Security, incidents, problems and requests

The definitions the rest of the paper is built on — incident, problem, known error, workaround and service request — and the routing test that decides which practice a described situation belongs to.

Lesson 2 of 3 in objective 6. Purpose and key terms of 15 ITIL practices, part of ITIL 4 Foundation.

The routing test: three practices, three different triggers. Incident — What happened: Something failed unexpectedly; Agreed in advance?: No; Success looks like: Service restored, fast. Service request — What happened: Somebody asked for a normal thing; Agreed in advance?: Yes, it is pre-defined; Success looks like: Fulfilled to the agreed target. Problem — What happened: Something keeps failing, or might; Agreed in advance?: No; Success looks like: Cause understood and managed Incident Service request Problem What happened Something failed unexpectedly Somebody asked for a normal thing Something keeps failing, or might Agreed in advance? No Yes, it is pre-defined No Success looks like Service restored, fast Fulfilled to the agreed target Cause understood and managed
The routing test: three practices, three different triggers.

Incident and problem, and the words that decide them

An incident is an interruption nobody planned, or a fall in the quality of a service. Both halves count, and the second is the one candidates forget when sorting a scenario: a service that has gone slow has had an incident just as surely as one that has stopped.

A problem is a cause, or a POTENTIAL cause, of one or more incidents. That second word carries real weight and is worth more than one mark across a paper: a problem can be identified before any incident has happened at all, which is why problem management includes proactive work and why "a problem is what caused an incident" is an incomplete answer offered as a distractor.

Known error and workaround

A known error is what a problem becomes once it has been analysed and still has no permanent fix. The trigger for the reclassification is the ANALYSIS, not any repair and not the existence of a workaround — a problem becomes a known error the moment it is understood, whether or not anything has been done about it.

A workaround is a way of holding down the damage an incident or a problem is doing while no permanent resolution exists yet. It is an action or a solution rather than a record. In the standard scenario — the cause is understood, no permanent fix exists, and restarting a service every morning keeps people working — the analysed problem is the known error and the morning restart is the workaround. Getting both labels onto the right halves is the whole question.

Two records and one measure, told apart by what is known and what is fixed. Problem — What it is: A cause, or a potential cause, of incidents; Cause known?: Not yet; Service restored?: Not by itself. Known error — What it is: A problem that has been analysed; Cause known?: Yes; Service restored?: Not necessarily. Workaround — What it is: A way to reduce the impact; Cause known?: Not required; Service restored?: Yes, without a fix Problem Known error Workaround What it is A cause, or a potential cause, of incidents A problem that has been analysed A way to reduce the impact Cause known? Not yet Yes Not required Service restored? Not by itself Not necessarily Yes, without a fix
Two records and one measure, told apart by what is known and what is fixed.

Problem management, information security, and requests

Problem management exists to make incidents both less likely and less damaging, by finding the causes behind them — actual and potential alike — and by keeping workarounds and known errors under active management. Note that managing workarounds and known errors is part of the PURPOSE, not an incidental activity — a purpose statement that stops at "find root causes" is missing half of it.

Information security management protects the information the organisation needs to conduct its business — keeping it from being disclosed, altered or lost, and available when it should be. When a question asks for a single practice to own confidentiality, integrity and availability of business data, this is it.

Service request management handles pre-defined, user-initiated requests that are a normal, agreed part of service delivery. A user asking for an additional licensed application that the organisation already offers is a request, not an incident: nothing has failed, and the thing being asked for was agreed in advance. That "agreed in advance" test is the one that separates requests from everything else.

Which words in a stem hand the question to which practice. Left column, What the question describes; right column, The practice that owns it. Fewer incidents, and less damage when they land and Workarounds and known errors under active management both point at Problem management (A purpose that stops at finding root causes is missing half). Confidentiality, integrity and availability of data and Guard the information the business runs on both point at Information security management (A single practice owns all three, not one each). Nothing has failed; it was asked for and pre-agreed and A user asks for another licensed app already on offer both point at Service request management (Agreed in advance is what separates a request from everything else). What the question describes The practice that owns it Fewer incidents, and less damage when they land Workarounds and known errors under active management Problem management A purpose that stops at finding root causes is missing half Confidentiality, integrity and availability of data Guard the information the business runs on Information security management A single practice owns all three, not one each Nothing has failed; it was asked for and pre-agreed A user asks for another licensed app already on offer Service request management Agreed in advance is what separates a request from everything else
Which words in a stem hand the question to which practice.

Worth carrying in

Incident
An interruption nobody planned, OR degraded quality. Both count.
Problem
A cause, or a POTENTIAL cause, of one or more incidents.
Known error
An analysed problem still awaiting a permanent fix. Analysis is the trigger.
Workaround
Reduces or removes impact while no full resolution exists. An action, not a record.
Problem management
Fewer and smaller incidents, by finding causes and managing workarounds and known errors.
Information security management
Protects business information from disclosure, alteration and loss.
Service request management
Pre-defined, user-initiated requests that are normal service delivery.

What the exam does with this

Objective
6. Purpose and key terms of 15 ITIL practices
Share of the exam
12.5% (the whole objective)
Questions in this lesson
5
Signed for by a person
0

Partly checked. None of the 5 questions here has been read against the cited source by a person. 5 questions have been checked against their cited clause by an automated pass — which is not the same thing, and is not a signature.

Only questions a person has signed for are used in mock exams here. That is the whole difference between the two kinds of checking above.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

Drill this lesson

A lesson is one sitting: the trainer draws a short run from these questions alone and spaces the ones you get wrong.

Practise Security, incidents, problems and requests

Questions in this lesson

Practise Security, incidents, problems and requests

The rest of objective 6