Change management auditing
Appearance
This December 2006 may be confusing or unclear to readers. |
This article appears to contain a large number of buzzwords. |
This article needs attention from an expert in computer science. Please add a reason or a talk parameter to this template to explain the issue with the article. |
This article needs additional citations for verification. |
Change management auditing is an information technology (IT) procedure for limiting unauthorized changes and errors to computer systems and disruptions to a company's IT assets, computer applications, and operating systems. A change management control system has specific procedures that define analysis, application, and review of changes to the computer infrastructure. Change management is therefore important to a company's IT security.
Change risks
Proper change control auditing can mitigate the following risks:
- Security features of the network turn off.
- Harmful code is distributed to users.
- Sensitive data is lost or becomes insecure.
- Financial report errors occur.
Control procedure
The following features are commonly part of a change management auditing procedure:
- Changes are requested in a formal process.
- Priority is assessed on urgency, potential benefits, and the ease with which changes can be corrected.
- Change management procedures are devised and documented.
- Changes are requested in a formal process.
- Requests are recorded and stored for reference.
- Change requests are ranked by priority.
- Priority is assessed based on urgency, potential benefits, and the ease with which changes can be corrected.
- The effect of the requested change is assessed.
- Each change is assessed based on its projected effect to the computer system and business operations. The assessment is documented with the request.
- Controls are imposed on changes.
- Changes are limited by automated or manual controls. In particular, unauthorized changes are periodically searched for.
- An emergency change process is in place.
- Policies clearly define emergency changes. Generally, these are errors that significantly impair system function and business operations, increase the system's vulnerability, or both. Emergency changes override some, but not all, controls. For instance, a proposed change might be documented, but not permitted without authorization.
- Change documentation is periodically updated.
- Maintenance tasks and changes are recorded.
- Controls are applied to new software releases.
- For security, new software releases often require controls such as back ups, version control, and a secure implementation.
- Software distribution is assessed for compliance.
- Software distribution is assessed for compliance with licence agreements. Noncompliance can have disastrous financial and legal results.
- Changes are submited for approval.
- Proposed changes are submitted for approval after auditors have reviewed the required resources, other changes, the effect, urgency, and the system's stability.
- Duties are separated
- Responsibility for creation, approval, and application are assigned to different personnel to avoid undesired changes.
- Changes are reviewed.
- Changes are monitored to assess the efficacy of change management policies.