How scoped, tested, approved, versioned, and reversible changes protect security and service reliability.
Security changes can affect access, evidence, availability, and trust boundaries. Control them through a documented process that makes scope, impact, ownership, validation, and recovery clear.
| Change type | Typical treatment |
|---|---|
| Standard | Repeatable, pre-authorized low-risk procedure |
| Normal | Planned change with context-specific assessment and approval |
| Emergency | Urgent response with expedited authority, evidence, and retrospective review |
Version history preserves who changed what and why. A backup or snapshot restores a known-good state. Mature change management uses both, especially for identity, firewall, DNS, routing, certificate, and access-policy changes.