Change management is the structured process for requesting, reviewing, approving, implementing, and documenting any change to IT systems. Software updates, firewall rule edits, and new deployments all move through defined steps so a routine tweak does not turn into an outage or an open door.
A typical flow starts with a change request that spells out the impact and a rollback plan, goes to a Change Advisory Board (CAB) for a risk-based decision, then runs in a scheduled window. Emergency changes take an expedited path but still get documented afterward. Where teams get burned is skipping the rollback plan or letting the emergency lane become the default, which quietly erases the audit trail that auditors and incident responders depend on. A change nobody recorded is the first thing you wish you had during a 2 a.m. investigation.
Why does change management matter for the CISSP exam?
Change management lives in Domain 7: Security Operations and pairs closely with configuration management. Know the request-to-review-to-approval flow, how it blocks unauthorized modifications, and why so many incidents trace back to a change made without one. ITIL frameworks are published through AXELOS ITIL.
Related terms: Configuration Management, Patch Management