Change Management Processes
Security teams usually participate in change management processes as reviewers and approvers. Change management is the process by which organizations make changes in their IT environment, such as the introduction of new software or platforms, the retirement of old software or platforms, and anything else that might constitute a change.
Change management is one of the disciplines in the well-known Information Technology Infrastructure Library (ITIL) and many organizations follow this approach. ITIL does not contain a specific security section; security teams need to determine their role in change management themselves. How this is done depends on the nature of the organization, its culture, and how it has organized changes in its IT environment.
Hence what follows is only some generic pointers. Security functions usually interact with change management at two levels: security architecture and change management.
Architecture
Security architecture...