ITIL capacity management

ITIL capacity management: baseline measurement and assertion vs. telemetry

2026-05-31 · governance-policy software-engineering mlops-deployment · medium · source → · wiki →
key claims
  1. ITIL v3/2011 and ITIL 4 both use "should" not "shall" for all capacity measurement data collection requirements, making telemetry-based baseline establishment a recommendation rather than a binding obligation under ITIL compliance aloneITIL v3 Service Design Chapter 4.3 (n.d.)PeopleCert (2023)
  2. The official ITIL Capacity Plan template formally accommodates assertion-based baselines by including an "Assumptions and database" section that explicitly states initial values for new services may be "assumed/estimated/agreed values, to be validated once operational."IT Process Wiki (n.d.)
  3. ITIL v3 defines three sub-processes (BCM, SCM, CCM) each with a different measurement focus: Business Capacity Management (BCM) translates business demand plans into service requirements using forecasts and is more dependent on projected estimates, while Component Capacity Management (CCM) monitors individual infrastructure component utilisation directly, making CCM more telemetry-dependent than BCMIT Process Wiki (n.d.)ITIL v3 Service Design Chapter 4.3 (n.d.)
  4. ITIL 4 consolidated BCM, SCM, and CCM into a single "Capacity and Performance Management" practice, removing the explicit sub-process structure of ITIL v3 and making the assertion-to-telemetry gradient less visible to practitioners working from ITIL 4 guidance alonePeopleCert (2023)IT Process Wiki (n.d.)
  5. ITIL specifies no mandatory validation gate, deadline, or escalation mechanism requiring that assertion-based baselines be superseded by telemetry-derived values after a service enters operational use, leaving the transition entirely at practitioner discretionIT Process Wiki (n.d.)ITIL v3 Service Design Chapter 4.3 (n.d.)
  6. ISO/IEC 20000-1:2018 Clause 8.6 uses mandatory "shall" language requiring organisations to monitor, measure, review, and report on capacity and performance, imposing a stricter measurement obligation than ITIL's "should" stance and excluding assertion-only baselines for ISO 20000-certified organisationsISO/IEC 20000-1:2018 (2018)
  7. Iden and Eikebrokk's 2013 systematic literature review of ITIL implementations found that capacity management is consistently among the least mature ITIL processes in practice, with data collection challenges and difficulty of predictive analysis identified as the primary barriers to maturity investmentEikebrokk (2013)
  8. ITIL's combination of assertion tolerance and the absence of a mandatory validation gate means that organisations relying solely on ITIL can remain in an assertion-based baseline posture indefinitely without formal non-compliance, and empirical implementation evidence indicates this pattern occurs in practiceIT Process Wiki (n.d.)Eikebrokk (2013)

Research Question

What does IT Infrastructure Library (ITIL) capacity management specify as the measurement practice for establishing a platform capability baseline, and where does it rely on assertion rather than telemetry?

Findings

(Populated from §6 Synthesis above.)

Executive Summary

IT Infrastructure Library (ITIL) capacity management specifies telemetry-based measurement as a recommended practice using "should" not "shall" throughout, in both ITIL v3/2011 and ITIL 4, which means telemetry is never a binding obligation under ITIL compliance alone. ITIL explicitly accommodates assertion-based baselines: the official Capacity Plan template includes an "Assumptions and database" section and specifically permits "assumed/estimated/agreed values" for new services, pending operational validation that ITIL itself never mandates. The boundary between assertion-acceptable and telemetry-required zones follows a gradient across ITIL v3's three sub-processes (Business, Service, and Component Capacity Management), with assertion tolerance highest at the business planning layer and lowest at the infrastructure component monitoring layer, but this gradient is implicit rather than explicitly governed in either ITIL version. ISO/IEC 20000-1:2018 Clause 8.6 imposes a stricter measurement obligation by mandating ("shall") ongoing empirical measurement of capacity and performance, but ISO 20000 certification is a separate requirement not implied by ITIL alignment.

Key Findings

  1. ITIL v3/2011 and ITIL 4 both use "should" not "shall" for all capacity measurement data collection requirements, making telemetry-based baseline establishment a recommendation rather than a binding obligation under ITIL compliance alone.

  2. The official ITIL Capacity Plan template formally accommodates assertion-based baselines by including an "Assumptions and database" section that explicitly states initial values for new services may be "assumed/estimated/agreed values, to be validated once operational."

