Change management is the disciplined process of planning, reviewing, and controlling changes to IT systems so that updates improve the environment without introducing new weaknesses. It brings structure to modification, ensuring changes are understood, approved, and reversible rather than ad hoc.
Within the Preparation phase, change management protects the security posture that other controls establish. Hardened baselines, tested configurations, and known-good states all erode if changes bypass review. Many incidents trace back not to a novel attack but to a change that opened a gap: an exposed service, a loosened permission, or an untested update. Governing change keeps those gaps from appearing unnoticed.
In practice, change management involves documenting proposed changes, assessing their risk and impact, scheduling them to limit disruption, and defining rollback plans before work begins. Higher-risk changes receive review by a change advisory process, while routine changes may follow pre-approved paths. Teams watch for configuration drift, verify that changes took effect as intended, and keep records that support troubleshooting and audit. Done well, change management lets an organization move quickly while keeping its known-good state intact.
References#
- ITIL, Change Enablement guidance
- NIST SP 800-128, Security-Focused Configuration Management of Information Systems