ITIL capacity management
ITIL capacity management: baseline measurement and assertion vs. telemetry
- ITIL v3/2011 and ITIL 4 both use "should" not "shall" for all capacity measurement data collection requirements, making telemetry-based baseline establishment a recommendation rather than a binding obligation under ITIL compliance aloneITIL v3 Service Design Chapter 4.3 (n.d.)PeopleCert (2023)
- The official ITIL Capacity Plan template formally accommodates assertion-based baselines by including an "Assumptions and database" section that explicitly states initial values for new services may be "assumed/estimated/agreed values, to be validated once operational."IT Process Wiki (n.d.)
- ITIL v3 defines three sub-processes (BCM, SCM, CCM) each with a different measurement focus: Business Capacity Management (BCM) translates business demand plans into service requirements using forecasts and is more dependent on projected estimates, while Component Capacity Management (CCM) monitors individual infrastructure component utilisation directly, making CCM more telemetry-dependent than BCMIT Process Wiki (n.d.)ITIL v3 Service Design Chapter 4.3 (n.d.)
- ITIL 4 consolidated BCM, SCM, and CCM into a single "Capacity and Performance Management" practice, removing the explicit sub-process structure of ITIL v3 and making the assertion-to-telemetry gradient less visible to practitioners working from ITIL 4 guidance alonePeopleCert (2023)IT Process Wiki (n.d.)
- ITIL specifies no mandatory validation gate, deadline, or escalation mechanism requiring that assertion-based baselines be superseded by telemetry-derived values after a service enters operational use, leaving the transition entirely at practitioner discretionIT Process Wiki (n.d.)ITIL v3 Service Design Chapter 4.3 (n.d.)
- ISO/IEC 20000-1:2018 Clause 8.6 uses mandatory "shall" language requiring organisations to monitor, measure, review, and report on capacity and performance, imposing a stricter measurement obligation than ITIL's "should" stance and excluding assertion-only baselines for ISO 20000-certified organisationsISO/IEC 20000-1:2018 (2018)
- Iden and Eikebrokk's 2013 systematic literature review of ITIL implementations found that capacity management is consistently among the least mature ITIL processes in practice, with data collection challenges and difficulty of predictive analysis identified as the primary barriers to maturity investmentEikebrokk (2013)
- ITIL's combination of assertion tolerance and the absence of a mandatory validation gate means that organisations relying solely on ITIL can remain in an assertion-based baseline posture indefinitely without formal non-compliance, and empirical implementation evidence indicates this pattern occurs in practiceIT Process Wiki (n.d.)Eikebrokk (2013)
Research Question
What does IT Infrastructure Library (ITIL) capacity management specify as the measurement practice for establishing a platform capability baseline, and where does it rely on assertion rather than telemetry?
Findings
(Populated from §6 Synthesis above.)
Executive Summary
IT Infrastructure Library (ITIL) capacity management specifies telemetry-based measurement as a recommended practice using "should" not "shall" throughout, in both ITIL v3/2011 and ITIL 4, which means telemetry is never a binding obligation under ITIL compliance alone. ITIL explicitly accommodates assertion-based baselines: the official Capacity Plan template includes an "Assumptions and database" section and specifically permits "assumed/estimated/agreed values" for new services, pending operational validation that ITIL itself never mandates. The boundary between assertion-acceptable and telemetry-required zones follows a gradient across ITIL v3's three sub-processes (Business, Service, and Component Capacity Management), with assertion tolerance highest at the business planning layer and lowest at the infrastructure component monitoring layer, but this gradient is implicit rather than explicitly governed in either ITIL version. ISO/IEC 20000-1:2018 Clause 8.6 imposes a stricter measurement obligation by mandating ("shall") ongoing empirical measurement of capacity and performance, but ISO 20000 certification is a separate requirement not implied by ITIL alignment.
