IT Service Catalogue Example: 72 IT Services
An IT service catalogue is the agreed list of the IT services an organisation relies on. Below is the catalogue behind our free Target Operating Model Builder: 72 IT services in six capability areas, each with a short description. Use it as a starting template for your own catalogue, then decide who should run each service.
What is an IT service catalogue?
An IT service catalogue lists the IT services that are live and available to the business, described in plain language so that IT and the rest of the organisation agree what each service is. For each service it usually records a short description, who can use it, how to request it, the hours and service levels that apply, and who owns it. ITIL treats the service catalogue as the single source of consistent information about the services IT provides, which makes it the natural starting point for any decision about support, cost or sourcing.
The 72 services in our IT service catalogue
The catalogue is grouped into six capability areas. Every area is a section in the Target Operating Model Builder, and you can add up to five services of your own to each one.
Service management processes (14 services)
The processes that keep IT controlled and improving, from strategy and tooling to incidents, changes and assets.
| Service | What it covers |
|---|---|
| IT Strategy & Technology Roadmap | Ownership of the IT strategy, technology roadmap and investment plan, aligned to business objectives. |
| ITSM Tooling & Platform | Provision, configuration and ongoing administration of the IT service management platform. |
| Incident Management | Restoring normal service as quickly as possible after an unplanned interruption, with the least impact on the business. |
| Major Incident Management | A coordinated response to high-severity incidents that materially disrupt services or affect many users. |
| Request Management | Fulfilment of standard requests such as access, equipment, software installations and information. |
| Problem Management | Investigating the underlying causes of recurring or major incidents to stop them happening again. |
| Change Management | Controlled assessment, approval, scheduling and review of changes to live services. |
| Release & Deployment Management | Planning, packaging and controlled rollout of software releases and infrastructure changes into production. |
| Knowledge Management | Capturing and reusing operational knowledge so issues are resolved faster and earlier. |
| Configuration Management (CMDB) | Recording and maintaining configuration items and their relationships in a configuration management database. |
| Asset Management | Tracking IT hardware and software assets from procurement and deployment through to refresh and disposal. |
| Continual Service Improvement | A structured cycle of measuring service performance and delivering improvements. |
| Project & Change Delivery | Scoped delivery of IT projects such as migrations, upgrades, office moves and new services, outside day-to-day running. |
| IT Procurement & Licensing | Sourcing and buying hardware, software and subscription licences through approved suppliers, including renewals. |
Service desk and service delivery (11 services)
How users get help, split by support line and by in-hours and out-of-hours cover, plus the reporting and management around it.
| Service | What it covers |
|---|---|
| First Line Service Desk In Hours | The single point of contact during business hours for user incidents and requests, with logging, triage and first-time resolution where possible. |
| Second Line Service Desk In Hours | Skilled technical support during business hours for tickets that first line cannot resolve, covering desktop, application and identity issues. |
| Third Line Service Desk In Hours | Expert support during business hours for complex issues across infrastructure, networks, cloud and core platforms. |
| First Line Service Desk Out of Hours | The single point of contact outside business hours, through nights, weekends and public holidays. |
| Second Line Service Desk Out of Hours | Skilled technical support outside business hours for tickets escalated from first line. |
| Third Line Service Desk Out of Hours | On-call expert support outside business hours for complex or critical incidents. |
| On-Site Support | Engineers attending offices or data centres for incidents and changes that cannot be resolved remotely. |
| Multilingual Support | Service desk support in several languages for users who work across countries. |
| Vendor Ticket Escalation | Managing tickets with software, hardware and connectivity vendors on the organisation's behalf until they are resolved. |
| Service Reporting & Dashboards | Reporting on service performance, SLA achievement, incident trends and user satisfaction. |
| Service Delivery Management | Named leadership accountable for service quality, governance, satisfaction and continual improvement. |
Technology management (15 services)
The day-to-day running of devices, networks, infrastructure, cloud platforms, data and backups.
| Service | What it covers |
|---|---|
| Business Application Support & Maintenance | Support and maintenance of business applications, including configuration, user administration, integrations and minor changes. |
| Endpoint Device Management | Provisioning, configuring, securing and managing the lifecycle of laptops, desktops and other user devices. |
| Mobile Device Management | Enrolling, configuring and securing corporate and personal mobile devices that access company data. |
| Network Device Management | Configuration, monitoring and lifecycle management of routers, switches, wireless and SD-WAN. |
| Connectivity Management | Management of internet and wide-area connectivity, including ISP relationships, fixed lines, broadband, MPLS and resilience links. |
| Voice & UC Management | Management of telephony, contact centre platforms, conferencing and unified communications. |
| Server, Storage & Infrastructure Management | Operational management of physical and virtual servers, storage and supporting infrastructure. |
| Data Centre Management | Management of data centre facilities, including space, power, cooling, cabling and physical access. |
| Workspace Platform Management (Microsoft 365 / Google Workspace) | Administration, hardening and optimisation of email, collaboration, file storage and messaging. |
| Identity Platform Management | Operation of the identity platform, including users, groups, policies and federation, for example Microsoft Entra ID, Active Directory or Google Cloud Identity. |
| Public Cloud Management (Azure / AWS / GCP) | Day-to-day operation, governance and optimisation of public cloud environments. |
| Database Management | Administration, performance tuning, backup checks and patching of database platforms. |
| Monitoring & Observability | Continuous monitoring of infrastructure, platforms and applications using metrics, logs and traces. |
| Infrastructure Backup Management | Backup, restore and replication for servers, storage and supporting infrastructure. |
| Workspace Backup Management (Microsoft 365 / Google Workspace) | Independent backup and restore of mailboxes, files, sites and chat, beyond the platform's own retention. |
Patch and vulnerability management (10 services)
Keeping every operating system, application and device patched, and finding and fixing vulnerabilities in order of risk.
