โ† All ISO 20000 Certification Flashcard Decks

Change Management Flashcards

7 cards from real ISO 20000 Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Change Management flashcards as text
  1. A change to a critical database is being planned. ISO 20000 requires that this change be tested. In which environment should testing occur BEFORE deployment to production?

    Answer: A test or non-production environment that mirrors production

    ISO 20000 requires testing in a controlled, non-production environment that represents production conditions to minimize risk.

  2. Which of the following BEST describes the relationship between change management and release management in ISO 20000?

    Answer: Change management authorizes changes; release management plans and deploys them

    ISO 20000 treats change management as the authorization gate and release management as the deployment mechanism, and they work in sequence.

  3. An ISO 20000-compliant organization notices that the number of unauthorized changes is increasing. What is the MOST appropriate corrective action?

    Answer: Review and strengthen the change management procedure and enforcement controls

    Increasing unauthorized changes indicate a process control failure; strengthening the procedure and its enforcement is the root-cause corrective action.

  4. Under ISO 20000, which document defines the criteria and authority levels for approving changes of different risk levels?

    Answer: Change management policy

    The change management policy establishes who can authorize changes at each risk level and the criteria for categorization.

  5. A service provider must demonstrate continual improvement of its change management process. Which ISO 20000 activity supports this?

    Answer: Regular review of change management KPIs and trend analysis to identify improvements

    Continual improvement requires measuring performance through KPIs and using trend analysis to identify and act on opportunities to improve the process.

  6. ISO 20000 requires that all changes be logged. What is the MINIMUM information that should be captured in a change record at initiation?

    Answer: Description of the change, requester, reason, and initial risk assessment

    At initiation, a change record must capture enough information to assess and evaluate the change, including what it is, why it is needed, who requested it, and an initial risk assessment.

  7. Which scenario represents a violation of ISO 20000 change management requirements?

    Answer: A technician deploys a server patch directly to production without raising a change request

    Deploying without a change request bypasses the authorization and tracking requirements of ISO 20000 change management, making it a clear violation.