How to implement ISO 27001:2022 Clause 6.3 Planning of Changes

Stuart Barker - High Table - ISO27001 Director

In this ultimate how to implement guide to ISO 27001 Clause 6.3 Planning Of Changes, you will learn directly from an ISO 27001 Lead Auditor:

1. Establish a Change Management Process

The Goal: Define a documented process for managing all changes to the ISMS, covering planning, approval, implementation, and review.

  • Challenge: Lack of consistency or personnel resisting formal procedures.
  • Solution: Develop a concise change management policy. Train personnel on the benefits of formal processes, such as improved operational stability and reduced risk.

2. Assess the Impact of Changes

The Goal: Evaluate the potential risks and opportunities of a change before implementation.

  • Challenge: Overlooking downstream impacts on complex systems.
  • Solution: Involve interested parties (IT, legal, department heads) in the assessment. Use established risk assessment methodologies to evaluate both positive and negative consequences.

3. Plan Changes in a Controlled Manner

The Goal: Detail resources, timelines, testing procedures, and communication strategies.

  • Challenge: Poor planning leading to delays or service disruptions.
  • Solution: Create a detailed implementation plan for every change. Assign clear responsibilities and deadlines, and plan for testing in non-production environments.

4. Authorise Changes

The Goal: Obtain formal sign-off from designated personnel before acting.

  • Challenge: Unauthorised changes causing security vulnerabilities.
  • Solution: Define approval levels based on the scale of the change. Use a ticketing platform or change management system to track approvals and maintain an audit trail.

5. Implement Changes as Planned

The Goal: Execute the change strictly according to the approved plan.

  • Challenge: Deviations from the plan introducing unexpected issues.
  • Solution: Monitor implementation closely using project management tools. Always have a documented rollback plan ready for unforeseen failures.

6. Test Changes

The Goal: Validate that the change functions as intended without negative side effects.

  • Challenge: Rushed testing leading to post-implementation incidents.
  • Solution: Develop detailed test plans covering unit, integration, and user acceptance testing (UAT). Validate the change from multiple perspectives before going live.

7. Communicate Changes

The Goal: Inform all interested parties about the change in a timely manner.

  • Challenge: User confusion and operational disruption due to lack of information.
  • Solution: Use multiple channels (email, intranet, meetings) to explain what is changing, why, and how it impacts stakeholders.

8. Review Changes

The Goal: Conduct a post-implementation review to assess effectiveness and capture lessons learned.

  • Challenge: Teams moving on too quickly without verifying success.
  • Solution: Schedule mandatory reviews for significant changes. Document lessons learned to drive continual improvement in your ISMS.

9. Document Changes

The Goal: Maintain accurate records of all modifications to the ISMS.

  • Challenge: Disconnected documentation making audits difficult.
  • Solution: Use a centralised log to record changes. Link these records to relevant ISMS documentation, such as the risk register or asset inventory.

10. Manage Emergency Changes

The Goal: Handle urgent security fixes quickly without losing control.

  • Challenge: Balancing speed with necessary oversight.
  • Solution: Define strict criteria for “emergency” changes. Create an expedited approval process that still requires retrospective documentation and review.

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top