Change Control Policy
Version 3.0
For Staff
Purpose
The purpose of this policy is to ensure that all changes to University IT Resources minimize any potential negative impact on services and Users.
Scope
This IT security policy, and all policies referenced herein, shall apply to all members of the University community, including faculty, students, administrative officials, staff, alumni, authorized guests, delegates, and independent contractors (the “User(s)” or “you”) who use, access, or otherwise employ, locally or remotely, the University’s IT Resources, whether individually controlled, shared, stand-alone, or networked.
Policy Statement
- All changes to University IT Resources must be documented and follow the Change Control Process to ensure appropriate planning, approval, testing, execution, and verification.
- Change requests may not be required for non-production (e.g., DEV, Test, QA) environments unless there is a significant upgrade or an impact.
- Change requests must document that the change has been successfully applied, tested, and verified in a non-production environment, when a suitable environment exists, before implementation in production.
- Changes to production environments must undergo impact examination before submitting the change request per the Change Control Process. This information will be used to determine the impact of the change by considering:
- The potential security and privacy impact of the proposed change;
- The impact the proposed change will have on business services or functionality to a specific group or groups;
- The risk involved by not making the change;
- The risk if the change does not go as planned; and
- Predictability of the success of the change.
- Changes must be vetted for security implications through Information Security and Assurance participation before implementation.
- Only authorized personnel with appropriate access privileges may implement changes in production environments.
- Significant User experience changes must be conveyed to the Change Advisory Board and communicated to the affected audience and IT Service Desk.
- Following implementation, production changes must be verified and documented to confirm the intended outcome and identify any unintended security, privacy, or service impacts.
- A lessons learned review must be conducted when a production change results in an incident.
Definitions
Change Control is a systematic approach to managing all changes to University IT Resources. The purpose is to ensure that no unnecessary changes are made, that all changes are documented, that services are not unnecessarily disrupted, and that resources are used efficiently.
IT Resources include computing, networking, communications, application, and telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and related materials and services.
NIST SP 800-53 Rev. 5 Controls
- CM-3 - Configuration Change Control
- CM-4 - Impact Analyses
- CM-5 - Access Restrictions for Change
Related Policies and Procedures
- Change Control Process
- Change Request in ServiceNow
- Patch Management Policy
- Vulnerability Management Policy
Implementation Information
| Review Frequency: | Triennial |
|---|---|
| Responsible Person: | Director of Change Management |
| Approved By: | CISO |
| Approval Date: | April 15, 2019 |
Revision History
| Version | Date | Description |
|---|---|---|
| 1.0 | 04/15/2019 | Initial document |
| 1.0.1 | 04/01/2020 | Updated policy statement |
| 1.2 | 06/02/2020 | Updated change request document |
| 1.3 | 03/03/2022 | Updated policy statement |
| 2.0 | 03/30/2023 | Updated the Change Request in ServiceNow link |
| 3.0 | 09/02/2026 | Added NIST SP 800-53 Rev. 5 controls CM-3, CM-4, and CM-5; strengthened requirements for production change testing, security and privacy impact analysis, authorized production access, post-implementation verification, and lessons learned. |
Policy Disclaimer Statement
Deviations from policies, procedures, or guidelines published and approved by Information Security and Assurance (ISA) will only be considered cooperatively between ISA and the requesting entity with sufficient notice to allow for conducting appropriate risk analysis, documentation, review, and notification to authorized University representatives where necessary. Failure to adhere to ISA written policies may be met with University sanctions up to and including dismissal.