PDF p.385
In progress
Change Management Programs
Summary
PDF p.385Change management is a systematic approach to managing changes in an organization, ensuring they are handled efficiently and effectively to minimize risks and avoid negative impacts on security, service availability, or performance.
In plain words
Supplementary — not from your PDFA change management programme is a systematic way to handle changes (software deployments, updates, patches, hardware, network and configuration changes, new integrations) so they don't harm security, availability or performance. The process: document the change, assess risk, get approval, then review and audit.
Detailed explanation
PDF p.385-
Purpose
- Systematic Approach: Manage changes to products or systems.
- Minimize Risks: Ensure changes do not negatively impact security or performance.
-
Types of Changes
- Software Deployments: Implementing new software.
- System Updates: Updating existing systems.
- Software Patching: Applying patches to fix vulnerabilities.
- Hardware Replacements/Upgrades: Updating hardware components.
- Network Modifications: Changing network configurations.
- System Configurations: Adjusting system settings.
- New Product Implementations: Introducing new products.
- New Software Integrations: Integrating new software.
- Support Environment Changes: Updating support systems.
-
Change Management Process
- Documentation: Details of changes, reasons, impacts, and rollback plans.
- Risk Assessment: Identify potential security impacts.
- Approval: Changes must be approved by appropriate personnel.
- Review and Audit: Ensure changes are completed correctly and securely.
Important terms
taken from the text above- Systematic Approach
- Manage changes to products or systems.
- Minimize Risks
- Ensure changes do not negatively impact security or performance.
- Software Deployments
- Implementing new software.
- System Updates
- Updating existing systems.
- Software Patching
- Applying patches to fix vulnerabilities.
- Hardware Replacements/Upgrades
- Updating hardware components.
- Network Modifications
- Changing network configurations.
- System Configurations
- Adjusting system settings.
- New Product Implementations
- Introducing new products.
- New Software Integrations
- Integrating new software.
- Support Environment Changes
- Updating support systems.
- Documentation
- Details of changes, reasons, impacts, and rollback plans.
- Risk Assessment
- Identify potential security impacts.
- Approval
- Changes must be approved by appropriate personnel.
- Review and Audit
- Ensure changes are completed correctly and securely.
Examples & real-world scenarios
Supplementary — not from your PDF- Documenting a change's reason, impact and rollback plan.
- A risk assessment before a network change.
- A post-change audit to confirm it went as planned.
Scenario
An unapproved patch breaks a production system. A change management programme requiring documentation, risk assessment and approval would have caught the risk first.
Common mistakes
Supplementary — not from your PDF- Making changes without documentation or approval.
- Skipping the post-change review.
Practical skills
Supplementary — not from your PDF- List the steps of a change management process.
What I should remember
Key Points PDF p.385- Systematic Approach: Manage changes efficiently.
- Minimize Risks: Avoid negative impacts.
- Types of Changes: Software, hardware, network, configurations.
- Process: Documentation, risk assessment, approval, review.