A.8.32 Change management
Put changes to facilities and systems through change management procedures.
12
artefacts
3
held by a system
3
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Submitted change request ticket · Ticketing / ITSM
- Change request log extract · SIEM / log platform
- Defect log for change · SIEM / log platform
periodic reviewEvidence produced at each review
- Signed change approval matrix · Ticketing / ITSM
- Change advisory board meeting minutes · Policy repository / GRC workspace
- Post implementation review report · Document repository
governing documentDocuments that govern the control
- Change request form · Policy repository / GRC workspace
- Approval email chain · Document repository
- Test plan document · Policy repository / GRC workspace
- Test execution report · Document repository
- Lessons learned register · Policy repository / GRC workspace
- Verification checklist · Document repository
First move
Start with the 3 of 12 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- missing formal approval
- no rollback plan documented
- testing performed after production deployment
- change records not linked to assets
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.8.31 Separation of development, test and production environments · A.8.33 Test information