HW 3
Quality in IT - ITIL
Session 8 – Executive session
Five Books
Service Strategy
Service Design
Service Transition
Service Operation
Continual Service Improvement
Five Books
Service Strategy
Service Design
Service Transition
Service Operation
Continual Service Improvement
ITIL Framework
ITIL Framework
Knowledge Management
Service Asset & Configuration Management
Change Management
Release Management
Change Evaluation
Service Validation & Testing
Service Transition Book
Overview & Introduction
Service Transition Book
Plan and manage the capacity and resources required to package, build, test and deploy a release into production
Provide a consistent and rigorous framework for evaluating the service capability and risk profile before a new or changed service is released
Establish and maintain the integrity of all identified service assets and configurations
Establish and maintain the integrity of all identified service assets and configurations
Provide good quality knowledge and information to expedite effective decisions about promoting a release
Provide efficient, repeatable build and installation mechanisms to deploy releases to test and production
Ensure that the service can be managed, operated and supported in accordance with service design
The goals of service transition
“Aligning the new or changed service with the organizational requirements and organizational operations”
Service Transition Book
The ability to adapt quickly to new requirements
The success rate of changes and releases for the organization
The predictions of service levels and warranties for new and changed services
Confidence in the degree of compliance with the organization requirements during change
Clarity of plans so the business can link their organization change plans to transition plans
Value to the organization
Service Transition Book
The scope of service transition includes the management and coordination of the processes, systems and functions to package, build, test and deploy a release into production and establish the service specified in the customer and stakeholder requirements.
The following activities are excluded from the scope of service transition best practices:
Minor modifications to the production services and environment, for example, replacement of a failed PC or printer, installation of standard software on a PC or server, new user
Ongoing continual service improvements that do not significantly impact the services or service provider’s capability to deliver the services, for example, request fulfilment activities driven from service operations
Scope of Service Transition
Service Transition Book
Knowledge management
Knowledge Management
An organizations ability to deliver a quality service or process rests, to a significant extent, on its ability to respond to circumstances.
To enable this to happen, those involved must have a sound understanding of the situation, the options, consequences and benefits.
An example of this knowledge in the service transition phase may include:
Identity of stakeholders
Acceptable risk levels and performance expectations
Available resource and timescales
Why have it?
Knowledge Management
“The goal of knowledge management is to enable organizations to improve the quality of management decision-making by ensuring that reliable and secure information and data is available throughout the service lifecycle”
The primary purpose is to improve efficiency by reducing the need to rediscover knowledge.
This is achieved by:
Enabling the service provider to be more efficient and improve the quality of the service, reduce costs, increase satisfaction
Ensuring staff have a clear and shared understanding of the value that their services provide to customers and how they are realized
(continued…)
The objectives of knowledge management
Knowledge Management
Ensuring that, as required, service provider staff have adequate information on –
Who is currently using the service they are providing
The current states of consumption
Service delivery constraints
Difficulties faced by customers, realizing the expected benefits from services
Knowledge Management
The diagram is a very simplified illustration of the relationship of the three levels, with data being gathered within the CMDB, and feeding through the CMS into the SKMS as information to support the informed decision making process.
Knowledge Management
Knowledge management is especially significant within service transition since relevant and appropriate knowledge is one of the key service elements being transitioned.
Examples where successful transition rests on appropriate knowledge management include:
User, service desk, support staff and supplier understanding of the new or changed service, …
…including knowledge of errors signed off before deployment, to facilitate their roles within that service
Awareness of the use of the service, and the discontinuation of previous versions
Establishment of the acceptable risk and confidence levels associated with the transition, e.g. measuring, understanding and acting correctly on results of testing and other assurance results
Values to the organization
Effective knowledge management is a powerful asset for people in all roles across all stages of the service lifecycle. It is an excellent method for individuals and teams to share data, information and knowledge about all facets of an IT service. The creation of a single system for knowledge management is recommended.
Knowledge Management
Knowledge identification capture and maintenance – Specifically knowledge management will identify and plan for the capture of relevant knowledge and the consequential information and data that will support it.
Knowledge transfer – This is the activity through which one unit (e.g. group or department) is affected by the experiences of another.
Activities
Knowledge Management
Learning styles
Knowledge visualization
Driving behavior
Seminars, webinars and advertising
Journals and newsletters
The transfer of knowledge can be observed through changes in the knowledge or performance or recipients, and at an individual or unit level.
knowledge transfer to match those who use it?
Knowledge Management
Data and information management – Knowledge rests on the management of the information and data that underpins it. For this process to be efficient it requires answers to some key input questions, such as how the data and information will be used, what conditions will need to be monitored, what data is available, what are the associated costs, legislative and requirements etc.
