IT governance and management

IT Service Management System (SMS)

We support the implementation of Service Management Systems based on ISO/IEC 20000-1, the standard that formalises how technology services are designed, delivered and improved.

Typical duration
8 to 12 months
Delivery
Blended — on site and remote
Support
SORT Redmine included
Integrates with
ISO/IEC 27001

Objective and scope

ISO/IEC 20000-1 brings to IT services the same logic of management, measurement and continual improvement that ISO/IEC 27001 brings to security. We implement the service catalogue and service levels, incident and problem management, change and release, capacity and availability, and the customer and supplier relationship cycle — all supported by SORT Redmine.


Project phases

Phase 1

SMS gap assessment

We review services, processes, tools and current agreements, and measure the gap against the requirements of ISO/IEC 20000-1.

Phase 2

Design and implementation

We define the service catalogue, service level agreements, and the incident, problem, change, release, capacity, availability and service continuity processes.

Phase 3

Competence and tooling

We train the teams and configure SORT Redmine as the system of record, workflow and measurement for the processes defined.

Phase 4

Audits and certification

Independent internal audit, handling of findings and support through to the certification audit.


What the implementation includes

  • IT service catalogue
  • Service level agreements (SLAs)
  • Incident and request management
  • Problem management
  • Change and release management
  • Capacity and availability management
  • Configuration and asset management
  • Supplier and customer management
  • Service continuity
  • Measurement, reporting and continual improvement

Frequently asked questions

How does it differ from ITIL?

ITIL is a body of good practice; ISO/IEC 20000-1 is a certifiable standard with auditable requirements. They complement each other: ITIL guides the how, the standard defines what has to be demonstrated.

Can it be certified together with ISO/IEC 27001?

Yes. They share the high-level structure, so policy, risk management, competence, internal audit and management review are integrated into a single system, with combined audits.

Is it relevant for a managed service provider?

That is exactly the most common use case: for an IT provider, certification is a verifiable commercial argument in front of its clients.

your business partner

Protecting you today, innovating for tomorrow