Wednesday, 25 September 2019

Overview of ISO 20000:2018 structure and requirements


ISO 20000:2018 


The ISO 20000 Certification standard provides organizations with a set of requirements for establishing, implementing, maintaining and continually improving a service management system (SMS).
Organizations can utilize the guidance in this standard as a framework on how to effectively manage an SMS. In September 2018, ISO 20000-1:2018 (Service Management System Requirements) and ISO 20000-10:2018 (Concepts and Vocabulary) were updated to address the evolving needs and challenges in the delivery of IT service management.

ISO 22000 Certification

New ISO 20000 structure


The updated version of ISO 20000-1:2018 has been restructured into the High-level Structure (HLS) to better align/integrate with other ISO management system standards, such as the Information Security Management System (ISMS) contained in ISO 27001
HLS details the requirements of service management processes. The operational processes are grouped into seven subsections that cover the entire lifecycle of the service creation, delivery, and support, as well as interactions with customers and suppliers – both internal and external.
However, ISO 20000 Certification does not include requirements for the structure of the SMS or for the terms used for its components. This illustration of the HLS should not be considered as a set-in-stone structural hierarchy, authority levels, or naming convention. Rather, the HLS should be considered as a framework that can be adjusted to suit the operational needs of the organization. For example, there may be an overlap of SMS support and operational processes within your organization, so it may make sense to combine these two areas. Nevertheless, regardless of how the HLS is organized, none of the requirements of the standard can be ignored, because all clauses are mandatory for compliance.
Furthermore, none of the clauses from ISO 20000:2011 have been deleted from the 2018 version. Clauses have only been modified and renamed in ISO 20000:2018 Certification where deemed necessary. The following sections contain details on the updated clauses.

Clause 4: Context of the organization


The context of the organization clause of ISO 20000:2018 Certification states the requirements necessary to establish, implement, maintain, and continually improve a service management system (SMS). Defining the scope and objectives of the SMS is highly emphasized in clause 4. Additionally, the clause stresses the importance of gaining an understanding of both internal and external factors and the role of interested parties (i.e., stakeholders), in addition to their requirements that may potentially impact an organization and its ability to achieve its objectives. In order to implement an effective SMS, clearly understanding these key points is crucial to success.

Clause 5: Leadership


Successful implementation of ISO 20000 Certification Services requires active engagement and commitment by an organization’s leadership. Proper commitment by the top management includes ensuring that the necessary policies, processes, people, tools, and technologies are in place to deliver quality services to the business. This clause includes specific requirements for top management to establish and communicate service management policy. Additionally, top management is also required to ensure that organizational roles, responsibilities, and authorities related to the SMS are communicated throughout the organization to support efficient delivery of services.

Clause 6: Planning


Planning for an SMS plays a critical role in an organization. Effective planning supports both risk management and the ability to seize opportunities. Planning clearly defines the actions required to achieve the organization’s service management objectives. When conducting planning for an SMS, service management-related objectives should be established at all relevant levels of the organization.

Clause 7: Support of the service management system


Clause 7 requirements emphasize the importance of the roles that multiple organizational areas play in supporting the effectiveness of the service management system. Requirements take a holistic an approach that covers critical areas such as availability of resources, employee competence, situational awareness, internal/external communications, documented information, and knowledge management for proper support of the SMS.

Clause 8: Operation of the service management system


The goal of the requirements in clause 8 is to ensure that the activities necessary for the operation of the SMS are conducted in an effective and efficient manner. Operations requirements in this clause cover all stages of the operational service lifecycle, such as planning and control, service design, and service assurance, among other areas. It should also be noted that this clause is “closest” to the processes required in the 2011 revision of the standard.

Clause 9: Performance evaluation


Clause 9 requires an organization to assess the performance of the SMS through monitoring, measurement, analysis, and evaluation of the system. It is suggested managerial good practice to have both external and internal audits done on your organization’s SMS. But there are specific requirements in this clause for establishing an audit program and conducting internal audits at regular intervals. Furthermore, the quantitative and qualitative data obtained from audits should be reported and reviewed by management in order to support informed decision making on the SMS.

Clause 10: Improvement


Included in clause 10 are requirements regarding nonconformity, corrective action, and continual improvement. The requirements in this clause specify the corrective actions to take when nonconformities are encountered by the organization. These actions support the continual improvement philosophy of effective service management
.
If you are looking for an ISO 20000 Certification Body to assist you with your certification, you should ensure that the company has the qualification and expertise necessary to offer relevant ISO 20000 Certification Services. While accreditation is not compulsory for ISO certification companies, an accreditation certificate is an indicator of good qualification. After reading that you have a question in mind that how to get ISO Certification for that there are many ISO 20000 Certification body helps to check out the ISO procedure. Check out these some frequently asked Questions.

Visit us to get ISO certified



No comments:

Post a Comment

5 steps to set up an emergency plan according to ISO 14001

Introduction Do you have a personal emergency plan? Probably not, but if you live in an area of very high risk of e.g., earthquake, it...