Establishing data and information requirements – Often, data and information is collected with no clear understanding of how it will be used and this can be costly. Efficiency and effectiveness are delivered by establishing the requirements for information.
Activities
Knowledge Management
Establishing data and information management procedures – When the requirements have been set up, data and information management to support knowledge management can be established. This will include, defining procedures required to maintain the data and information, procedures for access, storage (including backup and recovery), retrieval, rights and responsibilities etc.
Evaluation and improvement – As with all processes, the capture and use of data and information to support knowledge management and decision making requires attention to ongoing improvement.
Activities
Knowledge Management
SKMS: Service knowledge management System
CMS: Configuration Management System
KEDB: Known Error Database
DML: Definitive Media Library. The secure library in which the definitive authorised versions of all media CIs are stored and protected. The DML should include definitive copies of purchased software (along with license documents or information), as well as software developed on site
The terminology of knowledge management
Service Transition Book
Service asset and configuration management
Configuration Management
Why have service asset and configuration management
This process ensures the integrity of service assets and configurations in order to support the effective and efficient management of the IT organisation.
The main reason for configuration management is to gather the information needed (in a non-duplicated manner) about the IT components and how they relate to each other. The reason for this is to ensure that the relevant information is available for all the other processes to ensure that detailed impact and risk analysis can take place.
Configuration Management
Account for all the IT assets and configurations within the organization and its services
Provide accurate information on configurations and their documentation to support all the other service management processes
Provide a sound basis for incident management, problem management, change management and release management
Verify the configuration records against the infrastructure and correct any exceptions
Plan, identify, control, record, report, audit and verify service assets and configuration items
Account for manage and protect the integrity of service assets and configuration items throughout their lifecycle
The objectives of service asset and configuration management
Configuration Management
Provide accurate information to support business and service management
Ensure the integrity of those items by creating and maintaining an accurate Configuration Management System (CMS) as part of the Service knowledge management System (SKMS)
The objectives of service asset and configuration management
Configuration Management
Optimizing the performance of service assets and configurations improves the overall service performance and optimizes the costs and risks caused by poorly managed assets, e.g. service outages, fines, correct license fees and failed audits. SACM provides visibility of accurate representations of a service, release or environment that enables:
Better forecasting and planning of changes
Changes and releases to be assessed, planned and delivered successfully
Value to the organization of service asset and configuration management
Incidents and problems to be resolved within the service level targets
Service levels and warranties to be delivered
Better adherence to standards, legal and regulatory obligations
More business opportunities as able to demonstrate control of assets and services
Changes to be traceable from requirements
Configuration Management
Configuration management planning
A configuration management plan should define:
The purpose, scope and objectives of configuration management
Related policies, standards and processes that are specific to the support group
Configuration Management roles and responsibilities
CI (Configuration Item) naming conventions
The activities of service assets and configuration management
The schedule and procedures for performing Configuration Management activities: configuration identification, control, status accounting, configuration audit and verification
Interface control with third parties, e.g. Change Management, suppliers
Configuration management systems design, including scope and key interfaces
Configuration Management
Configuration identification
CIs are the components used to deliver a service. The CIs include software, documentation and SLA’s
Also identify the relationship between CI’s and the attributes for every CI
Control of CI’s
The objective of configuration control is to ensure that only authorized and identifiable CI’s are recorded in the CMDB upon receipt.
Configuration Management
Configuration status accounting
Status reports should be produced on a regular basis, listing, for all CI’s under control, their current version and change history. Status accounting reports on the current, previous and planned states of the CI’s should include:
Unique identifiers of constituent CI’s and their current status, e.g. under development, under test, live
Configuration baselines, releases and their status
Latest software item versions and their status for a system baseline/application
The person responsible for status change, e.g. from under test to live
Change history/audit trail
Open problems/RFC’s
Configuration Management
Configuration verification and audit
Service desk staff, while registering incidents, can do daily verification
Configuration audits should be considered at the following times:
Shortly after implementation of a new configuration management system
Before and after major changes to the IT infrastructure
Before a software release or installation to ensure that the environment is as expected
Following recovery from disasters and after a return to normal (this audit should be included in contingency plans)
Configuration Management
The goals of configuration management are to: �
Support many of the ITIL processes by providing accurate configuration information to assist decision making, e.g. the authorization of changes, the planning of releases, and to help resolve incidents and problems faster. �
Minimize the number of quality and compliance issues caused by incorrect or inaccurate configuration of services and assets
To define and control the components of services and infrastructure and maintain accurate configuration information on the historical, planned and current state of the services and infrastructure.
