Change Management Policy
v2.2
Purpose. This policy requires every change to a production client or Nova system to be planned, approved, tested and recorded so that outages and security weaknesses are prevented.
1.Purpose and scope
Unplanned changes are the leading cause of outages in managed environments. This policy applies to any change to production infrastructure, security controls, applications, integrations, cloud configuration or client-facing systems, whether made remotely or on site.
2.Change categories
Standard changes are pre-approved, low risk and repeatable, such as adding a user or replacing a like for like device, and are recorded in the ticket. Normal changes must be submitted on the Change Request Form, assessed for risk and approved before work starts. Emergency changes to restore service or contain a security incident must be approved verbally by the team lead and documented within 24 hours.
- Standard: pre-approved, recorded in the ticket
- Normal: change request, risk assessment, approval, scheduled window
- Emergency: verbal lead approval, documented within 24 hours
3.Requirements for every change
Every normal change must have a description, a business reason, a risk and impact assessment, a test plan, a rollback plan, a communication plan for affected users and a scheduled window agreed with the client. The change must be recorded in the Change Request Register and the site documentation updated afterwards.
4.Approval
The team lead approves low and medium risk changes. High risk changes, including firewall rule changes, identity platform changes and anything affecting more than one client, must be approved by the change advisory group that meets each Tuesday.
5.Post change review
Every change will be closed with a result of successful, rolled back or partially successful. Failed or rolled back changes will be reviewed at the next change advisory group meeting to identify what to improve.
6.Review
This policy will be reviewed annually and after any major outage caused by a change.