Incident Management

Incident Management

The leading IT Analysts agree that around 80% of all Incidents being reported to the IT Service Desk are caused by Change!


Webinar:  Incident & Problem – do we really need both?

View the webinar

An incident is an unplanned interruption to an IT service, or a reduction in the quality of an IT service. Failure of a configuration item that has not yet impacted service is also an incident.

The purpose of Incident Management is to restore normal service as quickly as possible, to minimise the adverse impact on business operations, and to ensure the best possible levels of service quality and availability are maintained. ‘Normal Service Operation’ is defined as an operational state where services and CIs are performing within their agreed service and operational levels.

Incident Management is highly visible to the business, and it is therefore easier to demonstrate its value than most areas in Service Operation. For this reason, Incident Management is often one of the first processes to be implemented in service management projects. The added benefit of doing this is that Incident Management can be used to highlight other areas that need attention – thereby providing a justification for expenditure on implementing other processes.

Incidents are mostly detected by users who would then contact the Service Desk, however proactive Incident Management could be detected by Event Management. Incidents are categorized to identify who should work on them and for trend analysis, and they are prioritized according to urgency and business impact.

Incidents should be tracked throughout their lifecycle to support proper handling and reporting on the status of incidents. Within the Incident Management system, status codes may be linked to incidents to indicate where they are in relation to the lifecycle. Examples of these might include:

  • Open  An incident has been recognized but not yet assigned to a support resource for resolution
  • In progress  The incident is in the process of being investigated and resolved
  • Resolved  A resolution has been put in place for the incident but normal state Service Operation has not yet been validated by the business or end user
  • Closed The user or business has agreed that the incident has been resolved and that normal state operations have been restored

Customers must be kept informed of the status of their incident at all times.

If an incident cannot be resolved quickly, it may be escalated. Functional escalation passes the incident to a technical support team (2nd line support) with appropriate skills; hierarchical escalation engages appropriate levels of management.

Always try to have different people responsible for Incident Management and Problem Management – these are different skills. Incident Management all about getting the customer back to work as quickly as possible, whereas Problem Management is about investigating the root cause of Incidents, which is a longer process.

Incident Management Activities:

Incident Management

ITIL Operational Support and Analysis Training


"*" geeft vereiste velden aan

Dit veld is bedoeld voor validatiedoeleinden en moet niet worden gewijzigd.


Kate Hamblin

Senior ITSM Consultant +44 0118 324 0620