Change Management
Process design, risk decisions, and practical controls for moving production systems without treating every change alike.
Change management is where an organization decides how much certainty it needs before touching a live service. The useful work is not moving every request through the same form. It is separating repeatable, low-consequence work from changes that alter customer exposure, recovery options, data handling, or a dependency nobody owns directly. Change managers set the operating rules, service owners supply impact knowledge, and engineers push back when approval queues obscure an urgent operational decision. The quality of the system shows up in its exceptions: a risky deployment paused for missing rollback evidence, a standard change removed from needless review, or a dependency discovered before the maintenance window closes.
This coverage follows the mechanics behind those decisions: ITIL 4 change enablement, workable risk classification, scheduling conflicts, CAB preparation, and the evidence a team needs when a plan changes in flight. It also examines the point where control becomes theater. A long approval trail does not compensate for an untested backout path, and a fast pipeline does not erase the need to name an accountable owner. Read these articles to sharpen the handoffs between requestor, implementer, reviewer, and service owner, then use that structure to make each production change easier to defend and easier to reverse.
Start here
-
ITIL 4 Change Enablement, Explained in Plain English
Sets the discipline in operational terms before the narrower workflow and escalation articles add detail.
-
The change-window scheduling problem, and how teams actually solve it
Shows why calendar coordination becomes a risk-control problem rather than an administrative scheduling task.
-
The 12 External Risk Sources Every CAB Should Monitor
Connects outside signals to the information a change decision body needs before approving work.
More on Change Management
-
This Week in Change Risk — Week of Aug 31, 2026
AI infrastructure hit the CISA KEV catalog hard this week: LiteLLM, Kestra, and JFrog joined nine new exploited CVEs. Plus SonicWall, PaperCut, and DORA.
-
Asset Inventory Reconciliation: The Quarterly Change
Running an external asset view against your internal inventory once a quarter turns shadow assets into a change queue. Here is the exact process.
-
BOD 26-04: Pre-Wire Your Emergency Change Before the Clock
CISA's BOD 26-04 sets a 16-row deadline table. Here is how a CAB pre-authorizes the ECAB so a 3-day KEV clock never catches you improvising.
-
The Patch You Could Calendar: SharePoint's RCE Chain
Microsoft split a SharePoint RCE chain across two Patch Tuesdays. Here is how a CAB stages a planned emergency change for a fix you know is coming.
-
The 3-Day KEV Clock: A CAB Runbook for CVE-2026-8037
CISA gave Progress LoadMaster CVE-2026-8037 a three-day deadline. How a change advisory board runs an emergency change against that clock.
-
NIS2 Incident Reporting: A 24/72/1-Month CAB Runbook
NIS2 Article 23 gives you 24 hours, 72 hours, and one month to report a significant incident. A CAB runbook for hitting all three deadlines.
-
Cross-Region Failover Testing: Why Untested DR Fails
In-region redundancy did not save Azure West US customers. A change-managed guide to cross-region failover testing, RTO/RPO tiers, and game days.
-
VMSA-2026-0006: A vCenter Emergency-Change Playbook
Broadcom's VMSA-2026-0006 patches two CVSS 9.8 vCenter flaws with no workaround. How a CAB should run it as an emergency change.
-
ServiceNow AI Change Risk Assessment: What CABs Must Verify
ServiceNow's July 2026 patch auto-fills change risk assessments with AI. What the four risk mechanisms actually do, and what your CAB still has to own.
-
CISA BOD 26-04: Risk-Based Patch Deadlines for CABs
CISA BOD 26-04 replaces the flat 14-day KEV clock with 3, 14, and 60-day risk-based deadlines. What change managers and CABs must rebuild by December.
-
Azure West US Outage: When a Maintenance Change Breaks a Region
A maintenance-automation bug cut Azure West US for 5 hours on July 23. A change manager's breakdown of the failure and the CAB controls that catch it.
-
DORA Change Management Checklist for Resilience Teams
What DORA requires from IT change managers: Articles 9, 12, 17, and 24-27 mapped to a practical CAB checklist, plus a 90-day compliance plan.
-
How to Run a CAB Meeting in 2026 (ITIL 4 Guide)
A practical, ITIL 4-aligned guide to running a Change Advisory Board meeting: agenda, roles, metrics, and failure modes to avoid.
-
ServiceNow vs Jira Service Management for Change (2026)
ServiceNow vs Jira Service Management change management compared: risk scoring, CAB tools, CMDB vs Assets, pricing, and which fits your org.
-
SOC 2 Change Management Controls and Real Audit Questions
SOC 2 change management under CC8.1, CC7.1, and CC6: what auditors actually ask, what evidence to keep, and where automation falls short.