What Is ITIL?

Also called: IT Infrastructure Library, Information Technology Infrastructure Library

Related problems: IT requests and changes are handled differently every time; A provider says it is ITIL-aligned and we don't know what that means; Auditors asking how IT changes and incidents are controlled; Building an IT support process without reinventing the wheel

ITIL is a widely used framework of best-practice guidance for managing IT as a set of services. It describes how organizations can plan, deliver, support and improve IT services, through practices such as incident management, service requests, change management and continual improvement. ITIL isn’t software or a law; it’s a body of published guidance, with training and certifications for individuals, that many IT teams and service providers use as the basis for their processes. The name began as an abbreviation of IT Infrastructure Library (often written out as Information Technology Infrastructure Library), but its owner has said for some years that ITIL is now simply a name, not an acronym, because the framework grew well beyond infrastructure.

At a glance

  • ITIL is guidance for IT service management (ITSM), not a tool or a regulation.
  • It covers practices such as incident, problem, change, request, service level and configuration management.
  • It’s designed to be adapted: most organizations adopt the parts that fit their size and needs.
  • Individuals can be ITIL certified; organizations typically claim alignment, not certification.
  • It originated in the UK public sector; its original expansion, IT Infrastructure Library, is no longer used officially.

What problem it solves

Without shared practices, IT teams tend to invent their own way of handling problems, requests and changes. Some approaches work; many have gaps that show up as lost tickets, unapproved changes that cause outages, or the same problem recurring because nobody looked for the root cause. When a company works with outside providers, different processes and vocabulary on each side add friction.

ITIL gives organizations a tested starting point and a common language. A team can adopt established practices for handling incidents or controlling changes instead of designing them from scratch. Buyers and providers can talk about priorities, service levels and escalation using the same terms. Auditors and customers asking how IT is controlled get answers grounded in recognized practice.

How it works

Guidance, not rules. ITIL is published as a set of books and guidance documents describing practices, principles and how they fit together. Organizations decide which to adopt and how far to go.

Core practices. Those most mid-sized organizations encounter include:

  • Incident management: restoring normal service quickly when something breaks, usually through a help desk and often organized as tiered IT support.
  • Service request management: handling routine requests such as access, equipment and software.
  • Problem management: finding and fixing root causes of recurring incidents.
  • Change enablement: assessing and approving changes so they don’t cause outages.
  • Service level management: agreeing on and reporting against targets, typically set in a service level agreement (SLA).
  • Configuration and asset management: keeping records of IT components and how they connect, often in a configuration management database (CMDB), alongside IT asset management (ITAM).
  • Continual improvement: regularly reviewing and improving services and processes.

Versions. ITIL has gone through several major revisions. Recent guidance emphasizes delivering value, flexibility and working alongside approaches such as agile and DevOps, compared with earlier, more process-heavy editions.

Certification. The framework is maintained by a private organization that runs accredited training and certification for individuals at several levels.

When it matters for buyers

  • When choosing an MSP or help desk provider. “ITIL-aligned” is a common claim; ask which practices they follow and how.
  • When setting up or maturing ITSM. ITIL offers ready-made practices to adapt instead of inventing your own.
  • When audits or customers ask about IT controls. Documented change and incident practices based on ITIL can help answer their questions.
  • When integrating with providers. Shared terminology for priorities, incidents and changes reduces confusion during handoffs.
  • When hiring. ITIL certification indicates familiarity with service management concepts, though not necessarily practical experience.

Our help desk overview covers outsourced support options, many of which describe their processes in ITIL terms.

Questions to ask vendors

  • Which ITIL practices do you follow, and how do they apply to our service?
  • How do you define incident priorities, and what response targets apply to each?
  • How are changes to our systems requested, assessed and approved?
  • Do you run problem management, and how will we see root cause findings?
  • Which version of ITIL are your staff certified in, and at what levels?
  • How do your processes connect to ours, especially for escalations and changes?

How it differs from ITSM

ITSM is the practice of managing and delivering IT as services to users. ITIL is one framework of guidance for doing ITSM, and the best known. An organization can run ITSM well using ITIL, another framework or a simple process of its own. Similarly, ITSM software platforms implement processes that often follow ITIL terminology, but buying one doesn’t mean you’re following ITIL. When a provider mentions ITIL, it’s describing how it approaches service management; when it mentions ITSM, it’s referring to the practice or the tools that support it.

Frequently Asked Questions

Is ITIL the same as ITSM?
No. ITSM is the practice of managing IT as services. ITIL is a widely used framework of guidance for doing it. Organizations can run ITSM using ITIL, another framework, or their own lighter process.
Is ITIL a standard you can be certified against?
Individuals can earn ITIL certifications through accredited training. Organizations don't get certified to ITIL itself; an organization wanting a certifiable IT service management standard typically looks at ISO/IEC 20000 instead. A provider saying it is ITIL-aligned usually means its processes follow ITIL guidance and its staff are trained in it.
Does a mid-sized company need ITIL?
Not in full. Many mid-sized organizations adopt a few ITIL practices, such as incident, request and change management, and keep them light. The framework is meant to be adapted, not implemented wholesale.
Does ITIL conflict with DevOps or agile?
It can when change approvals are slow and manual, but more recent ITIL guidance puts more weight on flexibility and value, and many organizations combine the two. Automated, low-risk changes can be pre-approved while higher-risk changes still get review.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.