9.3. Change Management Objective: Mandatory Control 1: Recommended Control 1: Recommended Control 2: To ensure information security is an integral part of the change management process, it should be incorporated into the agency’s IT governance and management activities When a configuration change impacts the security of a system and is subsequently assessed as having changed the overall security risk for the system, the agency must reaccredit the system Agencies should ensure that for routine and urgent changes: the change management process, as defined in the relevant information security documentation, is followed the proposed change is approved by the relevant authority any proposed change that could impact the security of a system or accreditation status is submitted to the Accreditation Authority for approval all associated information security documentation is updated to reflect the change Agencies should follow this change management process outline: produce a written change request submit the change request to all stakeholders for approval document the changes to be implemented test the approved changes notification to user of the change schedule and likely effect or outage implement the approved changes after successful testing update the relevant information security documentation including the SRMP, SecPlan and SOPs notify and educate system users of the changes that have been implemented as close as possible to the time the change is applied continually educate system users in regards to changes The need for change can be identified in various ways, including: system users identifying problems or enhancements vendors notifying of upgrades to software or IT equipment vendors notifying of the end of life to software or IT equipment advances in technology in general implementing new systems that necessitate changes to existing systems identifying new tasks requiring updates or new systems organizational change business process or concept of operation change 39

Select target paragraph3