| Service | What it covers |
|---|---|
| Windows Server Patching | Scheduled patching of Windows Server within change-controlled maintenance windows. |
| Windows Workstation Patching | Automated patch deployment to Windows endpoints, with phased rollouts and exception handling. |
| macOS Patching | Patch management for Apple devices, using mobile device management to deliver operating system updates and security patches. |
| Linux / Unix Server Patching | Kernel, package and security updates across Linux and Unix servers. |
| Non-OS Application Patching | Patching applications outside the operating system, such as browsers, runtimes and productivity tools. |
| Firmware & BIOS Patching | Firmware and BIOS updates for endpoints, servers and storage hardware. |
| Network Device Patching | Controlled firmware and software updates for routers, switches, firewalls, wireless controllers and load balancers. |
| Emergency & Zero-Day Patching | A rapid response process for critical zero-day and out-of-band vulnerabilities. |
| Vulnerability Scanning | Authenticated and unauthenticated scanning of servers, endpoints and network devices for known vulnerabilities. |
| Risk-Based Vulnerability Remediation | Fixing vulnerabilities in order of severity, exploitability and asset criticality. |
Cyber security management (13 services)
Detection, response, access control and data protection, plus the testing and training that show whether defences work.
| Service | What it covers |
|---|---|
| Security Event Monitoring (SIEM) | 24/7 collection, correlation and analysis of security events across the estate. |
| Managed Detection & Response (Endpoints) | Continuous monitoring of, and response to, threats on endpoints, using EDR or XDR tools and analysts. |
| Identity Threat Detection & Response (ITDR) | Detecting and responding to identity attacks such as credential theft, MFA fatigue and privilege abuse. |
| Access Management (SSO / MFA / Conditional Access) | Design and operation of single sign-on, multi-factor authentication and conditional access. |
| Privileged Access Management (PAM) | Control, monitoring and just-in-time elevation of privileged accounts. |
| Information Protection & Data Loss Prevention | Classifying sensitive information and enforcing policies that stop it being shared or moved inappropriately. |
| Network & Platform Security Management | Operation of firewalls, network access control, intrusion detection and prevention, and secure configuration. |
| Email & Web Security Management | Protection for email and web traffic, including anti-phishing, anti-malware and content filtering. |
| Cloud Security Posture Management (CSPM) | Continuous assessment and remediation of cloud configuration risks. |
| Security Incident Response (IR Retainer) | On-call incident response, with defined service levels, for security incidents beyond routine containment. |
| Phishing Simulation | Regular simulated phishing campaigns to test and improve how users respond to social engineering. |
| Cyber Awareness Training | Role-based security awareness training for all users. |
| Penetration Testing | Scheduled testing of external, internal and application estates by qualified testers. |
Governance, risk and compliance (9 services)
The certification, regulation, risk, policy and continuity work that shows the organisation is in control.
| Service | What it covers |
|---|---|
| Information Security Governance (ISO 27001 / SOC 2) | Running an information security management system aligned to ISO 27001, SOC 2 or a similar framework. |
| Cyber Essentials / Cyber Essentials Plus | Preparing for, implementing and certifying against the UK Cyber Essentials schemes. |
| Regulatory Compliance (GDPR / NIS2 / PCI DSS) | Operational support for regulations such as GDPR, NIS2, PCI DSS and sector frameworks. |
| Risk Management & Risk Register | Identifying, assessing, treating and monitoring information and operational risks through a risk register. |
| Policy & Standards Management | Writing, reviewing and maintaining IT and security policies, standards and procedures. |
| Audit Support & Evidence Management | Coordinating internal and external audits, including evidence, control walkthroughs and remediation of findings. |
| Business Continuity & Disaster Recovery Planning | Business continuity and disaster recovery plans, including business impact analysis, recovery objectives and exercises. |
| Supplier & Third-Party Risk Management | Due diligence and ongoing assurance of suppliers and SaaS providers. |
| Security Leadership (vCISO) | Named senior security leadership accountable for strategy, risk posture and board reporting. |
How to use this catalogue as a template
- Start with all 72 services. Mark any you do not run as Not Required, so the decision is still on record.
- Add the services that are specific to your organisation, up to five in each area.
- Decide who runs each service: your internal team, Managed247, a co-managed arrangement or another third party.
- Download your executive PDF and share it with your leadership team.
The Target Operating Model Builder takes you through all four steps in about ten minutes, free.
From service catalogue to target operating model
A service catalogue tells you what IT delivers. A target operating model tells you who should deliver it in future, and how the pieces are governed. Once your catalogue is agreed, the next step is to decide ownership for each service. Our guide to building a target operating model covers the full method, and our target operating model examples show how the mix looks for different organisations.
Frequently asked questions
-
What is an IT service catalogue?
An IT service catalogue is the agreed list of IT services that are live and available to the business. It describes each service in plain language and usually records who can use it, how to request it, the service levels that apply and who owns it.
-
What should an IT service catalogue include?
For each service: a name and plain description, who can use it, how to request it, the hours and service levels that apply, and who owns and delivers it. The ownership column is where a target operating model begins.
-
What is the difference between a service catalogue and a target operating model?
A service catalogue lists the services IT provides. A target operating model sets out how those services will be delivered in future, and by whom: the internal team, a managed provider, a co-managed arrangement or a specialist third party.
-
Is there a free IT service catalogue template?
Yes. The 72 services on this page are the catalogue inside our free Target Operating Model Builder. You can mark services as not required, add up to five of your own in each area, set who runs each one and download an executive PDF.
Map all 72 services in about ten minutes.
Free, with nothing to install. Or talk it through with our UK team.