Scope the services, build a service management system, and connect incidents, changes, suppliers, and improvement to customer outcomes.
Choose the service boundary
ISO/IEC 20000-1:2018 specifies requirements for establishing and improving a service management system. It covers planning, design, transition, delivery, and improvement of services. Begin with a service catalogue and the organizational boundary that manages those services; a department can be in scope even within a larger enterprise.
Record customers, service requirements, commitments, interfaces, and the suppliers needed to deliver each service. An abstract IT department scope gives little basis for measuring outcomes.
Connect service processes to decisions
Define how incidents, service requests, changes, releases, availability, capacity, continuity, and suppliers are handled and measured. Give each process an owner and a route for exceptions. The point is not to produce parallel process documents but to make a service reliable through ordinary work.
A change record, for example, should show risk, approval, deployment, and whether the service objective was maintained. An incident record should lead to recovery and, where needed, a lasting corrective action.
Share controls with security and resilience
ISO/IEC 27001 can govern information security risks for the same service, while ISO 22301 can address disruption and recovery. Share service inventory, supplier reviews, change evidence, and management reporting when the boundaries overlap. Preserve the different objectives: service management, information security, and business continuity answer distinct questions.
A customer may also request SOC 2. The operational records may be useful, but the SOC 2 system and criteria must be scoped with the independent CPA firm.
Measure whether delivery improves
Review service levels, incidents, changes, customer feedback, supplier performance, and recurring failures. Assign improvement actions with owners and dates; test whether they changed performance. Management review should decide where resources and design need to change, not merely acknowledge a dashboard.
Independent certification, if sought, is decided by a certification body and covers the assessed SMS scope.
Put it into practice
- Define the services and customers within the SMS boundary.
- Connect incidents, changes, suppliers, and continuity to service commitments.
- Reuse evidence across related management systems where scope overlaps.
- Track whether corrective actions improve service outcomes.
Primary sources
- ISO: ISO/IEC 20000-1:2018 service management systems
- ISO: ISO/IEC 20000 service management series overview
Normstone resources are general information, not legal advice or an independent assessment.