3Service operation
- 3.1Incident management
Centered on the fact that the purpose of incident management is the rapid restoration of service, not the investigation of root cause, this section covers prioritization by impact x urgency, escalation (functional and hierarchical), the separate handling of a major incident, and when to apply a workaround to restore service even before the root cause is known—together with how to judge these under SLA-target constraints.
- 3.2Problem management
Covers how the purpose of problem management is to prevent recurrence through root-cause identification and a permanent fix (in contrast with incident management, whose purpose is rapid restoration), the flow of raising a problem from recurring faults or major incidents and performing root-cause analysis (RCA), the use of a known error database (KEDB) that accumulates causes and workarounds, and choosing between reactive (waiting for a fault) and proactive (getting ahead via trend analysis) problem management.
- 3.3Event management and request fulfilment
Covers event management, which monitors state changes of components, catches signs that exceed a threshold, and can automatically raise incidents (distinguishing informational, warning, and exception events), and request fulfilment, which handles routine, low-risk service requests such as password resets or access grants through a flow separate from ordinary incidents—together with judging which report to route to which process.
- 3.4The service desk
Covers the role of the service desk as the single point of contact (SPOC) for users (centralizing communication and maintaining user satisfaction) and the structural patterns—local, centralized, virtual, and follow-the-sun—together with the judgment of which pattern to choose under constraints such as site distribution, language, the need for 24-hour coverage, and cost.

