Configuration Management
Database
A Service-aware IT But there’s a better way to solve these
Configuration Library challenges. A CMDB is a purpose-built
system for storing your IT infrastructure
With so much of the modern enterprise
and its relationship to each other. But the
powered by IT, visibility into IT
CMDB doesn’t just contain information
infrastructure is mission critical. But as
about your IT environment. It also puts
IT infrastructure continues to grow and
business context around it and helps
become more complex due to multi-cloud
IT organization become service oriented.
environments, serverless compute, and
Incident management, problem manage-
containerization, visibility into infrastructure
is like tracking a moving target. ment, and change management are core
functions in IT service management (ITSM).
For IT to gain visibility, it faces the chal-
The configuration management database
lenge of consolidating, maintaining, and
(CMDB) consolidates disparate IT man-
understanding complex configuration
agement systems into a single system
data. Often this data is found in many
different repositories, making it even of action.
harder for IT to find business service is- Unfortunately, many companies have
sues arising as a result of infrastructure struggled with CMDB projects and
changes. failed to realize the value it can provide.
They have a reputation for failed starts, or weekly. These activities are powered
lengthy implementations, and ongoing by Kubernetes and other container
maintenance challenges. This whitepaper orchestration engines on PaaS or public
provides you with the fundamentals cloud environments. A healthy CMDB
to help ensure your configuration data is the foundation to manage changes
management project with CMDB is a in these dynamic environments. It also
success. allows you can also understand the
complex relationships among this
Opening new value stream infrastructure supporting critical
with CMDB business services.
Enterprises use CMDB as a foundation Let’s take a detailed look at some of the
for IT service management but the value leading IT organization use cases where
does not end there. CMDB is the foun- CMDB improves existing processes and un-
dation for IT Operational Management, locks new value streams for the business.
Asset Management, Security Operation
Management , providing Audit/Compliance Experian’s CMDB success
capabilities.
Experian is a global company with
When CMDB becomes the configuration
thousands of employees in many
system of record, organizations see
countries. In 2016 they began their Service
benefits such as:
Central CMDB journey with a migration
• Reduced incident volume from an existing primary technology
• Reduced number of system outages asset repository to ServiceNow CMDB.
They leveraged service automation and
• Improved vulnerability response
orchestration opportunities using the
• Increased automation to respond platform. They expanded the reach of
to issues faster CMDB by building an automated feder-
Increasingly, CMDB is evolving from be- ated model, sourcing data from Qualys,
ing applicable for ITIL to now being rel- Tanium, FireEye, and other authoritative
evant for DevOps. IDC sees that 48% of sources. Next they leveraged CMDB to
organizations with DevOps deployed will build robust and automated business
release new code monthly service maps to further facilitate impact
and risk assessment for internal and client they start is important in improving
facing products. Next came development service availability, but it also reduces
of an automated method of identifying the run-rate workload for IT operations
and eliminating duplicate configuration teams. These teams spend huge
records to help further reduce manual amounts of time trying to make
processes. Finally, they added cloud sense of events from their monitoring
management with support for account systems. Often, the first time that IT
operations knows about a business
inventory management, along with
service outage is when end users
normalization of discovery approach.
complain. By integrating an event
Any organization’s IT functions can management solution with your
benefit from adopting CMDB. Some of CMDB, you can tackle this problem
the primary use cases include: head-on.
• IT service management is more
Event management combined with
efficient with CMDB. Configuration your service maps make diagnosing
Items (CIs) mapped to business ser- service outages much simpler
vices will improve the service desk because you can see how issues are
readiness and resolve issues fast- propagating across the business
er. When this mapping is in place, service. By linking remediation actions
both IT and business partners are to CIs, you don’t just diagnose service
on the same page about tracking outages faster — you fix them faster.
issues in impacted services. With
Save more with software asset
service maps, you know which busi-
management. Asset manage-
ness services are affected and can ment is usually considered a
plan accordingly. As a result, IT can financial function. A configu-
launch or resolve incidents rapidly ration management platform
since they have better visibility of can be used to track physical assets,
the infrastructure changes. software assets, and consumables.
What if you can have software asset
data in the same place where you
• Manage system outages in a better
manage IT? This way IT teams can track
way. Being proactive in stopping
where are all the installed assets and
business service outages before their utilization in a single platform.
• Respond to security vulnerabilities Building a Configuration
faster. A single source of truth — the Management Database (CMDB)
CMDB — is likewise a valuable tool for the Modern Enterprise
for security management teams. The
The fundamental building block of a CMDB
CMDB offers easy access to data,
is the CI (configuration item). A CI represents
which is useful to security manage-
an item under configuration management,
ment. Security teams can leverage
such as a router, a server, an application,
the CMDB to map threats, security
or even a logical construct such as a busi-
incidents, and discover vulnerabilities ness service.
in your IT infrastructure.
CMDB manages data for on-premises
and cloud environments. For example, it
Meet compliance requirements can store data from cloud resources such
with ease. Practically every as virtual machines, containers, or cloud
organization in every industry datacenters. This is to accommodate for
today is subject to various the complex environments of todays IT
regulatory requirements such operations. A properly maintained CMDB
as Sarbanes–Oxley (SOX), Health Insur- allows IT to have insight into the critical
ance Portability and Accountability business services that run on the IT
(HIPAA), and Payment Card Industry
infrastructure. This allows organizations
Data Security Standard (PCI DSS).
to better engage customers, drive
Additionally, many organizations are
revenues, increase efficiency, and create
subject to federal government regula-
new business insights. Service maps give
tions and certification programs.