Configuration Management
Asset management covers service assets across the whole service lifecycle. It provides a complete inventory of assets and who is responsible for their control. It includes: �
Full lifecycle management of IT and service assets, from the point of acquisition through to disposal. �
Maintenance of the asset inventory. Configuration management ensures that selected components of a service, system or product (the configuration) are identified, baselined and maintained and that changes to them are controlled. It also ensures that releases into controlled environments and operational use are done on the basis of formal approvals. �
The scope covers interfaces to internal and external service providers where there are assets and configuration items that need to be controlled, e.g. shared assets.
Configuration Management (Value)
Optimization of the performance of service assets improves the overall service performance and optimizes the costs and risks caused by poorly managed assets, e.g. service outages, correct license fees and failed audits.
Service asset and configuration management provides visibility of accurate representations of a service, release, or environment that enables: �
Better planning of changes and releases �
Improved Incidents and problems resolution �
Service levels and warranties to be delivered �
Better adherence to standards, legal and regulatory obligations (less non-conformances) �
Changes to be traceable �
The ability to identify the costs for a service
Configuration Management
Configuration items
A configuration item (CI) is an asset, service component or other item that is, or will be, under the control of configuration management.
Configuration items may vary widely in complexity, size and type, ranging from an entire service or system including all hardware, software, documentation and support staff to a single software module or a minor hardware component.
Configuration items may be grouped and managed together, e.g. a set of components may be grouped into a release.
Configuration items should be selected using established selection criteria, grouped, classified and identified in such a way that they are manageable and traceable throughout the service lifecycle.
CMDB
“A Configuration management database (CMDB) is a repository of information related to all the components of an information system. Although repositories similar to CMDBs have been used by IT departments for many years, the term CMDB…..
CMDB
Configuration Management Database (CMDB) creates one repository of information of all your “IT” components
Note: IT Components in CMDB are called CIs – Configuration Items
CMDB
Servers
Databases
Applications
Users & Contacts
Configurations
History
CMDB
Identify existing information repository
Hardware/Software – model/versions – record
Record of Office system configurations
Asset purchase register
The shelf holding user manuals
The wardrobe holding spare hardware
Service Transition Book
Change management
Change Management
The goals of change management are to:
Standardize methods and procedures are used for efficient and prompt handling of all changes
All changes to service assets and configuration items are recorded in the Configuration Management System (CMS)
Change Management
Change is inevitable, and the rate of change in technology is increasing and the organization's processes and business models constantly have to adapt to the economic climate, competitive pressures, and the opportunity to create through change and innovation.
Change management, as a discipline in distributed computing is usually somewhat lacking. Yet, change management for IT operations is critical to improving availability, performance and throughput.
Strong operational change management reduces errors, as well as planned and unplanned downtime.
Change Management
Changes arise for a variety of reasons:
Proactively, e.g. seeking organizational benefits such as reducing costs or improving services or increasing the ease and effectiveness of support
Reactively as a means of resolving errors and adapting to changing circumstances
Change Management
The purpose of change management is to:
Respond to the customer’s changing business requirements while maximizing value and reducing incidents, disruption and rework
Respond to the business and IT requests for change that will align the services with the business needs
The objective of the change management process is to ensure that changes are recorded and then evaluated, authorized, prioritized, planned, tested, implemented, documented and reviewed in a controlled manner and take necessary corrective action
Change Management
The top five risk indicators of poor change management are:
Unauthorized changes
Unplanned outages
A low change success rate
A high number of emergency changes
Delayed project implementations
Change Management
The scope of change management
“The addition, modification or removal of authorized, planned or supported service or service component and its associated documentation.”
Change Management
Value to the business of change management
Availability of IT service is essential for any organization. Service and infrastructure changes can have a negative impact through service disruption but change management adds value to the business by:
Prioritizing and responding to business change proposals
Contributing to meet governance, legal, contractual and regulatory requirements
Reducing failed changes and therefore service disruption, defects and rework
Delivering change promptly to meet business
Change Management
Value to the business of change management
(continued… adds value to the business by: )
Contributing to better estimations of the quality, time and cost of change
Assessing the risks associated with the transition of services (introduction or disposal)
Aiding productivity of staff through minimizing disruptions due to high levels of unplanned or emergency change
Change Management
Planning the concepts of change management
Change management policies (Policies that support change management include):
Creating a culture of change management across the IT organization
Aligning the service change management process with business, project and business/ organization change management processes
Prioritization of changes
Establishing accountability/responsibilities for changes through the service lifecycle
Establishing a single focal point for changes to minimize conflicting changes and potential disruption
Preventing anyone who is not authorized to make changes from having access to the production environment
Change Management
Planning the concepts of change management-Change management policies (continued…)
Establishing change windows
Performance and risk evaluation of all changes
Performance measures for the process
Change Management
Change management process design
The change management process should be planned in conjunction with release and configuration management.
