Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.32

Change Management: A Practical Implementation Guide

Move technology changes into operation through assessed, authorized and verifiable control.

This control concerns subjecting changes to information-processing facilities and systems to change-management procedures.

Practical interpretation: Change control should manage risk without blocking delivery. Standard, normal and emergency paths can differ, but all need accountability, testing, evidence and review.

What should the control achieve?

  • Changes are classified and authorized by risk.
  • Security impact and dependencies are considered.
  • Testing, communication and rollback are planned.
  • Emergency changes receive retrospective review.

Step-by-step implementation

1

Define change types

Distinguish standard, normal, major and emergency changes with criteria.

2

Capture required information

Record purpose, systems, risk, security impact, test, owner, schedule and rollback.

3

Assess and approve

Use technical, security, business and segregation review proportionate to risk.

4

Test and schedule

Validate in suitable environment and coordinate dependencies and stakeholders.

5

Implement and verify

Record execution, deviations, monitoring and success criteria.

6

Review and learn

Close evidence, assess failed and emergency changes and update standards.

What this could look like in practice

A firewall change includes requested flow, owner, risk, test and expiry. Peer review precedes deployment, monitoring verifies traffic and rollback is ready. Emergency changes are reviewed next business day.

ActivityPractical implementationEvidence
Standard changePreapproved automation follows controlled template.Deployment record
Normal changeRisk-based review and schedule apply.Change ticket
EmergencyUrgent authority and retrospective review are recorded.Emergency review
Failed changeRollback and root-cause action follow.Incident record

Implementation evidence

  • Change policy
  • Change classifications
  • Tickets
  • Risk assessments
  • Approvals
  • Test results
  • Deployment logs
  • Post-change reviews

Useful metrics

  • Changes causing incidents
  • Emergency-change rate
  • Unauthorized changes
  • Failed changes with review

Common mistakes

  • Treating every change identically.
  • Approving without understanding impact.
  • No rollback or success criteria.
  • Normalizing emergency changes.
  • Closing tickets before verification.

Questions an auditor may ask

  • How are changes classified?
  • What security impact is assessed?
  • Show an emergency review.
  • How are failed changes learned from?
Implementation test: Select a production change and trace request, risk, approval, testing, deployment, validation, rollback readiness and closure.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.