Change Enablement Explained
Change Enablement is the ITIL practice responsible for maximising the number of successful IT changes by ensuring risks are properly assessed, authorising changes to proceed, and managing the change schedule. It is not about performing the change itself — it is about governing whether and how a change happens.
The exam expects you to distinguish between three change types, and questions frequently hinge on identifying which type a described change falls into.
A standard change is low-risk, well-understood, and pre-authorised — it follows a defined, repeatable procedure and does not need individual authorisation each time. A common example is a routine password reset process or a pre-approved software patch that has been performed successfully many times before.
A normal change requires individual assessment, scheduling, and authorisation before it proceeds — because it is not routine enough to pre-approve, but is also not urgent enough to bypass the normal process. Most planned changes to production systems fall here, typically reviewed by a change authority (which may be a Change Advisory Board, though ITIL v5 does not mandate that specific body).
An emergency change must be implemented as soon as possible — typically to resolve a major incident or apply a critical security fix. Because there isn't time for the normal assessment process, emergency changes usually follow an expedited authorisation path, but they are still assessed and authorised, just faster and often by a smaller group.
A common exam trap is assuming 'emergency' means 'no authorisation required at all' — this is incorrect. Emergency changes are still authorised; the process is simply compressed to match the urgency.
A critical security vulnerability is discovered in a production system and must be patched within the next two hours to prevent active exploitation. Which type of change does this scenario describe?
Ready to test yourself on the full syllabus?