Incident management, priority and major incidents
Incident management in detail: what restoring service quickly actually means, how the order of work is decided when several incidents are open at once, and why major incidents get a procedure of their own.
Lesson 1 of 12 in objective 7. Seven ITIL practices in detail, part of ITIL 4 Foundation.
What the practice is trying to achieve
Incident management exists to keep the damage an incident does as small as it can be, by getting normal operation back quickly. Speed of RESTORATION is the objective, and understanding the cause is not part of it. A workaround that gets users working again, with the cause still unknown, is a completely successful incident resolution, and any option that makes root cause a condition of closing an incident belongs to a different practice.
The definition to keep alongside it: an incident is an interruption nobody planned, or a fall in the quality of a service. Degradation counts, which is why "the service is much slower than usual" is an incident and not a request.
Deciding what to work on first
When several incidents are open, the order is decided by an agreed classification scheme so that the ones with the highest business impact are worked first. The two words carrying the weight are AGREED and IMPACT. Not first-come-first-served, not whichever user shouts loudest, not the one that looks technically most interesting — a scheme settled in advance, applied consistently.
That is also why the categorisation applied when an incident is logged matters beyond tidiness: it is what feeds the prioritisation and, separately, what routes the incident to the right team.
Swarming, and major incidents
Swarming is the technique where several specialists from different teams work an incident together at the same time, and once the right person to carry on has become obvious, the others step away. It is worth knowing by name and worth contrasting with tiered escalation, which passes an incident from one level to the next in sequence. Swarming brings the expertise to the incident; escalation moves the incident to the expertise.
Major incidents get a separate procedure because they need shorter timescales and greater urgency than the normal path can deliver, and they are often handled by a dedicated temporary team assembled for the purpose. Note the reason the exam wants: it is about urgency and timescale, not about the incident being technically harder, and the separate procedure is agreed in advance rather than invented during the outage.
Worth carrying in
- Incident management
- Damage kept small by getting normal operation back fast.
- Incident
- An interruption nobody planned, or a fall in service quality.
- Prioritisation
- By an agreed classification scheme, highest business impact first.
- Swarming
- Several specialists work it together, then all but one step away.
- Major incident
- Shorter timescales, greater urgency, often a dedicated temporary team.
What the exam does with this
- Restoring service is the goal; finding the cause is not. A workaround with the cause unknown is a successful resolution.
- Prioritisation is by an agreed scheme and business impact — never by arrival order or by who is complaining.
- Swarming pulls people to the incident; escalation pushes the incident to people. Questions describe the behaviour, not the name.
- Major incidents are separated for urgency and timescale, and their procedure is agreed in advance.
- Objective
- 7. Seven ITIL practices in detail
- Share of the exam
- 47.5% (the whole objective)
- Questions in this lesson
- 5
- Signed for by a person
- 0
Partly checked. None of the 5 questions here has been read against the cited source by a person. 5 questions have been checked against their cited clause by an automated pass — which is not the same thing, and is not a signature.
Only questions a person has signed for are used in mock exams here. That is the whole difference between the two kinds of checking above.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
Drill this lesson
A lesson is one sitting: the trainer draws a short run from these questions alone and spaces the ones you get wrong.
Practise Incident management, priority and major incidents
Questions in this lesson
- Which statement best describes what the incident management practice is intended to achieve? machine-checked
- How is an incident defined in ITIL? machine-checked
- Several incidents are open at once and the support team must decide which to work on first. On what basis should the order be decided? machine-checked
- A difficult incident is worked on by pulling several specialists from different teams into the same session at the same time; once it becomes clear who is best placed to continue, the others step away. What is this technique called? machine-checked
- Why does an organisation define a separate procedure for major incidents rather than handling them exactly like all other incidents? machine-checked
Practise Incident management, priority and major incidents
The rest of objective 7
- Incident management, priority and major incidents — you are here
- Incident records, escalation and service requests
- Requests versus incidents, and finding problems
- Workarounds, known errors and problem control
- Change enablement and the three types of change
- Change authorities and the change schedule
- Authorisation routes and what a service desk is
- Service desk channels and user experience
- Service level agreements and honest targets
- Measurement, engagement and underpinning agreements
- Continual improvement and its model
- Who improves, which principles apply, and the value chain