Change Management Standards and Practices

How organizations affect change has been extensively studied within the context of many professional disciplines.

4 slides · 1 min read · Domain 7

Slide 1

Project management practices such as the Project Management Institute's "PRINCE," which is part of the institute's respected Project Management Body of Knowledge and others, address CM from organizational perspectives.

Information security frameworks address change within that context, including NIST Special Publication (SP) 800-128, Guide for Security-Focused Configuration Management of Information Systems.

ISO 27001, Annex A 12.1.2 identifies CM as a necessary control to address changes to the organization, business processes, information processing facilities and systems that affect information security.

One of the more widely adopted

The ITIL process distinguishes information technology change practices changes among three levels based is defined in the Information Technology on their urgency: Infrastructure Library (ITIL) version 4,

  • Standard changes, which are

under the name of Change Enablement.

relatively low-risk and follow This standard provides broad guidelines established procedures, for change management practices, recognizing that an individual organization's • Emergency changes are those which must be implemented immediately, and implementation of change practice will be affected by its culture, business

  • Normal changes, which do not fall

practices, statutory and regulatory into either of the other two levels.

requirements and other factors.

The flexibility of the ITIL practice recognizes, as do all of the major frameworks, that organizations have different approval processes based on the risk of change.

Test this domain