9.3.
Change Management
Objective:
Mandatory Control 1:
Recommended Control 1:
Recommended Control 2:
To ensure information security is an integral part of the change
management process, it should be incorporated into the agency’s
IT governance and management activities
When a configuration change impacts the security of a system and
is subsequently assessed as having changed the overall security
risk for the system, the agency must reaccredit the system
Agencies should ensure that for routine and urgent changes:
the change management process, as defined in the relevant
information security documentation, is followed
the proposed change is approved by the relevant authority
any proposed change that could impact the security of a
system or accreditation status is submitted to the
Accreditation Authority for approval
all associated information security documentation is
updated to reflect the change
Agencies should follow this change management process outline:
produce a written change request
submit the change request to all stakeholders for approval
document the changes to be implemented
test the approved changes
notification to user of the change schedule and likely effect
or outage
implement the approved changes after successful testing
update the relevant information security documentation
including the SRMP, SecPlan and SOPs
notify and educate system users of the changes that have
been implemented as close as possible to the time the
change is applied
continually educate system users in regards to changes
The need for change can be identified in various ways, including:
system users identifying problems or enhancements
vendors notifying of upgrades to software or IT equipment
vendors notifying of the end of life to software or IT equipment
advances in technology in general
implementing new systems that necessitate changes to existing systems
identifying new tasks requiring updates or new systems
organizational change
business process or concept of operation change
39