Standard changes: what the auditor reads in them
A standard change is pre-authorised: a low-risk, repeatable change that follows a documented procedure and does not go to the change board each time. The approval sits in the catalogue entry that defines it, so the row may carry no individual approver. The checker still lists it under no independent approval, because the export shows none; the answer for an auditor is the standard change catalogue entry.
How the checker recognises them
Read from the change type column: standard, pre-approved or routine.
Findings they raise most often
- No independent approval: Who approved this change before it reached production, and where is that approval recorded by someone other than the author?
- No ticket reference: Where are the request, the reason and the impact assessment for this change?
The clauses that speak to them
3 clausesCOBIT BAI06.01 Evaluate, prioritize and authorize change requestsThe clause text
All requests for change are evaluated to determine their impact on business processes and I&T services and to assess whether the change will adversely affect the operational environment and introduce unacceptable risk, and changes are logged, prioritised, categorised, assessed, authorised, planned and scheduled: formal change requests let process owners and IT request changes to processes, infrastructure, systems or applications, with all changes arising only through the change management process and pre-screened for standard changes; requests are categorised (business process, infrastructure, operating systems, networks, applications, packaged software) and related to affected configuration items; they are prioritised on business and technical requirements, resources and legal, regulatory and contractual reasons; each change is formally approved by process owners, service managers and IT technical stakeholders as appropriate, with low-risk frequent changes pre-approved as standard; approved changes are planned and scheduled; every request is evaluated in a structured way with impact analysis on processes, infrastructure, systems, applications, continuity plans and service providers so that all affected components are identified; and the effect of contracted providers on change management is considered, including integration of their processes into the enterprise's.
Where it usually falls short: Changes made outside the process by administrators with direct access; Impact analysis that ignores the continuity plan and outsourced components
Source: COBIT 2019
ISO 27001 8.32 Change managementThe clause text
Put changes to facilities and systems through change management procedures.
Where it usually falls short: Missing formal approval; No rollback plan documented
Source: ISO/IEC 27001:2022
SP 800-53 CM-3 Configuration change controlThe clause text
Requires the types of change that fall under configuration control to be defined, proposed changes to be reviewed and approved or rejected with explicit consideration of security and privacy impact, decisions and implemented changes to be documented, change records to be retained for a defined period, and change activity to be monitored and reviewed by the responsible body.
Where it usually falls short: Emergency changes bypass approval and are never retrospectively documented; Impact analysis recorded as a tick box with no security reasoning behind it
Source: NIST SP 800-53 Rev 5