Operations · Service Management
Change Management
Assessing, approving, scheduling and recording modifications to the environment so change is deliberate and reversible.
IntermediateUpdated 2026-09-01
Overview
Change enablement balances speed against risk. Standard changes are pre approved and low risk; normal changes are assessed and scheduled; emergency changes follow an expedited path with retrospective review.
The measurable objective is a high change success rate with low lead time. Processes that only maximise control produce shadow changes, which is worse than a lighter process that is actually followed.
How it works
- 01Each change records scope, risk assessment, implementation plan, test plan, rollback plan, timing and affected services.
- 02Approval authority scales with risk; peer review and automated testing substitute for committees on routine work.
- 03A change calendar exposes conflicts and freeze periods across teams.
- 04Post implementation review confirms outcome and captures failures as inputs to problem management.
Security considerations
- Require change records for firewall, identity, privilege and backup modifications specifically, these are the changes that cause security incidents.
- Detect unauthorised change through configuration drift monitoring, not only by trusting process compliance.
Common misconfigurations
- Every change classified as emergency to skip lead time.
- Rollback plans stated as 'restore from backup' without validating that it is feasible in the window.
- Cloud and code changes exempt from any record, leaving half the estate untraceable.
