Change management
A change management process is used to change hardware, install software, and configure various network devices. A change management process includes approval, testing, scheduling, and rollback arrangements.
Any changes to a system or process are likely to introduce new vulnerabilities and hence it is very important for the security manager to identify and address new risks.
The objective of change management
The main objective of the change management process is to support the processing and traceability of changes to a system. The change management process ensures that any modification to or updating of the system is carried out in a controlled manner.
Approval from the system owner
The security manager should also consider a structured change management process. While implementing a change, all relevant personnel should be kept informed and specific approval should be obtained from the relevant information asset owners.