Problem
DORA RT.07.01 requires organizations to assess the ICT services that support critical or important business functions. In practice, that becomes difficult when the model stops too early at a broad business service level, because it can hide which applications, service instances, or technical services are actually relevant for the assessment.
This blueprint helps solve that by using the Business Capability as the business offset for the function and the Business Application as the main design object, then extending the view into business services, service offerings, service instances, and technology management structures. That supports more precise reporting, helps avoid false positives when less critical components are affected, and adds clearer accountability through owners and department context.
What the Blueprint Includes
This blueprint gives a structured view of how a Business Application supports a business function in a DORA reporting context. It connects the application to the relevant business capability, service layers, service instance, technology management context, information used, and the people and organizational unit responsible for governing it.
- Business Application - The central record in the blueprint. This is the application you want to assess and govern in relation to a business function.
- Business Capability - Used as the business offset for the function. The blueprint includes both a capability and a parent capability to place the application in a business hierarchy.
- Parent Business Capability - Adds hierarchy above the main capability so the function can be understood in a broader business structure.
- Information Object - Represents the type of information the application uses or manages, which is important for governance, compliance, and resilience discussions.
- Service Instance - Represents the concrete instance supporting the application, which is critical for more accurate operational and DORA-oriented assessment.
- Technology Management Offering - Represents the technology-facing offering layer connected to the supporting service instance.
- Technology Management Service - Represents the underlying technology service context beneath the technology management offering.
- Business Service Offering - Provides a more precise service layer beneath the business service.
- Business Service - Shows the business-facing service context connected to the capability and the offering structure.
- User - Included for accountability roles around the application, such as business and application ownership.
- Department - Represents the organizational line of duty behind the application, helping connect the model to real accountability in the operating organization.

Considerations
This blueprint is most valuable when it is kept focused on traceability for DORA RT.07.01. The goal is to maintain a clear and practical support chain around the business function, so it is easier to understand what supports it, who is accountable, and which service and technology layers matter for reporting and resilience assessment.
- Use the Business Capability intentionally. Make sure the selected capability really reflects the business function or business context you want to report on. If the capability is too broad or too generic, the blueprint becomes less precise and less useful.
- Keep the Business Application as the main governance object. This blueprint works best when the application is the central object for ownership, lifecycle, and reporting relevance. That creates a stronger bridge between business context and operational reality.
- Note! More detailed requirements related to Service Instances, Offering, Services, and Capabilities should be added to their own blueprints.
- Use the service layers to improve precision. The Technology Management Offering, Technology Management Service, and Service Instance should help narrow the support chain and reduce ambiguity. They are most valuable when they help avoid broad assumptions about what is actually supporting the function.
- Maintain the business service context where it adds value. The Business Service Offering and Business Service become especially important when you need to explain or validate the business impact and users behind the service instance.
- Make ownership and accountability clear. Business owner, IT application owner, and Department should be maintained consistently so that governance, escalation, reporting, and follow-up activities have a clear point of responsibility.
- Keep information usage meaningful. The Information Object should represent information that matters for understanding the application’s purpose, resilience relevance, or reporting context, rather than being included only for completeness.
- Start small and improve iteratively. For DORA-related blueprints, it is usually better to begin with the most important business functions and a small set of measurable quality rules, then expand once the core records are reliable.
Benefits
When maintained well, this blueprint gives you a stronger foundation for DORA RT.07.01 by making the supporting ICT landscape easier to understand and defend. It improves traceability from business function to application, service instance, and technology support layers, while also making accountability more visible.
In practice, that means:
- more precise ICT service assessments
- fewer false positives in impact and resilience analysis
- clearer ownership and organizational accountability
- better evidence for audit, compliance, and continuity discussions
- a more scalable structure for improving reporting quality over time
The real value of this blueprint is that it turns a broad reporting obligation into a practical data structure that teams can actually maintain and improve.
Related Information
Check other blueprints related to Business Applications and Design & Planning.
Also, check other blueprints related to DORA.
This blueprint is created based on the following ServiceNow white papers:
How to Get This Blueprint?
If you’re already a Data Content Manager Customer, you can download the Blueprint from the Knowledge Base. You will need your login credentials to access the blueprint download page.










