ISO/IEC 27000 Change Management, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to change management.

Assessment Step

1
Change Management (ChangeManagement)
Are changes to information processing facilities and information systems subject to change management procedures?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Change Management
Changes to information processing facilities and information systems shall be subject to change management procedures.
Citations
27001
Annex A, Control 8.32
27002
Section 8.32