ISO/IEC 27001:2022 Annex A · Control 8.32
Change Management: A Practical Implementation Guide
Move technology changes into operation through assessed, authorized and verifiable control.
This control concerns subjecting changes to information-processing facilities and systems to change-management procedures.
What should the control achieve?
- Changes are classified and authorized by risk.
- Security impact and dependencies are considered.
- Testing, communication and rollback are planned.
- Emergency changes receive retrospective review.
Step-by-step implementation
Define change types
Distinguish standard, normal, major and emergency changes with criteria.
Capture required information
Record purpose, systems, risk, security impact, test, owner, schedule and rollback.
Assess and approve
Use technical, security, business and segregation review proportionate to risk.
Test and schedule
Validate in suitable environment and coordinate dependencies and stakeholders.
Implement and verify
Record execution, deviations, monitoring and success criteria.
Review and learn
Close evidence, assess failed and emergency changes and update standards.
What this could look like in practice
A firewall change includes requested flow, owner, risk, test and expiry. Peer review precedes deployment, monitoring verifies traffic and rollback is ready. Emergency changes are reviewed next business day.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Standard change | Preapproved automation follows controlled template. | Deployment record |
| Normal change | Risk-based review and schedule apply. | Change ticket |
| Emergency | Urgent authority and retrospective review are recorded. | Emergency review |
| Failed change | Rollback and root-cause action follow. | Incident record |
Implementation evidence
- Change policy
- Change classifications
- Tickets
- Risk assessments
- Approvals
- Test results
- Deployment logs
- Post-change reviews
Useful metrics
- Changes causing incidents
- Emergency-change rate
- Unauthorized changes
- Failed changes with review
Common mistakes
- Treating every change identically.
- Approving without understanding impact.
- No rollback or success criteria.
- Normalizing emergency changes.
- Closing tickets before verification.
Questions an auditor may ask
- How are changes classified?
- What security impact is assessed?
- Show an emergency review.
- How are failed changes learned from?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.