a short run from these questions alone and spaces the ones you get wrong.
Practise Security, incidents, problems and requests
Questions in this lesson
- An organization wants a single practice to own keeping the data its business runs on safe from disclosure, tampering and loss. Which practice is that? machine-checked
- Which pair correctly matches the ITIL 4 definitions of 'incident' and 'problem'? machine-checked
- A problem has been investigated and its cause is now understood, but no permanent fix has been implemented. Meanwhile, restarting a service every morning keeps users working. Which terms apply? machine-checked
- Which statement best describes the purpose of the problem management practice? machine-checked
- A user asks for an additional licensed application to be installed on their laptop. This is a standard, pre-approved offering listed in the service catalogue. Which practice should handle it, and why? machine-checked
Practise Security, incidents, problems and requests
The rest of objective 6
- Release, deployment, change, suppliers and events
- Security, incidents, problems and requests — you are here
- Service desk, configuration, assets and relationships