In this ultimate how to implement guide to ISO 27001 Clause 6.3 Planning Of Changes, you will learn directly from an ISO 27001 Lead Auditor:
Table of contents
1. Establish a Change Management Process
Formalise your approach by documenting a clear process for how ISMS changes will be planned, approved, implemented, and reviewed. From an auditor’s perspective, a documented process is primary evidence. It demonstrates that your approach is repeatable and not reliant on specific individuals.
- Challenge: Resistance to adopting formal procedures or lack of consistency.
- Solution: Develop a concise change management policy. Provide training to relevant personnel and emphasise benefits such as reduced risk and improved system stability.
2. Assess the Impact of Changes
Before implementation, you must understand the potential consequences. Auditors verify that you use a consistent method for evaluating how a change affects confidentiality, integrity, and availability. This involves conducting a risk assessment of the change’s impact on the ISMS.
- Challenge: Overlooking potential negative impacts or complexities.
- Solution: Involve interested parties in the assessment. Use established risk assessment methodologies to identify threats and opportunities associated with the change.
[Image of change management impact assessment matrix]
3. Plan Changes in a Controlled Manner
Effective planning is the heart of this clause. Auditors expect detailed plans for significant changes, including resources, realistic timelines, testing, and communication activities.
- Challenge: Inadequate planning leading to delays.
- Solution: Develop detailed implementation plans. Assign clear responsibilities and conduct thorough pre-production testing.
4. Authorise Changes
No change should proceed without proper sign-off. This ensures accountability. Use your existing management review team or a specific Change Advisory Board (CAB) to formally sign off on significant ISMS changes.
- Challenge: Implementing changes without proper authorisation (“Shadow IT”).
- Solution: Define clear approval levels. Use a change management system (ticket system) to track and record approvals.
5. Implement Changes as Planned
Execution must follow the authorised plan. Auditors look for records, such as system logs or project minutes, proving the implementation adhered to the plan. Deviations without re-authorisation are a common source of non-conformity.
- Challenge: Scope creep or deviation during implementation.
- Solution: Monitor the implementation process closely. Use project management tools and have rollback plans ready for unforeseen issues.
6. Test Changes
Never assume a change will function as expected. Testing must be commensurate with the risk. This validates that the change does not introduce new vulnerabilities.
- Challenge: Inadequate testing leading to production errors.
- Solution: Develop robust test plans. Use User Acceptance Testing (UAT) for process changes and vulnerability scanning for technical updates.
7. Communicate Changes
Affected stakeholders must be informed to prevent confusion. Update your formal communication plan and retain evidence of these communications (emails, intranet posts).
- Challenge: Stakeholders being unaware of changes, causing disruption.
- Solution: Develop a specific communication plan for each significant change using appropriate channels (e.g., team meetings, email alerts).
8. Review Changes
A post-implementation review (PIR) confirms the change achieved its goals. This is evidence of your commitment to continual improvement.
- Challenge: Moving to the next task without reviewing the previous change.
- Solution: Schedule PIRs for all significant changes. Document lessons learned and feed them back into the planning process.
9. Document Changes
A complete record is non-negotiable. Ensure document control includes versioning and retention of previous revisions.
- Challenge: Keeping records up-to-date.
- Solution: Use a centralised change management system. Integrate these records with other ISMS documentation, such as the risk register.
10. Manage Emergency Changes
Auditors understand the need for speed during emergencies but expect a defined procedure. You must balance rapid action with control.
- Challenge: Balancing speed with compliance during a crisis.
- Solution: Define clear criteria for “emergency” status. Establish an expedited approval process but ensure retrospective documentation and review.
