13.2 DSS Deliver, Service, and Support

Key Takeaways

  • DSS is the 6-objective Deliver, Service and Support management domain — the run layer after BAI hands a solution to operations.
  • DSS02 Managed Service Requests and Incidents restores service and fulfills requests; DSS03 Managed Problems finds and removes root causes so incidents do not keep returning.
  • APO13 Managed Security defines and monitors the information security management system; DSS05 Managed Security Services runs day-to-day security operations.
  • DSS06 Managed Business Process Controls maintains controls inside in-house or outsourced business processes; MEA02 Managed System of Internal Control evaluates the overall control system.
  • DSS01 Managed Operations executes standard operating procedures; DSS04 Managed Continuity keeps critical business processes and required I&T services available through disruption.
Last updated: August 2026

Quick Answer: Deliver, Service and Support (DSS) is the 6-objective management domain that runs I&T after BAI transitions a change. DSS01 Managed Operations executes operational procedures for internal and outsourced services. DSS02 Managed Service Requests and Incidents restores service and fulfills user requests. DSS03 Managed Problems finds root causes so incidents do not recur. DSS04 Managed Continuity keeps critical business processes and required I&T services available through disruption. DSS05 Managed Security Services is day-to-day security operations — not APO13 Managed Security, which owns the information security management system (ISMS). DSS06 Managed Business Process Controls maintains controls inside business processes; MEA02 Managed System of Internal Control evaluates the system of internal control. Do not call a restored incident a solved problem.

DSS is the smallest build-or-run domain and one of the highest-yield ones, because Foundation stems love incident versus problem and security planning versus security operations. Six official titles. Zero governance titles. The service desk does not become the board because it is busy.

Where DSS sits

Management’s verb set is plan, build, run, and monitor. DSS is the run domain. APO planned. BAI built, acquired, and transitioned. DSS keeps the lights on, restores what breaks, removes what keeps breaking, survives a site-down event, operates security services, and keeps business-process controls alive while work is actually happening.

If a stem is still defining requirements or running a pilot, you are in BAI. If the engine is live and Monday’s queue is on fire, you are in DSS. If someone is later assessing whether the control system is adequate, you have stepped into MEA — the next section — not back into DSS06.

The six official objectives

IDOfficial titleOne-sentence purpose
DSS01Managed OperationsCoordinate and execute the operational procedures that deliver internal and outsourced I&T services, including monitoring of those procedures.
DSS02Managed Service Requests and IncidentsProvide timely response to user requests and restore normal service for all types of incidents.
DSS03Managed ProblemsIdentify and classify problems, find root causes, resolve them, and recommend improvements so incidents do not keep returning.
DSS04Managed ContinuityEstablish and maintain the ability to continue critical business processes and required I&T services through incidents and disruptions.
DSS05Managed Security ServicesProtect enterprise information in line with security policy through operational security roles, access privileges, and security monitoring.
DSS06Managed Business Process ControlsDefine and maintain controls so information processed by in-house or outsourced business processes meets control requirements.

DSS01 Managed Operations

DSS01 Managed Operations is the shift that actually runs. Coordinate and execute the activities and standard operating procedures required to deliver internal and outsourced I&T services, and monitor those activities. Scheduling, job execution, backup execution, facilities procedures, and the outsourced runbook all sit here when they are operations, not projects.

DSS01 is easy to skip on a flashcard because it looks like “just operations.” The exam uses it as the home for run-the-engine work that is not an incident, not a problem, not a continuity event, and not a security service. Northline’s nightly claims batch, the vendor’s contracted operating hours, and the monitoring that those procedures actually ran are DSS01. A failed batch that users feel becomes a DSS02 incident. A batch that fails every Monday for the same reason becomes a DSS03 problem. The procedure of running the batch is still DSS01.

High-yield pair 1: DSS02 versus DSS03

Memorize this pair until it is automatic.

LensDSS02 Managed Service Requests and IncidentsDSS03 Managed Problems
ObjectA user request, or an unplanned interruption / reduction of serviceThe underlying cause of one or more incidents
JobRecord and fulfill requests; record, investigate, diagnose, escalate, and restore incidentsIdentify, classify, find root cause, resolve, and recommend improvement
SuccessService is back, or the request is doneThe failure mode is removed or mitigated so it does not keep returning
Time senseNow — restore and fulfillNext — stop the recurrence
Northline pictureMobile app is down for 400 users; the desk restores service in 20 minutesThe same crash has happened four Mondays; a team traces a capacity leak and removes it

DSS02 has two official objects in one title: service requests and incidents. A password reset is a request. A severity-1 outage is an incident. Both are DSS02. Neither is a problem until someone treats the cause as the object of work.

DSS03 Managed Problems is not a slow incident. It is a different objective. Restore first (DSS02), then decide whether the pattern deserves root-cause work (DSS03). An enterprise that only restores, and never hunts causes, has DSS02 without DSS03. An enterprise that refuses to restore until the permanent fix is designed has inverted the pair — users stay down while someone writes a five-why.

ITIL language will appear as flavor in stems. Use it as a hint, not as a license to invent COBIT titles. The official COBIT 2019 names remain Managed Service Requests and Incidents and Managed Problems.

DSS04 Managed Continuity

DSS04 Managed Continuity establishes and maintains a plan so the business and IT can respond to incidents and disruptions, continue critical business processes and required I&T services, and keep information available at a level the enterprise accepts.

