Change management policy
**Document control**
| Field | Value | |---|---| | Organization | [COMPANY NAME] | | Policy owner | [OWNER NAME / ROLE] | | Approver | [APPROVER NAME / ROLE] | | Version | [VERSION] | | Effective date | [YYYY-MM-DD] | | Next review | [YYYY-MM-DD] |
**Mapped themes:** SOC 2 CC8.1; ISO/IEC 27001:2022 Annex A.8.32, A.8.9 (educational mapping).
1. Purpose
This policy ensures changes to information processing systems are authorized, tested as appropriate, and recoverable so unauthorized or poorly controlled changes do not undermine security objectives.
2. Scope
Applies to production application, infrastructure-as-code, identity, and security-control changes for in-scope systems. Standard low-risk changes may follow a pre-approved path documented below.
3. Change types
- **Standard:** Pre-approved, low risk, documented runbook (e.g. routine dependency patch within policy).
- **Normal:** Requires review/approval before production deploy.
- **Emergency:** Production hotfix with retrospective review within [N] business days.
4. Policy statements
- Production changes are linked to a ticket or change record with requester, description, and risk notes.
- Normal changes require peer review (pull request or equivalent) and successful required CI checks before merge/deploy.
- Deployments to production are performed through approved pipelines; direct undocumented production edits are prohibited except break-glass with logging.
- Rollback or remediation plans are considered for high-risk changes.
- Emergency changes are logged and reviewed after the fact by [ROLE].
- Segregation of duties is applied proportionate to risk; compensating controls are documented when the same engineer must author and deploy.
5. Related documents
Information security policy; Access control policy; Secure development standards [LINK].
---
**Disclaimer:** Educational template only — not legal advice. Adapt with your auditor. ComplianceBase is vendor-neutral and independent.