Expert Advice Community

Guest

Change management

  Quote
Guest
Guest user Created:   Sep 30, 2018 Last commented:   Sep 30, 2018

Change management

I'm a fresh graduate who just got hired in information security team in the IT deanship of the university that I graduated from, part of our job is to manage changes in our environment, the environment is relatively small and still growing, the IT deanship has approximately 40 employees, we run different services on about 200 servers. As a small security team with limited experience how can we start managing changes in an effective way? in our case, what is considered to be a change? for example, updating the OS of server? blocking firewall port? editing or deleting a database record? is there a general rule that we can follow?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 30, 2018

Answer:

To manage changes in an effective way, the first thing you have to do is to define a change management policy, to explain to all interested parties how changes to information systems are controlled. In this policy you will define what is to be considered as a change (e.g., the addition, modification or removal of any authorized, planned, or supported component that could have an effect on IT services.).

Depending on the complexity of the environment and competence level of the team, you may also consider the development of change procedures to detail specific activities to be performed (e.g., procedure to change firewall rules, or update a database management system).
To see how a change management policy looks like, I suggest you to take a look at the free demo of our Change Management Policy at this link: https://advisera.com/27001academy/documentation/change-management-policy/

This article will provide you further explanation about change management:
- How to manage changes in an ISMS according to ISO 27001 A.12.1.2 https://advisera.com/27001academy/blog/2015/09/14/how-to-manage-changes-in-an-isms-according-to-iso-27001-a-12-1-2/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 30, 2018

Sep 30, 2018

Suggested Topics