Continuity is not “the incident lasted a long time.” A DSS02 incident restores a service that is supposed to be up now. DSS04 is the capability to keep or recover critical work when the normal environment is not available — site loss, regional outage, ransomware that takes the claims engine offline for days. Northline’s regional failover, the paper-claims fallback that is actually rehearsed, and the recovery time the business will accept are DSS04.

Do not steal this job with BAI04 Managed Availability and Capacity. BAI04 designs availability and capacity into the change. DSS04 is the run-domain continuity capability after disruption. Do not steal it with EDM03 Ensured Risk Optimization either. The board sets appetite. Management runs continuity.

High-yield pair 2: APO13 versus DSS05

Chapter 12 already stacked risk and security. Repeat the operational half until you cannot miss it.

AltitudeOfficial objectiveJob
GovernanceEDM03 Ensured Risk OptimizationBoard appetite and tolerance; I&T-related risk identified and managed at board altitude
Management planningAPO12 Managed RiskContinual identification, assessment, and treatment of I&T risk within tolerance
Management planningAPO13 Managed SecurityDefine, operate, and monitor an ISMS
Management runDSS05 Managed Security ServicesDay-to-day security services: access privileges, vulnerability handling, security monitoring, operational protection

DSS05 Managed Security Services protects enterprise information so operational security risk stays acceptable in accordance with the security policy. It establishes and maintains information-security roles and access privileges and performs security monitoring. That is the SOC shift, the access-granting desk, the vulnerability scan that actually runs, the SIEM that someone watches.

APO13 Managed Security is the ISMS — the management system that defines how security is governed as a system of policies, roles, control objectives, and ISMS monitoring. Northline can buy a SIEM (DSS05-flavored) and still fail APO13 if nobody owns the ISMS. It can write a beautiful ISMS and still fail DSS05 if nobody grants access correctly or watches the alerts. Neighbors, not twins. Neither title is Ensured. Neither is a project in BAI.

High-yield pair 3: DSS06 versus MEA02

DSS06 Managed Business Process Controls defines and maintains appropriate business process controls so information related to and processed by in-house or outsourced business processes satisfies information-control requirements. Application input edits, segregation of duties inside the claims workflow, maker-checker on a payment, and the control that still applies when a vendor runs the process all sit here.

MEA02 Managed System of Internal Control — taught fully in the next section — continuously monitors and evaluates the control environment as a system. DSS06 puts and keeps controls in the process. MEA02 assesses whether the system of internal control is adequate. A stem about embedding an edit in the claims payment process is DSS06. A stem about management evaluating whether the internal-control system as a whole still works is MEA02.

Do not call DSS06 “audit.” Do not call it “the ISMS.” Do not promote it to EDM. It is a run-domain management objective about business process and application controls where the work happens, including when that work is outsourced.

Scenario: Monday on the Northline service floor

The digital-claims engine is live. Watch the IDs.

  1. DSS01 runs the overnight batch and the vendor operating procedures. Monitoring shows the batch completed.
  2. At 8:10 the mobile app fails for 400 users. DSS02 records the incident, diagnoses, escalates, and restores service in twenty minutes. A separate queue fulfills access requests from new adjusters — also DSS02, because requests live in the same official title.
  3. The same crash has now happened four Mondays. DSS03 opens a problem, classifies it, finds a capacity leak BAI04 should have caught, and recommends a permanent fix so Monday does not keep repeating.
  4. A regional fiber cut later that week takes the primary site offline. DSS04 invokes continuity: failover, the accepted information-availability level, continuation of critical claims intake. This is not “a long incident.” It is continuity.
  5. While the site is degraded, DSS05 watches access and security monitoring so the failover path does not become an open door. The ISMS that says this must happen is still APO13; the service that does it on the shift is DSS05.
  6. Through all of it, DSS06 keeps maker-checker on claim payments — including the outsourced overflow team — so a continuity event is not an excuse to skip process controls. Next quarter, MEA02 will evaluate whether that control system, as a system, is still adequate. That later evaluation is not DSS06.

Exam traps

  • Incident = problem. DSS02 restores and fulfills. DSS03 removes root causes.
  • DSS02 as incidents only. The official title is Managed Service Requests and Incidents.
  • APO13 = DSS05. ISMS versus security services.
  • DSS06 = MEA02. Process/application controls versus the system of internal control.
  • DSS04 as a long DSS02 ticket. Continuity is a planned capability for disruption, not a slow restore.
  • DSS01 as the whole run domain. Operations is one of six official titles.
  • Calling DSS governance because operations feels “in charge.” Only EDM is governance.

Prefer the answer that keeps all six official titles, keeps restore separate from root cause, keeps the ISMS above security services, and keeps process controls below the MEA02 control-system evaluation.

Loading diagram...
DSS run domain: operations, incident versus problem, continuity, security services, process controls
Test Your Knowledge

The claims mobile app fails for 400 users. The desk restores service in 20 minutes, then a separate team hunts the recurring root cause. Which pair is correct?

A
B
C
D
Test Your Knowledge

How do APO13 Managed Security and DSS05 Managed Security Services differ?

A
B
C
D
Test Your Knowledge

What is the purpose of DSS06 Managed Business Process Controls, and how does it differ from MEA02 Managed System of Internal Control?

A
B
C
D