# Change management policy

Source: https://aestech.com.au/policy-templates/#change-management-policy
Markdown URL: https://aestech.com.au/policy-templates/change-management-policy.md

Use for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how changes to production systems, applications, infrastructure and configurations are requested, assessed, approved, tested, implemented and reviewed, so that changes do not introduce security or availability risk.

2. Scope
This policy applies to all changes to production and security-relevant systems, including code deployments, infrastructure changes, configuration changes, database changes and changes to security controls. It applies to all employees and contractors who make such changes.

3. Policy statements
- All changes to production must be recorded in a ticket or pull request before implementation.
- Changes must describe the reason, the affected systems, the risk and the rollback plan.
- Changes must be reviewed and approved by an authorised person other than the sole implementer, except for pre-approved standard changes.
- Changes must be tested before release where practical.
- Production, test and development environments must be kept separate.
- Emergency changes may bypass normal lead time but must still be recorded, approved as soon as practical and reviewed afterwards.
- Significant changes must be assessed for their effect on security controls and compliance scope.
- Changes affecting customers or availability must include a communication and rollback plan.

4. Roles and responsibilities
- The [Engineering Lead] owns the change process and the definition of standard changes.
- Change requesters document and propose changes.
- Approvers review risk and authorise changes.
- Implementers carry out changes and confirm success or trigger rollback.

5. Procedures
- Raise a change record with description, risk, test evidence and rollback plan.
- Obtain the required review and approval before deployment.
- Deploy through the approved pipeline and verify the outcome.
- For emergency changes, record the change, gain expedited approval and complete a post-change review.
- Maintain a list of pre-approved standard changes and review it periodically.

6. Evidence and records
Keep change tickets and pull requests, approvals, test evidence, deployment records, rollback plans, emergency change reviews and the standard change list.

7. Review cadence
This policy is reviewed at least annually and after major changes to the deployment process.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md