IT this visibility. They visualize the CIs that
Although these various regulations
differ in their requirements, they all support a particular business service
share the common goal of ensuring and how these CIs are related to improve
that sensitive data and systems are visibility of your products and services.
appropriately secured, and proper These service maps are derived from CIs
governance and accountability is held directly in your CMDB, connecting
established. The CMDB is an essential your business services to your infrastruc-
tool to help organizations meet their ture. Then you can use AI processes such
audit and compliance needs. as machine learning, advanced analytics,
and actionable intelligence to benefit from Your configuration management
this visibility of your business services. platform should have the
capability to regularly poll for
Manually entering information about CIs or receive events from cloud
is time-consuming and can be error-prone. resources, to automatically create
Even in a small organization, too many CIs, and manag e their life cycles as
appropriate.
changes take place and manual entry
cannot be depended on for very long.
Keeping the Database Healthy
Yet, many organizations start out using
and Trusted
this method to establish their CMDB
Change is a major cause of service outages
before automated processes are created. and yet change is an everyday part of IT
infrastructures. With a healthy CMDB you
Automated technologies that can discover
can evaluate the impact of these daily
CIs are the most efficient, repeatable,
changes and respond to them properly to
and accurate method for populating the
quickly fix or prevent service outages.
CMDB. The CMDB will ensure the most
Most organizations face difficult challenges
recent and accurate profile of the CI is
when implementing a CMDB. A con-
loaded. Mature automated technologies
figuration item (CI) is the fundamental
also can map the relationship between
structural management unit of the CMDB.
business services and underlying infra-
Everything IT supports is ultimately
structure.
expressed in terms of CIs. Thus, the quality
Some data cannot be gathered of CI data will be an essential tenet of your
automatically, such as business ability to effectively communicate the current
and organizational information. state of items powering your services.
Information about people can-
The configuration management
not be gathered by a scan of the net-
team should be relentless in
work and must be entered manually.
challenging the IT organization
Depending on your organization, you to improve CI data quality. You
may have a number of other business need to put technology and processes
strategic information that will require in place to ensure that the data within
manual input, too. your CMDB remains accurate.
Addressing the challenge of keeping the Configuration management is an ongoing
CMDB healthy is vital. Preventing bad discipline in any organization. Changes
data is your first line of defense. This come from the evolution of corporate
involves creating identification rules for CI strategies that are then translated into
and attribute population and reviewing technology decisions that then need to be
every automation method that updates implemented.
the CMDB. The second line of defense
It’s important to regularly measure your
is having regular reports run of the data
effectiveness and benefit to the organi-
looking for CI issues and bringing them
zation. You should collect metrics on the
to the attention of the configuration
management team. Common CI issues following:
include duplicate CIs, CMDB de-duplication • How many configuration manage-
process can identify and reconcile duplicate ment requests are fulfilled
CI records to improve CMDB health. Finally,
• CMDB defects identified and fixed
regular data quality procedures must be
implemented to look for defective data. • Number of CIs missing key attributes
An open channel must exist between the • Size of CMDB (only for the classes
users and the configuration management being managed in the data dictionary)
team to communicate defective CI data. A • Number of incidents and changes
process (preferably automated) must exist
placed on items where there is no
to handle such defects. Most important,
corresponding CI
you don’t want to just fix the defects —
you need to fix the process that allowed • Number of reports designed and run
the defects to occur in the first place. • List of IT use cases for which the
CMDB is being utilized with detailed
Many processes and people
metrics on each (for example, number
downstream of the CMDB
depend on the quality and and type of reports produced)
accuracy of the data in the
CMDB to do their jobs. When
When you have the tools and processes
inaccurate data affects the success
of those processes, those people lose in place for a healthy CMDB, you need
trust in the CMDB and the configuration to keep it healthy and resolve issues as
management team. they arise. The best way to do this is to
monitor your CMDB using a CMDB health
dashboard. With it you can monitor key
CMDB key performance indicators (KPIs),
including completeness, compliance, and
correctness. In addition to aggregate
scorecards, you can also drill into CMDB
details for specific business services, and
individual CIs allowing you to pinpoint
CMDB problems and request corrective
action. The CMDB health benchmarks can
measure your CMDB health relative to
other ServiceNow customers and industry
standards.
With a healthy and service-aware CMDB,
you have better capability to diagnose
service issues, detect root cause prob-
lems quickly, and find resolution with
reduced mean time to resolve. For
example, real-world enterprises have
seen results such as:
• Over 50% reduction in major
incidents in spite of huge IT growth
• A decrease of 30% in false
positive incidents
• 22% fewer major outages
To learn more about Configuration
Management and ServiceNow CMBD,
visit servicenow.com to read Configuration
Management and CMDB For Dummies,
ServiceNow Special Edition.
For Dummies is a trademark of John WiIey & Sons, Inc. ISBN: 978-1-119-59404-8