Change Management
A structured process for proposing, reviewing, approving, and implementing changes to systems, processes, or configurations. Change management prevents uncontrolled modifications from introducing risk.
Why it matters
Uncontrolled changes are a leading cause of outages, security incidents, and audit findings. A deployment without review, a firewall rule changed on the fly, a database migration run in production without approval. Change management creates a paper trail that proves changes were intentional, reviewed, and authorized. Auditors check for it in every engagement because it sits at the intersection of availability, integrity, and accountability.
In practice
Change management involves categorizing changes by risk, routing them through appropriate approval workflows, testing before deployment, and documenting outcomes. Emergency changes get expedited review but still require post-implementation documentation. In vucavoid, change-related controls are linked to the processes and systems they govern, with effectiveness reports that verify your change process is followed consistently rather than bypassed under pressure.