8.32 Change management
Requires change management procedures to govern changes made to information systems and to the facilities that process information. Older source material adds that changes should be controlled by formal, documented and e
5
artefacts
0
held by a system
3
at each review
hard
to go live
Ticketing / ITSM
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Change records for the period, showing risk and security impact assessment, testing evidence, approval and implementation record · Ticketing / ITSM
- Evidence of segregation between the person requesting, approving and implementing a change · Ticketing / ITSM
- Evidence of detection of unauthorised change, reconciling changes made against changes approved · Ticketing / ITSM
governing documentDocuments that govern the control
- The change management procedure covering the types of change, the authorisation required and the route for emergency change · Policy repository / GRC workspace
- Rollback plans and evidence they are viable, plus post implementation review records · Policy repository / GRC workspace
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Emergency change route used routinely to avoid the standard process, with retrospective approval that is never refused
- Security impact assessment reduced to a checkbox with no analysis behind it
- No reconciliation between changes made and changes approved, so unauthorised change is undetectable
- Approver and implementer the same person, so approval carries no independent judgement
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet8.31 Separation of development, test and production environments · 8.33 Test information