Resources · Target Operating Model

IT Service Catalogue Example: 72 IT Services

An IT service catalogue is the agreed list of the IT services an organisation relies on. Below is the catalogue behind our free Target Operating Model Builder: 72 IT services in six capability areas, each with a short description. Use it as a starting template for your own catalogue, then decide who should run each service.

What is an IT service catalogue?

An IT service catalogue lists the IT services that are live and available to the business, described in plain language so that IT and the rest of the organisation agree what each service is. For each service it usually records a short description, who can use it, how to request it, the hours and service levels that apply, and who owns it. ITIL treats the service catalogue as the single source of consistent information about the services IT provides, which makes it the natural starting point for any decision about support, cost or sourcing.

The 72 services in our IT service catalogue

The catalogue is grouped into six capability areas. Every area is a section in the Target Operating Model Builder, and you can add up to five services of your own to each one.

Service management processes (14 services)

The processes that keep IT controlled and improving, from strategy and tooling to incidents, changes and assets.

ServiceWhat it covers
IT Strategy & Technology RoadmapOwnership of the IT strategy, technology roadmap and investment plan, aligned to business objectives.
ITSM Tooling & PlatformProvision, configuration and ongoing administration of the IT service management platform.
Incident ManagementRestoring normal service as quickly as possible after an unplanned interruption, with the least impact on the business.
Major Incident ManagementA coordinated response to high-severity incidents that materially disrupt services or affect many users.
Request ManagementFulfilment of standard requests such as access, equipment, software installations and information.
Problem ManagementInvestigating the underlying causes of recurring or major incidents to stop them happening again.
Change ManagementControlled assessment, approval, scheduling and review of changes to live services.
Release & Deployment ManagementPlanning, packaging and controlled rollout of software releases and infrastructure changes into production.
Knowledge ManagementCapturing and reusing operational knowledge so issues are resolved faster and earlier.
Configuration Management (CMDB)Recording and maintaining configuration items and their relationships in a configuration management database.
Asset ManagementTracking IT hardware and software assets from procurement and deployment through to refresh and disposal.
Continual Service ImprovementA structured cycle of measuring service performance and delivering improvements.
Project & Change DeliveryScoped delivery of IT projects such as migrations, upgrades, office moves and new services, outside day-to-day running.
IT Procurement & LicensingSourcing and buying hardware, software and subscription licences through approved suppliers, including renewals.

Service desk and service delivery (11 services)

How users get help, split by support line and by in-hours and out-of-hours cover, plus the reporting and management around it.

ServiceWhat it covers
First Line Service Desk In HoursThe single point of contact during business hours for user incidents and requests, with logging, triage and first-time resolution where possible.
Second Line Service Desk In HoursSkilled technical support during business hours for tickets that first line cannot resolve, covering desktop, application and identity issues.
Third Line Service Desk In HoursExpert support during business hours for complex issues across infrastructure, networks, cloud and core platforms.
First Line Service Desk Out of HoursThe single point of contact outside business hours, through nights, weekends and public holidays.
Second Line Service Desk Out of HoursSkilled technical support outside business hours for tickets escalated from first line.
Third Line Service Desk Out of HoursOn-call expert support outside business hours for complex or critical incidents.
On-Site SupportEngineers attending offices or data centres for incidents and changes that cannot be resolved remotely.
Multilingual SupportService desk support in several languages for users who work across countries.
Vendor Ticket EscalationManaging tickets with software, hardware and connectivity vendors on the organisation's behalf until they are resolved.
Service Reporting & DashboardsReporting on service performance, SLA achievement, incident trends and user satisfaction.
Service Delivery ManagementNamed leadership accountable for service quality, governance, satisfaction and continual improvement.

Technology management (15 services)

The day-to-day running of devices, networks, infrastructure, cloud platforms, data and backups.

ServiceWhat it covers
Business Application Support & MaintenanceSupport and maintenance of business applications, including configuration, user administration, integrations and minor changes.
Endpoint Device ManagementProvisioning, configuring, securing and managing the lifecycle of laptops, desktops and other user devices.
Mobile Device ManagementEnrolling, configuring and securing corporate and personal mobile devices that access company data.
Network Device ManagementConfiguration, monitoring and lifecycle management of routers, switches, wireless and SD-WAN.
Connectivity ManagementManagement of internet and wide-area connectivity, including ISP relationships, fixed lines, broadband, MPLS and resilience links.
Voice & UC ManagementManagement of telephony, contact centre platforms, conferencing and unified communications.
Server, Storage & Infrastructure ManagementOperational management of physical and virtual servers, storage and supporting infrastructure.
Data Centre ManagementManagement of data centre facilities, including space, power, cooling, cabling and physical access.
Workspace Platform Management (Microsoft 365 / Google Workspace)Administration, hardening and optimisation of email, collaboration, file storage and messaging.
Identity Platform ManagementOperation of the identity platform, including users, groups, policies and federation, for example Microsoft Entra ID, Active Directory or Google Cloud Identity.
Public Cloud Management (Azure / AWS / GCP)Day-to-day operation, governance and optimisation of public cloud environments.
Database ManagementAdministration, performance tuning, backup checks and patching of database platforms.
Monitoring & ObservabilityContinuous monitoring of infrastructure, platforms and applications using metrics, logs and traces.
Infrastructure Backup ManagementBackup, restore and replication for servers, storage and supporting infrastructure.
Workspace Backup Management (Microsoft 365 / Google Workspace)Independent backup and restore of mailboxes, files, sites and chat, beyond the platform's own retention.

