ISSeG logo

 Training and Dissemination web site

FP6 logo

Integrated Site Security for Grids

A project co-funded by EU FP6 programme
Home page

Top Recommendations
Top Threats
Security Checklists
Risk assessment

my Role
my Site
my Community
All Recommendations
All Threats
Training
Downloads

Security terms


Contact
ISS & ISSeG

Recommendation

Manage changes to information processing facilities and systems

ID: R13

What: Operational systems and applications should be subject to strict change management control.
Why: Inadequate control of changes to information processing facilities and systems is a common cause of system or security failures. Changes to the operational environment, especially when transferring a system from development to operational stage, can impact reliability.
How :

Changes to operational systems should only be made when there is a valid reason to do so, such as an increase in the risk to the system. Updating systems with the latest versions of operating systems or applications is not always in the best interest of an organization, as this could introduce more vulnerabilities and instability than the current version. There may also be a need for additional training, license costs, support, maintenance and administration overhead, and new hardware especially during migration.

Formal management responsibilities and procedures should be in place to ensure satisfactory control of all changes to equipment, software or procedures. When changes are made, an audit log containing all relevant information should be retained. In particular, the following items should be considered:

  • Identification and recording of significant changes
  • Planning and testing of changes
  • Assessment of the potential impacts, including security impacts, of such changes
  • Formal approval procedure for proposed changes
  • Communication of change details to all relevant persons
  • Fallback procedures, including procedures and responsibilities for aborting and recovering from unsuccessful changes and unforeseen events.
Further information on change management can be found at the following links:
Relevant recommendations

R32, R33

Relevant threats:

T18, T19,

Relevant ISS audit questions: Q45, Q46, Q89, Q93
Keywords Application, Developer, Management, Network, Security, Service, Vulnerability
Recommendation Category:
Technical - Administrative -  Educational - X
Copyright (c) Members of the
ISSeG Collaboration
2008
Top of page Home page Information Society and media logo

This is version 5.2 of the website - view release notes
 -view visitor statistics