NEW
Font size
WorksheetsQuiz-P2-2-Change control
Total questions: 13
Worksheet time: 7mins
Which is a purpose of the "Change control " practice
To ensure that accurate and reliable information about the configuration of services, and the CIs that support them, is
available when and where it is needed. This includes information on how CIs are configured and the relationships between them.
To minimize the number of successful service and product changes by ensuring that risks have been properly assessed,authorizing changes to proceed, and managing the change schedule.
To maximize the number of successful
service and product changes by ensuring
that risks have been properly assessed,
authorizing changes to proceed, and
managing the change schedule.
To plan and manage the full lifecycle of all IT
assets, to help the organization:
● maximize value
● control costs
● manage risks
● support decision-making about purchase,
re-use, retirement, and disposal of assets
● meet regulatory and contractual
requirements.
Which is a scope of the "change control" practice?
The scope of change control is defined by customer. It will typically include all IT infrastructure, applications, documentation, processes, supplier relationships and anything else that might directly or indirectly impact a product or service
The scope of change control is defined by each organization. It will typically include all IT infrastructure, applications, documentation, processes, supplier relationships and anything else that might directly or indirectly impact a product or service
The scope of change control is defined by Supplier. It will typically include all IT infrastructure, applications, documentation, processes, supplier relationships and anything else that might directly or indirectly impact a product or service
The scope of change control is defined by user. It will typically include all IT infrastructure, applications, documentation, processes, supplier relationships and anything else that might directly or indirectly impact a product or service
What is a change?
Any financially valuable component that can contribute to the delivery of an IT product or service.
A version of a service or other configuration item,
or a collection of configuration items, that is made
available for use.
Any component that needs to be managed
in order to deliver an IT service.
A change is the addition, modification, or removal of anything that could have a direct or indirect effect on IT services
Which statement about "Change authority." is CORRECT?
The person or group who authorizes a change is known as a change authority. It is essential that the correct change authority is assigned to each type of change to ensure that change control is both efficient and effective.
To make new and changed services and
features available for use.
To ensure that accurate and reliable information about the configuration of services, and the CIs that support them, is available when and where it is needed. This
includes information on how CIs are configured and the relationships between them.
To ensure that the availability and
performance of a service are maintained at
sufficient levels in case of a disaster.
Which is NOT a kind of the change type ?
Standard change
Normal change
Emergency change
Exception change
Which statement about "Standard change." is CORRECT?
These are low-risk, pre-authorized changes that are well understood and fully documented, and can be implemented
without needing additional authorization.
These are changes that need to be scheduled, assessed, and authorized following a process.
These are changes that must be implemented as soon as
possible; for example, to resolve an incident or implement a security patch.
Some changes are low risk, and the
change authority for these is usually
someone who can make rapid decisions, often using automation to speed up the change.
Which statement about "Standard change." is NOT CORRECT?
These are low-risk, pre-authorized changes that are well understood and fully documented, and can be implemented
without needing additional authorization.
They are often initiated as service requests,
but may also be operational changes.
When the procedure for a standard change is created
or modified,
there should be a full risk assessment and
authorization as for any other change.
Initiation of a standard
change is triggered by the creation of a
change request.
Which statement about "normal change." is CORRECT?
These are changes that must be implemented as soon as
possible; for example, to resolve an incident or implement
a security patch.
These are changes that need to be
scheduled, assessed, and authorized
following a process.
These are low-risk, pre-authorized changes
that are well understood and fully
documented, and can be implemented
without needing additional authorization.
normal changes are not typically included in a change
schedule, and the process for assessment and authorization is
expedited to ensure they can be implemented
quickly.
Which statement about "normal change." is NOT CORRECT?
They are often initiated as service requests,
but may also be operational changes.
Some normal changes are low risk, and the
change authority for these is usually
someone who can make
rapid decisions, often using automation to
speed up the change.
Other normal changes are very major and
the change authority could be as high as
the management board (or equivalent).
Initiation of a normal
change is triggered by the creation of a
change request.
Which statement about "Emergency change." is CORRECT?
These are changes that must be implemented as soon as
possible; for example, to resolve an incident or implement
a security patch.
These are changes that need to be
scheduled, assessed, and authorized
following a process.
These are low-risk, pre-authorized changes
that are well understood and fully
documented, and can be implemented
without needing additional authorization.
When the procedure for a Emergency change is created or modified,
there should be a full risk assessment and
authorization as for any other change.
Which statement about "Emergency change" is NOT CORRECT?
Emergency changes are not typically included in a change
schedule, and the process for assessment and authorization is
expedited to ensure they can be implemented
quickly.
As far as possible, emergency changes should be subject to the same testing, assessment, and authorization as normal changes, but it may be acceptable to defer some documentation until
after the change has been implemented, and sometimes it will be necessary to implement the change with less testing due to time constraints.
These are changes that need to be scheduled, assessed, and authorized following a process.
There may also be a separate change authority for emergency changes, typically including a small number of senior managers who understand the business risks involved.
What is NOT a recommendation of the change control?
Change control must balance the need to
make beneficial changes that will deliver
additional value with the need to protect
customers and users from the adverse
effect of changes.
Organizational change management
manages the people aspects of changes to
ensure that improvements and
organizational transformation initiatives are
implemented successfully. Change control
is usually focused on changes in
products and services.
Change schedule is used to help plan changes, assist in communication, avoid conflicts, and assign resources.
It can also be used after changes have been deployed to provide information needed for incident management, problem management, and
improvement planning.
When a change cannot be resolved
quickly, it is often useful to find and
document a workaround for future
incidents, based on an understanding of
the problem.
How does Change control contribute to the Obtain/build value chain activity?
Changes to components are subject to
change control, whether they are built in
house or obtained from suppliers.
Changes may have an impact on delivery
and support, and information about changes
must be communicated to personnel who
carry out this value chain activity.
Changes to product and service portfolios,
policies, and practices all require a certain
level of control, and the change control
practice is used to provide it.
Many improvements will require changes to
be made, and these should be assessed and
authorized in the same way as all other
changes.
