<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Change Risk Intel</title><description>Independent research and news on IT change management, operational risk, and CAB decision-making.</description><link>https://changeriskintel.com/</link><language>en-us</language><ttl>10080</ttl><item><title>The 12 External Risk Sources Every CAB Should Monitor</title><link>https://changeriskintel.com/posts/12-external-risk-sources-every-cab-should-monitor/</link><guid isPermaLink="true">https://changeriskintel.com/posts/12-external-risk-sources-every-cab-should-monitor/</guid><description>The 12 external feeds — CISA KEV, Patch Tuesday, cloud status pages, NVD, and more — a CAB should track before approving changes.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The 12 external feeds — CISA KEV, Patch Tuesday, cloud status pages, NVD, and more — a CAB should track before approving changes.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/12-external-risk-sources-every-cab-should-monitor/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>change-management</category><category>risk-intelligence</category><category>cab</category><category>operational-risk</category><author>Ben Ennis</author></item><item><title>AWS us-east-1 Outage History: A 5-Year Timeline</title><link>https://changeriskintel.com/posts/aws-us-east-1-outage-history-5-year-timeline/</link><guid isPermaLink="true">https://changeriskintel.com/posts/aws-us-east-1-outage-history-5-year-timeline/</guid><description>Every confirmed AWS us-east-1 outage since 2021, sourced from AWS&apos;s own post-event summaries, with root causes and what changed.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Every confirmed AWS us-east-1 outage since 2021, sourced from AWS&apos;s own post-event summaries, with root causes and what changed.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/aws-us-east-1-outage-history-5-year-timeline/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>aws</category><category>us-east-1</category><category>cloud-outages</category><category>postmortem</category><category>reliability</category><author>Ben Ennis</author></item><item><title>Best Change Management Software for Regulated Industries 2026</title><link>https://changeriskintel.com/posts/best-change-management-software-regulated-industries-2026/</link><guid isPermaLink="true">https://changeriskintel.com/posts/best-change-management-software-regulated-industries-2026/</guid><description>10 ITSM vendors compared on FedRAMP, SOC 2, SoD, CAB, and data residency for SOX, HIPAA, PCI DSS, and DORA-scoped buyers.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;10 ITSM vendors compared on FedRAMP, SOC 2, SoD, CAB, and data residency for SOX, HIPAA, PCI DSS, and DORA-scoped buyers.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/best-change-management-software-regulated-industries-2026/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>change-management-software</category><category>itsm</category><category>regulated-industries</category><category>vendor-comparison</category><category>grc</category><author>The Change Risk Intel Desk</author></item><item><title>The change-window scheduling problem, and how teams actually solve it</title><link>https://changeriskintel.com/posts/change-window-scheduling-how-teams-solve-it/</link><guid isPermaLink="true">https://changeriskintel.com/posts/change-window-scheduling-how-teams-solve-it/</guid><description>Change window scheduling means balancing low-risk timing against staffing and burnout. Here&apos;s how CAB teams, tools, and policy actually resolve it.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Change window scheduling means balancing low-risk timing against staffing and burnout. Here&apos;s how CAB teams, tools, and policy actually resolve it.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/change-window-scheduling-how-teams-solve-it/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>change-window</category><category>scheduling</category><category>cab</category><category>change-management</category><category>operations</category><author>Ben Ennis</author></item><item><title>DORA Change Management Checklist for Resilience Teams</title><link>https://changeriskintel.com/posts/dora-operational-resilience-change-managers-checklist/</link><guid isPermaLink="true">https://changeriskintel.com/posts/dora-operational-resilience-change-managers-checklist/</guid><description>What DORA requires from IT change managers: Articles 9, 12, 17, and 24-27 mapped to a practical CAB checklist, plus a 90-day compliance plan.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;What DORA requires from IT change managers: Articles 9, 12, 17, and 24-27 mapped to a practical CAB checklist, plus a 90-day compliance plan.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/dora-operational-resilience-change-managers-checklist/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>dora</category><category>eu-regulation</category><category>operational-resilience</category><category>compliance</category><category>change-management</category><author>The Change Risk Intel Desk</author></item><item><title>How to Read a CISA KEV Entry and What to Do Next</title><link>https://changeriskintel.com/posts/how-to-read-a-cisa-kev-entry/</link><guid isPermaLink="true">https://changeriskintel.com/posts/how-to-read-a-cisa-kev-entry/</guid><description>A field-by-field guide to CISA KEV catalog entries, BOD 22-01 obligations, and a 24-hour runbook for when a new KEV drops.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;A field-by-field guide to CISA KEV catalog entries, BOD 22-01 obligations, and a 24-hour runbook for when a new KEV drops.