← ITIL 4 Foundation: service and production decisions
06 / 7 · 22 MIN

Restore, investigate, and change

Separate recovery, cause management, and change authorization.

Concept and mechanism

Incident management seeks to reduce impact and restore service. Problem management addresses actual or potential causes, workarounds, and known errors. An analyzed but unresolved problem may be treated as a known error. A workaround reduces impact without necessarily removing the cause. Change enablement supports successful changes through risk assessment, authorization, and coordination. A standard change has predefined conditions and preauthorization; a normal change follows the appropriate model; an emergency uses an accelerated mechanism without making accountability optional.

Guided application

During a batch failure, prioritize by impact and urgency using agreed criteria. If a suitable workaround exists, recover and validate the functional result while preserving investigation evidence. Do not necessarily wait for a definitive cause before restoring. If the intervention exceeds a standard model, seek appropriate assessment and authority. Not every change needs a CAB, but each needs the handling defined for its context. Record what was confirmed, what remains unvalidated, and when the next communication will occur.

IN PRACTICE

Restarting restores processing, but failure repeats for three nights. The incident can recover while the problem remains under investigation and the workaround remains documented.

Common pitfalls

Waiting for the cause before recovering; declaring an emergency to avoid authorization; closing investigation because processes are active.

Related topics: Requests, service levels, and improvement · Outcomes, service, and value

Take this idea with you

Recover with evidence, retain cause management, and authorize changes according to risk and context.

Create account

Reference: PeopleCert ITIL 4 Foundation syllabus v4.2.0 (GogoTraining mirror) · ITIL 4 Foundation; syllabus v4.2.0 (March 2025)