Under active development Content is continuously updated and improved

CHM-01Change Management Workflow

>Control Description

Change scope, change type, and roles and responsibilities are pre-established and documented in a change control workflow; notification and approval requirements are also pre-established based on risk associated with change scope and type.

Theme

Process

Type

Preventive

Policy/Standard

Change Management Policy

>Implementation Guidance

1. Ensure that the change management process is established and well-documented, and should be approved by the management and communicated to all the relevant stakeholders. 2. Ensure that roles and responsibilities are defined for each activity and change scope, that change type is predefined. 3. Ensure that the change workflow has a mandatory approval and notification requirements incorporated based on risk and change type.

>Testing Procedure

1. Inspect Organization's policy to determine whether: a. Change scope, change type, and roles and responsibilities are pre-established. b. Notification and approval requirements are pre-established based on the risk associated with change scope and type. 2. Inspect change management ticketing and tracking tools to determine whether the change control workflow is defined in accordance with the defined requirements.

>Audit Artifacts

E-CHM-01
E-CHM-03

>Framework Mappings

Cross-framework mappings provided by Adobe CCF Open Source under Creative Commons License.

Ask AI

Configure your API key to use AI features.