* Inside ITIL’s Gold Book for application management
We’ve all been paying attention to the IT Infrastructure Library as it pertains to managing IT services. But the Gold Book – or ITIL’s guide for application management – is not so familiar or even known at all.
Application management in and of itself is clearly something we’ve been dealing with as an industry nearly as long as we’ve been addressing service-level management (SLM). Any operations personnel, from service desk staff to network and systems management professionals, will tell you how important it is to have visibility into the performance of critical business applications. ITIL’s best practices guide, however, takes the requirement further by defining the link between application development service quality. The idea is to make certain to build in support for all aspects of ITIL’s Service Support and Delivery as well as Security at the time of application design and development, addressing the entire lifecycle of an application.
Application failure represents a large percentage of product outages in any enterprise environment. Certainly there are human errors and equipment failures and a host of other challenges. Still, it is the business application that touches end users, customers, and business partners.
Some SLM vendors in fact come very close to equating the application with the service that is being delivered when in reality there are many underlying technologies that must also be in place to ensure service quality.
The question really becomes: How can IT have any control over service quality unless applications are built with the instrumentation necessary to provide visibility and control? We have an artificial distinction in IT that separates application development (or new services) from the delivery of services (or service management). Those responsible for service management most often have little or no role in the development or acquisition of new applications.
ITIL introduces some new concepts for application management. As with all ITIL best practices, there is a strong emphasis on understanding business goals and objectives and then relating those needs to IT strategy.
In the Gold Book, we are introduced to the idea of an application portfolio, which would be unique to each company. It is a data store that contains details of all applications running throughout an enterprise. The goal is to have a central place to track information about the business value and contribution of each application. There are entries for all applications regardless of their phase in the application lifecycle up until the application is retired.
Another concept in the Gold Book that is very pertinent to IT governance and accountability is the recommendation to create or evaluate a baseline for risk management when creating or deploying any application. The baseline for risk management is a means for understanding your own limitations before you begin work on a new application. It is critical in terms of understanding where failures might occur and whether the organization is prepared to invest its resources. This assessment may guide choices for the company in sourcing particular application needs. For example, it can sometimes be more cost effective to outsource routine application services and, depending upon the risk assessment, executives may choose this approach.
The Gold Book spends a great deal of time on general best practices around application development. There are discussions about designing and building reusable software and a definition of an application lifecycle, with phases for defining requirements, designing, building, deploying, operating, and optimizing.
There is also much discussion about requirements – both functional and non-functional; the non-functional requirements are for building better manageability into the application. To illustrate what some of those non-functional requirements would be, there is a checklist that recommends evaluating needs for all aspects of service delivery and support. For your reference, the specific disciplines include configuration management, change management, release management, security management, incident management, problem management, capacity management, availability, service continuity, SLM and financial management.
Many enterprises are currently following processes and best practices for application development. ITIL’s approach, however, expands the view of what it means to link tightly the functions of application development and IT or business services. One issue to consider in this approach is certainly the maturity level of Service Support and Service Delivery within your own enterprise. Since the Gold Book seems to be one of the least discussed components of ITIL Best Practices, Enterprise Management Associates is very interested to hear from any organizations that have begun adoption of the recommendations in the Gold Book. If you are willing to share your experiences or point of view on this subject, please contact me at mailto:lisaeh@emausa.com




