In this ultimate how to implement guide to ISO 27001 Clause 6.3 Planning Of Changes, you will learn directly from an ISO 27001 Lead Auditor:
Table of contents
1. Establish a Change Management Process
The Goal: Define a documented process for managing all changes to the ISMS, covering planning, approval, implementation, and review.
- Challenge: Lack of consistency or personnel resisting formal procedures.
- Solution: Develop a concise change management policy. Train personnel on the benefits of formal processes, such as improved operational stability and reduced risk.
2. Assess the Impact of Changes
The Goal: Evaluate the potential risks and opportunities of a change before implementation.
- Challenge: Overlooking downstream impacts on complex systems.
- Solution: Involve interested parties (IT, legal, department heads) in the assessment. Use established risk assessment methodologies to evaluate both positive and negative consequences.
3. Plan Changes in a Controlled Manner
The Goal: Detail resources, timelines, testing procedures, and communication strategies.
- Challenge: Poor planning leading to delays or service disruptions.
- Solution: Create a detailed implementation plan for every change. Assign clear responsibilities and deadlines, and plan for testing in non-production environments.
4. Authorise Changes
The Goal: Obtain formal sign-off from designated personnel before acting.
- Challenge: Unauthorised changes causing security vulnerabilities.
- Solution: Define approval levels based on the scale of the change. Use a ticketing platform or change management system to track approvals and maintain an audit trail.
5. Implement Changes as Planned
The Goal: Execute the change strictly according to the approved plan.
- Challenge: Deviations from the plan introducing unexpected issues.
- Solution: Monitor implementation closely using project management tools. Always have a documented rollback plan ready for unforeseen failures.
6. Test Changes
The Goal: Validate that the change functions as intended without negative side effects.
- Challenge: Rushed testing leading to post-implementation incidents.
- Solution: Develop detailed test plans covering unit, integration, and user acceptance testing (UAT). Validate the change from multiple perspectives before going live.
7. Communicate Changes
The Goal: Inform all interested parties about the change in a timely manner.
- Challenge: User confusion and operational disruption due to lack of information.
- Solution: Use multiple channels (email, intranet, meetings) to explain what is changing, why, and how it impacts stakeholders.
8. Review Changes
The Goal: Conduct a post-implementation review to assess effectiveness and capture lessons learned.
- Challenge: Teams moving on too quickly without verifying success.
- Solution: Schedule mandatory reviews for significant changes. Document lessons learned to drive continual improvement in your ISMS.
9. Document Changes
The Goal: Maintain accurate records of all modifications to the ISMS.
- Challenge: Disconnected documentation making audits difficult.
- Solution: Use a centralised log to record changes. Link these records to relevant ISMS documentation, such as the risk register or asset inventory.
10. Manage Emergency Changes
The Goal: Handle urgent security fixes quickly without losing control.
- Challenge: Balancing speed with necessary oversight.
- Solution: Define strict criteria for “emergency” changes. Create an expedited approval process that still requires retrospective documentation and review.
