is-operations10 min read

Change Management: Process, CAB, and Emergency Changes

Learn about change management processes, the Change Advisory Board, and emergency change procedures for CISA exam preparation.

CISAPractice|

Understanding Change Management

Change management is one of the most critical IT governance processes. It ensures that standardized methods and procedures are used for efficient handling of all changes to the IT infrastructure, minimizing the impact of change-related incidents on service quality. For IS auditors, change management is a primary area of focus because unauthorized or poorly managed changes are a leading cause of system outages and security vulnerabilities.

The Change Management Process

A structured change management process typically includes the following steps:

  • Request for Change (RFC): A formal request that documents the proposed change, its justification, risk assessment, rollback plan, and implementation schedule. All changes should originate from an RFC.
  • Assessment and Evaluation: The change is evaluated for its potential impact, risk, resource requirements, and alignment with business objectives. Testing in a non-production environment is essential before approval.
  • Authorization: Changes must be formally approved before implementation. The level of authorization depends on the change category and risk level.
  • Implementation: The approved change is implemented according to the documented plan. Implementation should be scheduled during maintenance windows when possible.
  • Post-Implementation Review: After deployment, the change is reviewed to confirm it achieved its objectives without unintended consequences.

Change Advisory Board (CAB)

The Change Advisory Board is a group of stakeholders who assess, prioritize, and authorize changes. The CAB typically includes representatives from IT operations, development, security, and business units. The CAB ensures that changes are reviewed from multiple perspectives and that potential conflicts between changes are identified. An Emergency CAB (ECAB) is a smaller group convened for urgent changes that cannot wait for the regular CAB meeting.

Types of Changes

  • Standard Changes: Pre-approved, low-risk changes that follow established procedures (e.g., password resets, routine patches). These do not require CAB approval for each occurrence.
  • Normal Changes: Changes that follow the full change management process, including RFC submission, CAB review, and formal approval.
  • Emergency Changes: Urgent changes needed to restore service or address critical security vulnerabilities. These follow an expedited process but must still be documented and reviewed retrospectively.

Audit Considerations

IS auditors should verify that all changes are logged, approved before implementation, and tested in a non-production environment. Auditors should review CAB meeting minutes, check that emergency changes are properly documented after the fact, and ensure that unauthorized changes are detected and investigated.

CISA Exam Tips

For the CISA exam, change management is a high-priority topic. Remember that every change should have an RFC, a risk assessment, and a rollback plan. Emergency changes must still be documented and reviewed retrospectively. The CAB's role is advisory; final authorization may rest with the change manager or IT management.

Related Tags

Change ManagementCABEmergency ChangesIS Operations

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free