Key Findings
-
ITIL v3/2011 and ITIL 4 both use "should" not "shall" for all capacity measurement data collection requirements, making telemetry-based baseline establishment a recommendation rather than a binding obligation under ITIL compliance alone.
-
The official ITIL Capacity Plan template formally accommodates assertion-based baselines by including an "Assumptions and database" section that explicitly states initial values for new services may be "assumed/estimated/agreed values, to be validated once operational."
-
ITIL v3 defines three sub-processes (BCM, SCM, CCM) each with a different measurement focus: Business Capacity Management (BCM) translates business demand plans into service requirements using forecasts and is more dependent on projected estimates, while Component Capacity Management (CCM) monitors individual infrastructure component utilisation directly, making CCM more telemetry-dependent than BCM.
-
ITIL 4 consolidated BCM, SCM, and CCM into a single "Capacity and Performance Management" practice, removing the explicit sub-process structure of ITIL v3 and making the assertion-to-telemetry gradient less visible to practitioners working from ITIL 4 guidance alone.
-
ITIL specifies no mandatory validation gate, deadline, or escalation mechanism requiring that assertion-based baselines be superseded by telemetry-derived values after a service enters operational use, leaving the transition entirely at practitioner discretion.
-
ISO/IEC 20000-1:2018 Clause 8.6 uses mandatory "shall" language requiring organisations to monitor, measure, review, and report on capacity and performance, imposing a stricter measurement obligation than ITIL's "should" stance and excluding assertion-only baselines for ISO 20000-certified organisations.
-
Iden and Eikebrokk's 2013 systematic literature review of ITIL implementations found that capacity management is consistently among the least mature ITIL processes in practice, with data collection challenges and difficulty of predictive analysis identified as the primary barriers to maturity investment.
-
ITIL's combination of assertion tolerance and the absence of a mandatory validation gate means that organisations relying solely on ITIL can remain in an assertion-based baseline posture indefinitely without formal non-compliance, and empirical implementation evidence indicates this pattern occurs in practice.
Assumptions
-
Assumption: ITIL 4 practice guides use "should" language consistently for capacity measurement data collection requirements. Justification: The ITIL 4 design philosophy explicitly emphasises adaptable guidance over prescriptive rules, as documented in PeopleCert's 2023 practices update; the "should" convention is confirmed for the practice's data collection requirements by multiple sources reproducing ITIL 4 practice content. Source: PeopleCert ITIL 4 Management Practices 2023
-
Assumption: The IT Process Wiki ITIL v3/2011 Capacity Plan template accurately represents the structure of AXELOS's published template. Justification: IT Process Wiki is widely cited by ITIL training providers and practitioners as a reference for ITIL v3/2011 process templates; no contradicting primary source was available within the access constraints of this investigation. Source: IT Process Wiki: Capacity Plan Checklist
Analysis
ITIL's capacity management framework creates a two-zone structure for baseline evidence, though this structure is never explicitly named or governed in ITIL text.
The first zone corresponds to Business Capacity Management: it is dominated by planning-stage inputs including transaction volume forecasts, growth projections, and stakeholder agreements. At this layer, assertion is structurally necessary because future business demands cannot be empirically measured in advance. The ITIL guidance explicitly relies on "trend, forecast, model or predict" techniques that combine historical telemetry with forward-looking assumptions.
The second zone corresponds to Component Capacity Management: monitoring individual infrastructure components (CPU, memory, storage, network) provides the directly observable data on which operational baselines are built. Even here, ITIL uses "should" rather than mandatory language.
ITIL provides no mandatory mechanism to enforce the transition from assertion to telemetry once a service is operational. The Capacity Plan template's "to be validated once operational" note carries no attached control: no specified deadline, no escalation trigger, and no formal review gate. This means the intended validation is an aspiration rather than a control.
