Home / Articles / Information Security
Information Security

ISO 20000: Running IT as a Service, Not a Cost Centre

ISO 20000 is the standard for IT service management — delivering IT as reliable, measurable services aligned to the business. Here's what it requires.

By Shamir George · 5 min read

When IT is run as a reactive cost centre, it firefights. Run as a service, it delivers predictable, measurable value to the business. ISO 20000 is the international standard for an IT service management system (SMS) — and it's closely aligned with the ITIL practices many IT teams already know.

Services, not just systems

The mental shift ISO 20000 demands is from managing technology to managing services — defined offerings with agreed levels of quality. That means Service Level Agreements (SLAs), a service catalogue, and measuring whether you actually meet what you promised, rather than just keeping servers running.

The core service-management processes

  • Incident and request management — restore service fast; handle routine requests cleanly.
  • Problem management — find and fix root causes so incidents stop recurring.
  • Change management — make changes without breaking things.
  • Service level management — agree, monitor, and report on SLAs.
  • Capacity and availability management — ensure services can meet demand, now and ahead.
The difference between IT-as-cost and IT-as-service is whether anyone agreed, in advance, what "good" looks like — and whether you measure against it.

The management-system wrapper

Like its sibling standards, ISO 20000 uses the Annex SL structure, so the SMS has leadership ownership, planning, and continual improvement built in. It integrates naturally with ISO 27001 (information security) — many IT organizations run both, because secure and well-managed services are two sides of the same coin.

Why certify

  • Demonstrates reliable, measurable IT to customers and management.
  • Reduces downtime and recurring incidents through disciplined problem and change management.
  • Provides a common language with outsourcers and managed-service providers.

Run IT as a service

My ISO 20000 course covers the service-management processes, SLAs, and the management-system requirements that turn reactive IT into reliable, measured service delivery.

View the ISO 20000 course →

Questions

Is ISO 20000 the same as ITIL?

No — ITIL is a body of best-practice guidance; ISO 20000 is a certifiable standard. They align closely, and ITIL practices help you meet ISO 20000 requirements.

Does it work with ISO 27001?

Yes — they share the Annex SL structure and are commonly run together, since well-managed IT services and information security reinforce each other.

← All articles