  3. ITIL v3 defines three sub-processes (BCM, SCM, CCM) each with a different measurement focus: Business Capacity Management (BCM) translates business demand plans into service requirements using forecasts and is more dependent on projected estimates, while Component Capacity Management (CCM) monitors individual infrastructure component utilisation directly, making CCM more telemetry-dependent than BCM.

  4. ITIL 4 consolidated BCM, SCM, and CCM into a single "Capacity and Performance Management" practice, removing the explicit sub-process structure of ITIL v3 and making the assertion-to-telemetry gradient less visible to practitioners working from ITIL 4 guidance alone.

  5. ITIL specifies no mandatory validation gate, deadline, or escalation mechanism requiring that assertion-based baselines be superseded by telemetry-derived values after a service enters operational use, leaving the transition entirely at practitioner discretion.

  6. ISO/IEC 20000-1:2018 Clause 8.6 uses mandatory "shall" language requiring organisations to monitor, measure, review, and report on capacity and performance, imposing a stricter measurement obligation than ITIL's "should" stance and excluding assertion-only baselines for ISO 20000-certified organisations.

  7. Iden and Eikebrokk's 2013 systematic literature review of ITIL implementations found that capacity management is consistently among the least mature ITIL processes in practice, with data collection challenges and difficulty of predictive analysis identified as the primary barriers to maturity investment.

  8. ITIL's combination of assertion tolerance and the absence of a mandatory validation gate means that organisations relying solely on ITIL can remain in an assertion-based baseline posture indefinitely without formal non-compliance, and empirical implementation evidence indicates this pattern occurs in practice.

Assumptions

Analysis

ITIL's capacity management framework creates a two-zone structure for baseline evidence, though this structure is never explicitly named or governed in ITIL text.

The first zone corresponds to Business Capacity Management: it is dominated by planning-stage inputs including transaction volume forecasts, growth projections, and stakeholder agreements. At this layer, assertion is structurally necessary because future business demands cannot be empirically measured in advance. The ITIL guidance explicitly relies on "trend, forecast, model or predict" techniques that combine historical telemetry with forward-looking assumptions.

The second zone corresponds to Component Capacity Management: monitoring individual infrastructure components (CPU, memory, storage, network) provides the directly observable data on which operational baselines are built. Even here, ITIL uses "should" rather than mandatory language.

ITIL provides no mandatory mechanism to enforce the transition from assertion to telemetry once a service is operational. The Capacity Plan template's "to be validated once operational" note carries no attached control: no specified deadline, no escalation trigger, and no formal review gate. This means the intended validation is an aspiration rather than a control.

ISO 20000's "shall" language imposes a stronger measurement obligation than ITIL's "should" stance on this control surface. An ISO 20000 audit requires demonstrable evidence of ongoing measurement: a Capacity Plan containing only agreed or assumed values without supporting operational telemetry would not satisfy Clause 8.6. The practical consequence is that the assertion tolerance permitted by ITIL alone is incompatible with ISO 20000 certification once a service is in operation.

The Iden and Eikebrokk (2013) empirical finding is consistent with this inference: organisations defer capacity management maturity because data collection is costly, and ITIL provides no mandatory gate that would force that investment. The primary driver the authors identify is the cost and difficulty of telemetry implementation, not the absence of a mandate; ITIL's lack of a mandatory validation gate removes the structural pressure that might otherwise force organisations to bear that cost. A plausible rival explanation is that organisations would defer telemetry investment regardless of what ITIL requires, because data collection is expensive; the absence of evidence that ISO 20000-certified organisations achieve measurably higher capacity management maturity than ITIL-only organisations would support that rival, but this comparison is outside the scope of the empirical literature reviewed here.

The companion completed research item on capability claim vs. production telemetry arbitration (github.com identified telemetry override as the most reliable arbitration mechanism for capability claim conflicts. The present findings establish that ITIL-aligned organisations may legitimately have no operational telemetry to override against, because ITIL does not require it to be collected. Where an organisation relies on an ITIL-compliant assertion-based baseline and has never established operational telemetry, the telemetry override pathway described in the arbitration item is structurally unavailable.

Risks, Gaps, and Uncertainties

Open Questions


sources


cites
cites Capability claim vs. production telemetry: arbitration mechanisms and overestimation
cites SRE: establishing SLOs as contractual capability boundaries
related (frontmatter)
related SRE: establishing SLOs as contractual capability boundaries
related Capability claim vs. production telemetry: arbitration mechanisms and overestimation

Connected items

Loading…

View full knowledge graph →