Planning of changes: why change management is often underestimated

    Back to blog
    change-management
    iso27001

    Change Management: An Underestimated Success Factor in ISO 27001

    Many organizations invest a lot of time in firewalls, backups, monitoring, and vulnerability management. However, disruptions to systems are often caused by something much simpler: a change that has not been adequately prepared, tested, or communicated.

    An incorrect configuration change, a software update that has unexpected consequences, or a change made directly in production can lead to service outages, data breaches, or security incidents within minutes.

    That is why change management is an important part of a mature management system and plays a central role in ISO 27001.

    What is Change Management?

    Change management is the process by which organizations implement changes to systems, applications, infrastructure, processes, and configurations in a controlled manner.

    The goal is simple:

    To change without causing unwanted disruptions.

    A good change management process ensures that changes are assessed, tested, approved, implemented, and evaluated in advance.

    This involves not only looking at technical risks but also considering the implications for availability, security, quality, and service delivery.

    Why is Change Management So Important?

    Virtually every organization is continuously changing:

    • Software is updated.

    • Servers are replaced.

    • Configurations are adjusted.

    • New processes are introduced.

    • Suppliers are replaced.

    • Security measures are tightened.

    Every change carries risks.

    In practice, many incidents do not arise from hackers or technical defects, but from human errors during changes.

    Consider, for example:

    • A firewall rule that accidentally grants too much access.

    • A software update that disables a critical functionality.

    • A database change that results in data loss.

    • A misconfigured cloud environment.

    That is precisely why ISO 27001 requires organizations to manage changes in a controlled manner.

    Change Management in ISO 27001

    In ISO 27001, change management is explicitly mentioned in Annex A control 8.32.

    The standard requires that changes to information processing facilities and information systems are managed.

    This means, among other things, that organizations:

    • Assess risks in advance.

    • Document responsibilities.

    • Test changes before they are implemented.

    • Formally approve changes.

    • Evaluate the results of changes.

    • Can reverse unexpected consequences.

    An auditor will therefore regularly ask:

    • How are changes recorded?

    • Who is authorized to approve changes?

    • How is testing conducted?

    • How are emergency changes handled?

    • How can a change be reversed?

    Not Every Change Needs to Go Through a CAB

    A common mistake is the belief that every change must be reviewed by an extensive Change Advisory Board (CAB).

    This often leads to unnecessary bureaucracy.

    Mature organizations distinguish between different types of changes.

    Standard Changes

    Low-risk changes that occur regularly and have been pre-approved.

    Examples:

    • Updating workplace software.

    • Adding a new employee.

    • Installing a printer.

    Normal Changes

    Changes that require a risk analysis and approval.

    Examples:

    • Implementing a new application.

    • Adjusting a firewall.

    • A change in a business process.

    Emergency Changes

    Changes that must be implemented immediately to resolve an incident or security issue.

    For example:

    • Patching an actively exploited vulnerability.

    • Blocking a compromised account.

    These changes may be expedited, but must still be evaluated and documented afterward.

    Testing is More Important than Forms

    Some organizations focus primarily on forms and approval steps.

    In practice, the quality of testing is often much more important.

    A change that has been extensively approved but never tested still poses a significant risk.

    A mature change process therefore includes:

    • A testing environment.

    • Acceptance criteria.

    • An implementation plan.

    • A rollback plan.

    • A post-implementation evaluation.

    For critical changes, it must be clear in advance how the organization will revert to the old situation if the change fails.

    The Principle: No Changes Directly in Production

    The main principle of change management is simple:

    Changes must not cause disruptions to service delivery.

    Therefore, changes should first be assessed and tested before they reach the production environment.

    Direct changes in production without assessment, documentation, or testing are one of the most common audit findings in ISO 27001 and ISO 20000.

    Although exceptions may be made for emergency changes, these must always be documented and evaluated afterward.

    Practical Tips

    Organizations looking to improve their change management can start with the following measures:

    • Record all significant changes centrally.

    • Distinguish between standard, normal, and emergency changes.

    • Conduct risk analyses for impactful changes.

    • Test changes in an acceptance environment beforehand.

    • Define a rollback procedure.

    • Evaluate major changes afterward.

    • Ensure that responsibilities are clearly documented.

    Conclusion

    Good change management is not about forms or bureaucracy. It is about implementing changes in a controlled manner without compromising the quality, availability, or security of services.

    Organizations that systematically assess, test, and document changes experience fewer disruptions, recover faster from errors, and demonstrably meet the requirements of ISO 27001 better.

    Most disruptions do not arise from what organizations change, but from how they change.