Patch and vulnerability management (10 services)

Keeping every operating system, application and device patched, and finding and fixing vulnerabilities in order of risk.

ServiceWhat it covers
Windows Server PatchingScheduled patching of Windows Server within change-controlled maintenance windows.
Windows Workstation PatchingAutomated patch deployment to Windows endpoints, with phased rollouts and exception handling.
macOS PatchingPatch management for Apple devices, using mobile device management to deliver operating system updates and security patches.
Linux / Unix Server PatchingKernel, package and security updates across Linux and Unix servers.
Non-OS Application PatchingPatching applications outside the operating system, such as browsers, runtimes and productivity tools.
Firmware & BIOS PatchingFirmware and BIOS updates for endpoints, servers and storage hardware.
Network Device PatchingControlled firmware and software updates for routers, switches, firewalls, wireless controllers and load balancers.
Emergency & Zero-Day PatchingA rapid response process for critical zero-day and out-of-band vulnerabilities.
Vulnerability ScanningAuthenticated and unauthenticated scanning of servers, endpoints and network devices for known vulnerabilities.
Risk-Based Vulnerability RemediationFixing vulnerabilities in order of severity, exploitability and asset criticality.

Cyber security management (13 services)

Detection, response, access control and data protection, plus the testing and training that show whether defences work.

ServiceWhat it covers
Security Event Monitoring (SIEM)24/7 collection, correlation and analysis of security events across the estate.
Managed Detection & Response (Endpoints)Continuous monitoring of, and response to, threats on endpoints, using EDR or XDR tools and analysts.
Identity Threat Detection & Response (ITDR)Detecting and responding to identity attacks such as credential theft, MFA fatigue and privilege abuse.
Access Management (SSO / MFA / Conditional Access)Design and operation of single sign-on, multi-factor authentication and conditional access.
Privileged Access Management (PAM)Control, monitoring and just-in-time elevation of privileged accounts.
Information Protection & Data Loss PreventionClassifying sensitive information and enforcing policies that stop it being shared or moved inappropriately.
Network & Platform Security ManagementOperation of firewalls, network access control, intrusion detection and prevention, and secure configuration.
Email & Web Security ManagementProtection for email and web traffic, including anti-phishing, anti-malware and content filtering.
Cloud Security Posture Management (CSPM)Continuous assessment and remediation of cloud configuration risks.
Security Incident Response (IR Retainer)On-call incident response, with defined service levels, for security incidents beyond routine containment.
Phishing SimulationRegular simulated phishing campaigns to test and improve how users respond to social engineering.
Cyber Awareness TrainingRole-based security awareness training for all users.
Penetration TestingScheduled testing of external, internal and application estates by qualified testers.

Governance, risk and compliance (9 services)

The certification, regulation, risk, policy and continuity work that shows the organisation is in control.

ServiceWhat it covers
Information Security Governance (ISO 27001 / SOC 2)Running an information security management system aligned to ISO 27001, SOC 2 or a similar framework.
Cyber Essentials / Cyber Essentials PlusPreparing for, implementing and certifying against the UK Cyber Essentials schemes.
Regulatory Compliance (GDPR / NIS2 / PCI DSS)Operational support for regulations such as GDPR, NIS2, PCI DSS and sector frameworks.
Risk Management & Risk RegisterIdentifying, assessing, treating and monitoring information and operational risks through a risk register.
Policy & Standards ManagementWriting, reviewing and maintaining IT and security policies, standards and procedures.
Audit Support & Evidence ManagementCoordinating internal and external audits, including evidence, control walkthroughs and remediation of findings.
Business Continuity & Disaster Recovery PlanningBusiness continuity and disaster recovery plans, including business impact analysis, recovery objectives and exercises.
Supplier & Third-Party Risk ManagementDue diligence and ongoing assurance of suppliers and SaaS providers.
Security Leadership (vCISO)Named senior security leadership accountable for strategy, risk posture and board reporting.

How to use this catalogue as a template

  1. Start with all 72 services. Mark any you do not run as Not Required, so the decision is still on record.
  2. Add the services that are specific to your organisation, up to five in each area.
  3. Decide who runs each service: your internal team, Managed247, a co-managed arrangement or another third party.
  4. Download your executive PDF and share it with your leadership team.

The Target Operating Model Builder takes you through all four steps in about ten minutes, free.

From service catalogue to target operating model

A service catalogue tells you what IT delivers. A target operating model tells you who should deliver it in future, and how the pieces are governed. Once your catalogue is agreed, the next step is to decide ownership for each service. Our guide to building a target operating model covers the full method, and our target operating model examples show how the mix looks for different organisations.

FAQs

Frequently asked questions

  • What is an IT service catalogue?

    An IT service catalogue is the agreed list of IT services that are live and available to the business. It describes each service in plain language and usually records who can use it, how to request it, the service levels that apply and who owns it.

  • What should an IT service catalogue include?

    For each service: a name and plain description, who can use it, how to request it, the hours and service levels that apply, and who owns and delivers it. The ownership column is where a target operating model begins.

  • What is the difference between a service catalogue and a target operating model?

    A service catalogue lists the services IT provides. A target operating model sets out how those services will be delivered in future, and by whom: the internal team, a managed provider, a co-managed arrangement or a specialist third party.

  • Is there a free IT service catalogue template?

    Yes. The 72 services on this page are the catalogue inside our free Target Operating Model Builder. You can mark services as not required, add up to five of your own in each area, set who runs each one and download an executive PDF.

Map all 72 services in about ten minutes.

Free, with nothing to install. Or talk it through with our UK team.