Process for controlling changes to IT systems to minimise disruption and security risk.
Change management controls how changes are made to IT systems—ensuring changes are properly assessed, approved, implemented, and documented. Uncontrolled changes cause outages and introduce security vulnerabilities. Change management typically includes change requests, impact assessment, approval workflows, implementation procedures, and post-implementation review. Emergency change procedures handle urgent situations while maintaining appropriate controls.
Why It Matters
The DSC Perspective:
Uncontrolled changes cause incidents. Change management ensures changes are assessed for security impact and properly implemented. It also provides audit trail of what changed and when.
