Cyberstudy
PDF p.385 In progress

Change Management Programs

Open PDF at p.385 19 flashcards

Summary

PDF p.385

Change management is a systematic approach to managing changes in an organization, ensuring they are handled efficiently and effectively to minimize risks and avoid negative impacts on security, service availability, or performance.

In plain words

Supplementary — not from your PDF

A change management programme is a systematic way to handle changes (software deployments, updates, patches, hardware, network and configuration changes, new integrations) so they don't harm security, availability or performance. The process: document the change, assess risk, get approval, then review and audit.

Detailed explanation

PDF p.385
  • Purpose
    • Systematic Approach: Manage changes to products or systems.
    • Minimize Risks: Ensure changes do not negatively impact security or performance.
  • Types of Changes
    • Software Deployments: Implementing new software.
    • System Updates: Updating existing systems.
    • Software Patching: Applying patches to fix vulnerabilities.
    • Hardware Replacements/Upgrades: Updating hardware components.
    • Network Modifications: Changing network configurations.
    • System Configurations: Adjusting system settings.
    • New Product Implementations: Introducing new products.
    • New Software Integrations: Integrating new software.
    • Support Environment Changes: Updating support systems.
  • Change Management Process
    • Documentation: Details of changes, reasons, impacts, and rollback plans.
    • Risk Assessment: Identify potential security impacts.
    • Approval: Changes must be approved by appropriate personnel.
    • Review and Audit: Ensure changes are completed correctly and securely.

Important terms

taken from the text above
Systematic Approach
Manage changes to products or systems.
Minimize Risks
Ensure changes do not negatively impact security or performance.
Software Deployments
Implementing new software.
System Updates
Updating existing systems.
Software Patching
Applying patches to fix vulnerabilities.
Hardware Replacements/Upgrades
Updating hardware components.
Network Modifications
Changing network configurations.
System Configurations
Adjusting system settings.
New Product Implementations
Introducing new products.
New Software Integrations
Integrating new software.
Support Environment Changes
Updating support systems.
Documentation
Details of changes, reasons, impacts, and rollback plans.
Risk Assessment
Identify potential security impacts.
Approval
Changes must be approved by appropriate personnel.
Review and Audit
Ensure changes are completed correctly and securely.

Examples & real-world scenarios

Supplementary — not from your PDF
  • Documenting a change's reason, impact and rollback plan.
  • A risk assessment before a network change.
  • A post-change audit to confirm it went as planned.

Scenario

An unapproved patch breaks a production system. A change management programme requiring documentation, risk assessment and approval would have caught the risk first.

Common mistakes

Supplementary — not from your PDF
  • Making changes without documentation or approval.
  • Skipping the post-change review.

Practical skills

Supplementary — not from your PDF
  • List the steps of a change management process.

What I should remember

Key Points PDF p.385
  • Systematic Approach: Manage changes efficiently.
  • Minimize Risks: Avoid negative impacts.
  • Types of Changes: Software, hardware, network, configurations.
  • Process: Documentation, risk assessment, approval, review.