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/how-to-read-a-cisa-kev-entry/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>cisa-kev</category><category>vulnerability-management</category><category>cybersecurity</category><category>patch-management</category><author>Ben Ennis</author></item><item><title>How to Run a CAB Meeting in 2026 (ITIL 4 Guide)</title><link>https://changeriskintel.com/posts/how-to-run-a-cab-meeting-in-2026/</link><guid isPermaLink="true">https://changeriskintel.com/posts/how-to-run-a-cab-meeting-in-2026/</guid><description>A practical, ITIL 4-aligned guide to running a Change Advisory Board meeting: agenda, roles, metrics, and failure modes to avoid.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;A practical, ITIL 4-aligned guide to running a Change Advisory Board meeting: agenda, roles, metrics, and failure modes to avoid.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/how-to-run-a-cab-meeting-in-2026/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>cab</category><category>change-advisory-board</category><category>itil</category><category>change-management</category><author>Ben Ennis</author></item><item><title>ITIL 4 Change Enablement, Explained in Plain English</title><link>https://changeriskintel.com/posts/itil-4-change-enablement-explained/</link><guid isPermaLink="true">https://changeriskintel.com/posts/itil-4-change-enablement-explained/</guid><description>ITIL 4 renamed change management to change enablement. Here&apos;s what changed, the three change types, and how ServiceNow and Jira implement it.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;ITIL 4 renamed change management to change enablement. Here&apos;s what changed, the three change types, and how ServiceNow and Jira implement it.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/itil-4-change-enablement-explained/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>itil</category><category>itil-4</category><category>change-enablement</category><category>change-management</category><author>The Change Risk Intel Desk</author></item><item><title>Patch Tuesday: What It Is and How to Plan Around It</title><link>https://changeriskintel.com/posts/patch-tuesday-what-it-is-and-how-to-plan/</link><guid isPermaLink="true">https://changeriskintel.com/posts/patch-tuesday-what-it-is-and-how-to-plan/</guid><description>Patch Tuesday schedule 2026, MSRC cadence, and a CAB-ready playbook for scheduling change windows around Microsoft&apos;s monthly updates.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Patch Tuesday schedule 2026, MSRC cadence, and a CAB-ready playbook for scheduling change windows around Microsoft&apos;s monthly updates.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/patch-tuesday-what-it-is-and-how-to-plan/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>patch-tuesday</category><category>msrc</category><category>microsoft</category><category>patch-management</category><category>cybersecurity</category><author>The Change Risk Intel Desk</author></item><item><title>ServiceNow vs Jira Service Management for Change (2026)</title><link>https://changeriskintel.com/posts/servicenow-vs-jira-service-management-change-2026/</link><guid isPermaLink="true">https://changeriskintel.com/posts/servicenow-vs-jira-service-management-change-2026/</guid><description>ServiceNow vs Jira Service Management change management compared: risk scoring, CAB tools, CMDB vs Assets, pricing, and which fits your org.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;ServiceNow vs Jira Service Management change management compared: risk scoring, CAB tools, CMDB vs Assets, pricing, and which fits your org.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/servicenow-vs-jira-service-management-change-2026/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>servicenow</category><category>jira-service-management</category><category>itsm</category><category>change-management</category><category>vendor-comparison</category><author>Ben Ennis</author></item><item><title>SOC 2 Change Management Controls and Real Audit Questions</title><link>https://changeriskintel.com/posts/soc-2-change-management-controls-audit-questions/</link><guid isPermaLink="true">https://changeriskintel.com/posts/soc-2-change-management-controls-audit-questions/</guid><description>SOC 2 change management under CC8.1, CC7.1, and CC6: what auditors actually ask, what evidence to keep, and where automation falls short.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;SOC 2 change management under CC8.1, CC7.1, and CC6: what auditors actually ask, what evidence to keep, and where automation falls short.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/soc-2-change-management-controls-audit-questions/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>soc-2</category><category>compliance</category><category>audit</category><category>change-management</category><category>trust-services-criteria</category><author>The Change Risk Intel Desk</author></item><item><title>SOX Change Control Checklist Mapped to Your ITSM Workflow</title><link>https://changeriskintel.com/posts/sox-change-control-requirements-mapped-to-itsm/</link><guid isPermaLink="true">https://changeriskintel.com/posts/sox-change-control-requirements-mapped-to-itsm/</guid><description>What SOX §404 and ITGC actually require for IT change control, mapped field-by-field to ServiceNow and Jira Service Management tickets.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;What SOX §404 and ITGC actually require for IT change control, mapped field-by-field to ServiceNow and Jira Service Management tickets.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://changeriskintel.com/posts/sox-change-control-requirements-mapped-to-itsm/&quot;&gt;Read the full analysis on Change Risk Intel →&lt;/a&gt;&lt;/p&gt;</content:encoded><category>sox</category><category>compliance</category><category>itgc</category><category>change-control</category><category>audit</category><author>The Change Risk Intel Desk</author></item></channel></rss>