Concept and mechanism
Incident management seeks to reduce impact and restore service. Problem management addresses actual or potential causes, workarounds, and known errors. An analyzed but unresolved problem may be treated as a known error. A workaround reduces impact without necessarily removing the cause. Change enablement supports successful changes through risk assessment, authorization, and coordination. A standard change has predefined conditions and preauthorization; a normal change follows the appropriate model; an emergency uses an accelerated mechanism without making accountability optional.
Guided application
During a batch failure, prioritize by impact and urgency using agreed criteria. If a suitable workaround exists, recover and validate the functional result while preserving investigation evidence. Do not necessarily wait for a definitive cause before restoring. If the intervention exceeds a standard model, seek appropriate assessment and authority. Not every change needs a CAB, but each needs the handling defined for its context. Record what was confirmed, what remains unvalidated, and when the next communication will occur.
Restarting restores processing, but failure repeats for three nights. The incident can recover while the problem remains under investigation and the workaround remains documented.
Common pitfalls
Waiting for the cause before recovering; declaring an emergency to avoid authorization; closing investigation because processes are active.
Related topics: Requests, service levels, and improvement · Outcomes, service, and value
Recover with evidence, retain cause management, and authorize changes according to risk and context.
Reference: PeopleCert ITIL 4 Foundation syllabus v4.2.0 (GogoTraining mirror) · ITIL 4 Foundation; syllabus v4.2.0 (March 2025)