EXIN EX0-115: Legacy IT Service Management Foundation and the ISO/IEC 20000:2018 Path
IT service management is the discipline of organizing people, processes, technology, suppliers, information, and continual improvement around services that create value for customers and users. A service can depend on many technical components, but users experience the outcome as one service. Foundation-level knowledge therefore focuses on how an organization plans, delivers, supports, measures, and improves services consistently rather than managing each server or application in isolation.
EXIN EX0-115 is the legacy exam code for IT Service Management Foundation based on ISO/IEC 20000. EXIN’s current qualification is IT Service Management Foundation based on ISO/IEC 20000:2018. The older code remains useful for core ITSM concepts, but candidates in 2026 should prepare against the current ISO/IEC 20000:2018 syllabus and current EXIN materials rather than assuming historical wording or standard references remain unchanged.
An IT service enables customers to achieve outcomes without requiring them to manage every underlying cost and risk directly. The provider still needs to understand the people, technology, information, suppliers, and processes required to deliver that result reliably.
Value depends on more than technical uptime. A payroll service can have healthy servers but still fail the business if users cannot authenticate or payments are processed incorrectly. Service thinking connects technical components with the outcome customers and users actually need.
Service ownership should therefore be clear. One accountable owner can coordinate technical teams, suppliers, service levels, risks, improvements, and customer communication even when no single team controls every underlying component.
The EXIN certifications page provides the wider vendor context. Current study should use the live ISO/IEC 20000:2018 foundation path as the authority for terminology and exam scope.
ISO/IEC 20000:2018 describes a service management system that gives the organization a structured way to establish policy, objectives, responsibilities, planning, support, operation, performance evaluation, and improvement for service management.
The SMS should be connected to business objectives rather than run as a documentation exercise. Management needs to know which services are in scope, who owns them, which customers and suppliers are involved, what resources are required, and how performance will be measured.
Documented information should support operation and evidence. Procedures, policies, service records, agreements, change records, incident data, and improvement actions are useful when they help people perform work consistently and demonstrate that the system operates as intended.
Internal audit and management review help determine whether the SMS is working beyond daily operations. Findings, customer feedback, service performance, risks, supplier issues, and improvement status should lead to management action rather than become static compliance records.
Services need defined customers, users, owners, scope, dependencies, and service-level expectations. Service agreements should focus on measurable commitments that matter to the customer rather than metrics chosen only because they are easy for the provider to collect.
Supplier relationships are part of the service. A cloud provider, telecom carrier, software vendor, data-centre operator, or managed-service partner can affect the customer outcome even when the internal IT team does not operate that component directly.
Supplier performance should therefore be monitored against the service need, and contracts should define responsibilities, escalation, security, continuity, and exit expectations where relevant. Outsourcing a component does not outsource accountability for the customer experience.
Relationship management also includes understanding changing customer needs. A service level that was acceptable two years ago can become inadequate after business growth, regulatory change, or a move to 24-hour operations.
An incident is an unplanned interruption, reduction in quality, or event that needs restoration. The immediate goal is to restore normal service as quickly as reasonable while managing business impact and preserving useful evidence.
Service requests are different because they represent standard user needs such as information, access, or a predefined change. Treating routine requests as incidents can distort operational metrics and create unnecessary urgency.
Priority should reflect impact and urgency. One executive with a minor issue can be less important than a widespread outage affecting a critical business process. Escalation, communication, ownership, and target times should be defined so response is consistent under pressure.
Major incidents need coordinated communication as well as technical work. Customers, management, suppliers, and support teams should receive appropriate updates while responders keep a reliable timeline of actions and decisions.
Problem management looks beyond immediate restoration to identify causes, contributing factors, known errors, and opportunities to prevent repeat incidents. Not every incident requires a separate deep investigation, so organizations should prioritize recurring, high-impact, or strategically important issues.
Workarounds can restore service while a permanent fix is prepared, but they should be documented and controlled. A workaround that becomes permanent without review can create new risk and hide the need for a proper solution.
Trend analysis can reveal problems that one incident does not make obvious. Repeated authentication failures, capacity alerts, or service restarts may each look minor until the pattern shows a systemic weakness.
Changes can fix incidents, deliver new capability, improve security, or update infrastructure, but they can also cause outages. Change control should assess risk, impact, dependencies, timing, testing, authorization, communication, and rollback in proportion to the change.
Standard low-risk repeatable changes can follow a pre-authorized model, while significant production changes need stronger review. Emergency changes still need ownership, evidence, and post-change review even when normal lead times are impossible.
Release and deployment activities should ensure that changes are introduced into live service in a controlled way. Technical success is not enough; monitoring, support documentation, user communication, training, and recovery procedures should be ready before the new or changed service is considered operational.
When a change fails, restoration is only the first step. Review why testing, dependency analysis, authorization, timing, or rollback did not prevent the impact, and use that evidence to improve the change model for future work.
Availability management considers whether services are accessible when agreed, while capacity management considers whether resources can support current and future demand. Both should be based on business needs rather than maximum technical performance everywhere.
Service continuity prepares the organization to maintain or restore critical services after major disruption. Recovery time, data loss, suppliers, alternate sites, cloud dependencies, communications, and manual workarounds can all affect whether the business can continue.
Information security protects confidentiality, integrity, and availability within the service context. Access control, supplier security, incident handling, encryption, backup, logging, and risk management should support the service and its customer obligations.
The related EXIN ISMP source exam develops security management in more depth. ITSM candidates should understand how security requirements fit inside service planning and operation even when a specialist security team owns detailed implementation.
Organizations should measure service performance, incidents, requests, changes, supplier outcomes, capacity, availability, customer satisfaction, and other indicators that support decisions. Metrics become harmful when teams optimize the number instead of the service outcome.
Continual improvement uses data, feedback, audits, incidents, problems, changes, customer needs, and business priorities to select improvements deliberately. An improvement should have an owner, objective, expected benefit, measurement method, and review.
Management review and internal audit provide additional evidence about whether the service management system is effective. Findings should lead to corrective action rather than become annual reports that do not change operations.
Improvement can be incremental. Reducing repeated request delays, improving monitoring coverage, clarifying supplier escalation, or automating one safe standard change can produce meaningful service value when the result is measured and sustained.
EX0-115 reflects an older EXIN IT Service Management Foundation generation based on earlier ISO/IEC 20000 material. EXIN’s current active Foundation exam is based on ISO/IEC 20000:2018 and emphasizes the introduction to ITSM, the service management system, and operation of the SMS.
Build a study map from old EX0-115 subjects into the current syllabus. Durable concepts such as service value, agreements, incidents, problems, changes, suppliers, availability, continuity, security, measurement, and improvement remain useful, but standard clauses, terminology, and exam references should come from current materials.
A useful scenario is one business service supported by an internal application team, cloud provider, service desk, network supplier, and security team. Introduce a major incident, failed change, supplier outage, and capacity problem, then explain ownership, communication, restoration, problem follow-up, measurement, and improvement.
Finish the scenario with a quarterly service review: compare actual service levels, customer feedback, major incidents, supplier performance, open risks, failed changes, capacity trends, audit findings, and improvement actions. Decide which one or two changes should receive priority next and explain the evidence behind that choice.
Verify the live EXIN syllabus once more before the exam so current wording, materials, and ISO/IEC 20000:2018 emphasis are reflected in your final study plan.
That approach preserves the conceptual value of EXIN EX0-115 while keeping current preparation aligned to the active ISO/IEC 20000:2018 certification instead of treating a legacy code as today’s exam.