This helps to evaluate the impact of the change on the current and planned services and releases.
Change Management
Types of changes
The organization/business need to ensure that appropriate procedures are available to cover the different types of change requests.
For different change types there are specific procedures, e.g. for impact assessment and change authorization.
Standard
Normal
Emergency
Change Management
A change model
A process model is a way of predefining the steps that should be taken to handle a process (in this case a process for dealing with a particular type of change) in an agreed way. Support tools can then be used to manage the required process. This will ensure that such changes are handled in a predefined path and to predefined timescales.
These models are usually input to the change management support tools in use and the tools then automate the handling, management, reporting and escalation of the process.
Change Management
Standard changes (pre-authorized)
A standard change is a change to a service or infrastructure for which the approach is pre-authorized by change management that has an accepted and established procedure to provide a specific change requirement.
The elements of a standard change are:
There is a defined trigger to initiate the request for change
The activities/tasks are well known, documented and proven
Authority is given in advance (these changes are preauthorized
The risk is usually low
Change Management
A normal change
A normal change refers to changes that must follow the complete change management process. Normal changes are often categorized according to risk and impact to the organization/business. For example, minor change – low risk and impact, significant change – medium risk and impact and major change – high risk and impact.
By definition a normal change will proceed through all steps of the change management process and those that are categorized as medium or high risk will be reviewed by the Change Advisory Board (CAB).
Change Management
Record requests for change
Change logging
Review the request for change
Assess and evaluate the change
Evaluation of change
Allocation of priorities
Change planning and scheduling
Authorizing the change
Coordinating change implementation
Review and close change record
The activities are of the normal change process are:
Change Management
Emergency changes
Emergency change is reserved for changes intended to repair an error in an IT service that is impacting the business to a high degree or to protect the organization from a threat.
Change Management
The Change Advisory Board
The Change Advisory Board (CAB) exists to support the authorization of higher risk changes
Change Management
Change management process interfaces
Program and project management
Program and project management must work in partnership to align all the processes and people involved in service change initiatives.
Asset and configuration management
As changes are implemented, the configuration management information is updated. The Configuration Management System (CMS) may also be used to carry out risk and impact assessment for changes that are being assessed. The CMS may also related changes to particular configuration items.
Change Management
Problem management
Problem management is another key process that interacts with change management as changes are often required to implement workarounds and to fix known errors. Problem management is a major source of requests for change and also often a contributor to CAB discussion.
IT service continuity
IT service continuity has many procedures and plans should be updated via change management to ensure that they are accurate, up to date and that stakeholders are aware of changes
Change Management
Security management
Security management interfaces with change management since changes required by security will go via change management process and security will be a key contributor to CAB discussion on many services. All change will be assessed for its potential impact on the security plan.
Other processes
Most ITIL service management process have an interaction with change management either as an initiator of change via a request for change or as a member of the CAB.
Change Management
Key performance indicators and metrics for change management
The key performance indicators for change management are:
The number of changes implemented to services which met the customer’s agreed requirements, e.g. quality/ cost/time (expressed as a percentage of all changes)
Reduction in the number of disruptions to services, defects and rework caused by inaccurate specification, poor or incomplete impact assessment of changes � Reduction in the number of unauthorized changes.
Change Management
Key performance indicators and metrics for change management (Continued)
The key performance indicators for change management are:
Reduction in the number and percentage of unplanned changes and emergency fixes
Change success rate (percentage of changes deemed successful at review/number of RFCs approved)
Reduction in the number of changes where remediation is invoked
Change Management
Key performance indicators and metrics for change management (Continued)
The key performance indicators for change management are:
Reduction in the number of failed changes
Average time to implement based on urgency/priority/change type
Incidents attributable to changes
Percentage accuracy in change estimate
Change Management
Process flow for Standard Change (pre-authorized)
Change Management
Process flow for Normal Change
Change Management
Authorization
Change Management
Seven “R’s” of Change Management
Who RAISED the change
What is the REASON for the change
What is the RETURN required from the change
What are the RISKS involved in the change
What RESOURCES are required to deliver the change
Who is RESPONSIBLE for the change
What is the RELATIONSHIP between this change and other changes.