Skip to main content
Review and revision metadata
Review Date: 2026-08-18
Reviewer: Operations Manager

previous version on gdrive

6.3 Planning of Changes

When a systemic, technological, or structural need to modify the ISMS is identified, the alteration must be executed in a planned, highly controlled manner to preserve system integrity and maintain compliance thresholds.

6.3.1 ISMS Change Management Procedure

Modifications to the framework must progress sequentially through the following formal governance lifecycle, satisfying ISO/IEC 27001 Clause 6.3 and aligning with A.08.32 (Change Management):

  1. Assess the Need for Change: Identify and document the driving justification for the structural change (e.g., internal audit deficiencies, risk assessment outcomes, or external regulatory adjustments).
  2. Define the Scope of Change: Clearly outline the precise boundaries of the change, defining all affected assets, technical controls, corporate policies, and operational procedures.
  3. Plan the Change Process: Construct an explicit change plan detailing implementation timelines, functional responsibilities, and required resource allocations.
  4. Assess Risks and Impacts: Evaluate whether the change introduces secondary vulnerabilities, operational friction, or regression risks to our certified ISO/IEC 27001 profile.
  5. Involve Relevant Stakeholders: Engage all necessary engineering teams, compliance officers, and management tiers to ensure comprehensive awareness of downstream impacts and deployment expectations.
  6. Test Changes in a Controlled Environment: Stage and validate technical or architectural adjustments in an isolated, secure non-production environment to verify functionality and ensure no configuration gaps exist.
  7. Monitor the Change Implementation: Track deployment telemetry in real-time to intercept and remediate any unforeseen operational side effects or edge-case security anomalies.
  8. Review the Change: Evaluate the proposed change against the organization’s active security objectives and risk management frameworks to ensure complete operational alignment.
  9. Approval from Management: Present the finalized change plan to relevant decision-makers to secure explicit, formal approval prior to production deployment.
  10. Verify the Success of the Change: Audit the post-implementation outcomes to verify successful remediation and ensure that all intended security objectives are met.
  11. Update Documentation: Revise and synchronize all associated ISMS documentation, control descriptions, and policy frameworks to accurately reflect the newly implemented state.
  12. Monitor the Effectiveness of the Changes: Conduct ongoing monitoring to validate the long-term performance and stability of the implemented modification.

6.3.2 Auditability and Records Management

To ensure traceability for external auditors and internal review boards:

  • All documentation, staging results, and associated risk analysis files are stored securely in the dedicated SIA Changes ISMS repository folder.
  • Structural alterations to the framework are centrally tracked and logged inside the Changes to ISMS Register.