PDP-7 Change Management Workflow

Estimated reading: 2 minutes 2101 views

What is PDP-7 Change Management Workflow Control?

Policies, procedures, and documentation are integral parts of a good security program. The PDP-7 change management workflow provides the step-by-step procedures required for the creation, development, and implementation of a change.

As an organization, you must define the different types of changes (application, infrastructure, etc.) that could happen in your environment and the procedure to take those changes through deployment. There is no right or wrong way to format it, as each organization is unique.

The workflow must include a representation of the key tasks. Usually, the following key tasks are required:

  • Planning
  • Design
  • Development
  • Testing
  • Approval
  • Implementation/Deployment

Available tools in the marketplace

No tool recommendation is made for this section

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version.

Control implementation

To implement this control,

You need to document a change management policy and workflow that include the following components:

  • The types of changes in your organization (i.e., infrastructure changes, application changes, etc.)
  • The process to identify and prioritize changes
  • The changes in the tracking process
  • The changes in the development process
  • The changes in the testing process
  • The changes in the approval process
  • The changes in the deployment process

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action:

  1. Provide your change management policy or workflow.

Evidence example

For the suggested action, an example is provided below:

  1. Provide your change management policy or workflow.
    The following screenshot demonstrates the development lifecycle procedures available on the TrustCloud intranet share site.
    PDP 7 Change Management Workflow 01

Join the conversation