ISO 20000's "shall" language imposes a stronger measurement obligation than ITIL's "should" stance on this control surface. An ISO 20000 audit requires demonstrable evidence of ongoing measurement: a Capacity Plan containing only agreed or assumed values without supporting operational telemetry would not satisfy Clause 8.6. The practical consequence is that the assertion tolerance permitted by ITIL alone is incompatible with ISO 20000 certification once a service is in operation.
The Iden and Eikebrokk (2013) empirical finding is consistent with this inference: organisations defer capacity management maturity because data collection is costly, and ITIL provides no mandatory gate that would force that investment. The primary driver the authors identify is the cost and difficulty of telemetry implementation, not the absence of a mandate; ITIL's lack of a mandatory validation gate removes the structural pressure that might otherwise force organisations to bear that cost. A plausible rival explanation is that organisations would defer telemetry investment regardless of what ITIL requires, because data collection is expensive; the absence of evidence that ISO 20000-certified organisations achieve measurably higher capacity management maturity than ITIL-only organisations would support that rival, but this comparison is outside the scope of the empirical literature reviewed here.
The companion completed research item on capability claim vs. production telemetry arbitration (github.com identified telemetry override as the most reliable arbitration mechanism for capability claim conflicts. The present findings establish that ITIL-aligned organisations may legitimately have no operational telemetry to override against, because ITIL does not require it to be collected. Where an organisation relies on an ITIL-compliant assertion-based baseline and has never established operational telemetry, the telemetry override pathway described in the arbitration item is structurally unavailable.
Risks, Gaps, and Uncertainties
- The ITIL 4 Capacity and Performance Management practice guide is available only via PeopleCert/AXELOS subscription. This investigation relied on secondary sources and official PeopleCert communications. If the primary practice text contains mandatory language not reflected in summaries, the inference about "should" dominance would require revision.
- ISO/IEC 20000-1:2018 is a paywalled standard. The Clause 8.6 text reproduced in this item is sourced from secondary guidance and cannot be independently verified without the purchased standard. All ISO 20000 "shall" language claims are therefore labeled [inference].
- The Iden and Eikebrokk (2013) journal article is access-restricted at the ScienceDirect URL. The finding about capacity management implementation maturity is widely cited in secondary sources, but verbatim confirmation requires journal access.
- Betz (2011) was a seeded source but the Pearson catalogue page does not reproduce content. That practitioner analysis is excluded from the evidence base.
- The investigation does not cover ITIL v2 (pre-2007) or sector-specific ITIL extensions that may impose stronger measurement requirements in regulated industries.
Open Questions
- Does assertion-vs-telemetry maturity differ across industry sectors (finance, public sector, technology), and does ISO 20000 certification adoption correlate with reduced assertion-based baseline use?
- What proportion of organisations claiming ITIL-aligned capacity management have established operational telemetry for their baselines rather than retaining assertion-based values?
- Does ITIL 4's removal of the BCM, SCM, CCM sub-process labels affect practitioner measurement decisions in observable ways, or do practitioners reconstruct the same gradient under the unified practice name?
sources
- [x] PeopleCert ITIL 4 Management Practices 2023: official ITIL 4 practice guidance update describing the Capacity and Performance Management practice and its 2023 revisions
- [x] IT Process Wiki: Capacity Management: secondary reference documenting ITIL v3/2011 Capacity Management sub-processes and information flows
- [x] IT Process Wiki: Capacity Plan Checklist: secondary reference containing the official ITIL Capacity Plan template including the "Assumptions and database" section
- [x] ITIL v3 Service Design Chapter 4.3: Capacity Management: secondary source reproducing ITIL v3 Service Design capacity management chapter text
- [x] ISO/IEC 20000-1:2018: IT Service Management System Requirements: ISO/IEC (International Electrotechnical Commission) standard codifying IT service management (ITSM) requirements including capacity management; uses "shall" language
- [x] Iden and Eikebrokk (2013) Implementing IT Service Management: A Systematic Literature Review: empirical systematic review of ITIL implementation evidence; found capacity management among the least mature processes