التفاصيل

Information Technology service management system

ISO/IEC 20000-1:2018

01

مقدمة الخدمة

Information technology service management system certification is an authoritative evaluation mechanism for organizations to establish, implement, operate, monitor, review, maintain and improve IT service management capabilities. IT aims to ensure that IT services are consistent with business needs through standardized processes and deliver measurable, high-quality and high-availability IT services. This certification is mainly based on the international standard of ISO/IEC 20000-1:2018 "Information Technology Service Management Part 1: Service Management System Requirements", which comprehensively inspects the management ability of the organization's IT service in the whole life cycle, and finally grants the organization a certification certificate with a validity period of three years.

Certification core content

The certification of information technology service management system revolves around the systematic management of IT services, with the following dimensions as the core:

Service management system planning: understand the organization and its environment, identify the needs of relevant parties, determine the scope of the system, formulate service management policies and objectives, and clarify responsibilities and authorities.

Service delivery and planning: service level management (SLA formulation and monitoring), service catalog management, capacity management, availability management, service continuity management and information security management.

Relationship and agreement management: supplier management, business relationship management and service report management.

Solution and control process: incident management, problem management, configuration management, change management, release and deployment management.

Resources and capacity guarantee: personnel capacity and training, financial budget and accounting, resource allocation and knowledge management.

Performance evaluation and improvement: service performance monitoring, internal audit, management review, nonconformity correction and continuous improvement mechanism (PDCA cycle)

Certification business scope

Information technology service management system certification covers the following six categories of service activities:

Planning and design services: information system consulting planning, information system software design and development, and information technology consulting services.

integration services: equipment system integration services and software system integration services.

Testing and supervision services: information system testing services, software product testing services, information system engineering supervision and software engineering supervision services.

Operation and maintenance services: infrastructure operation and maintenance services, hardware operation and maintenance services and software operation and maintenance services.

Security services: risk assessment, security operation and maintenance, emergency response and disaster recovery.

Business process services: e-commerce support services, software operation services, data processing, call center/service desk services.

Certification process

Information technology service management system certification is usually divided into the following stages:

Application and acceptance: submit application materials (business license, system documents, etc.), and the certification body will conduct application review to confirm that the organization has the basic conditions for certification (the system has been in operation for 3 months, completed internal audit and management review, and has not been subject to administrative punishment by the competent department within one year).

First-stage audit (document audit): conduct document audit and site preparation evaluation, review the compliance of system documents with standard requirements, and confirm the adequacy of second-stage audit preparation.

The second stage audit (on-site audit): conduct on-site audit, including personnel interview, document record inspection, on-site inspection of service process, service performance verification, evaluate the compliance and effectiveness of the system, and identify nonconformities.

Rectification and review: for the nonconformities found in the audit, the organization shall complete the rectification within the specified time limit and submit the evidence, which will be reviewed by the audit team.

Certification decision and certification: Certification certificate will be issued after the technical review is passed, confirming that the organization meets the standard requirements. The certificate is valid for three years and can be found on the website of CNCA.

Supervision and audit: conduct supervision and audit once a year after obtaining the certificate (the interval shall not exceed 12 months) to confirm that the system continues to meet the certification requirements.

Re-certification audit: Re-certification audit is conducted before the certificate expires, and the certification qualification is extended, usually for three years.

Certification value

Improve service quality and operational efficiency: through standardized processes and quantitative management, help enterprises optimize IT service processes, reduce redundant operations and human errors, and significantly improve service reliability and response speed; Establish a continuous improvement service management mechanism to quickly respond to market demand and improve customer satisfaction.

Enhance market competitiveness: certification is an internationally recognized IT service management standard, which can help enterprises get extra points in bidding, especially for data-sensitive industries such as finance and telecommunications; Large enterprises often take certification as the entry threshold for suppliers, and they can win high-value customer cooperation opportunities through certification.

Strengthen risk management and compliance: establish a sound risk assessment and emergency response mechanism (such as data backup in different places and emergency plan for failures) to effectively prevent risks such as data leakage and system downtime, and reduce business interruption losses caused by IT failures; At the same time, it meets the requirements of GDPR, Network Security Law and other laws and regulations.

Optimize resource allocation and cost control: by clarifying the division of responsibilities and process specifications, enterprises can eliminate process redundancy and precipitate best practices, shorten the average processing time of IT failures, improve the efficiency of operation and maintenance personnel, reduce resource waste and reduce operating costs.

Promote the integration of IT and business: the system requires IT departments to change from "technology-oriented" to "business-oriented", and define the IT needs of various business departments through service catalogs to avoid waste of resources and improve collaborative efficiency.

Obtaining government support: some regions (such as Zhejiang and Shanghai) provide government subsidies to certified enterprises; Certification helps enterprises to meet international standards and expand overseas markets.

03

عملية الخدمة

04

ملف القواعد

هل تحتاج إلى هذه الشهادة؟

اتصل بنا