Change Management Board (CMB)
4 slides · 2 min read · Domain 7
Change Management Board
Change management boards evaluate, approve, and oversee IT changes to minimize risk and align with business objectives.
Most organizations have a hierarchy of approval authorities, depending on the level of risk a particular change presents to the operation.
Centralized change management boards (CMBs) typically oversee the changerelated activities, providing structure for stakeholder engagement and formal approval, while ensuring that the changes are properly resourced and implemented.
Clearly, the responsibilities and span of control that the CMB exerts will vary greatly depending on the organization.
The span of the CMB's interests may include all aspects of change management that concern the organization's security team.
These overlapping activities— such configuration management, vulnerability management, and patch management—are typically carried out within the framework of change management.
Many organizations don't make a distinction between these activities, while others conduct them in entirely separate silos.
CMBs should be concerned with continuous process improvement in all aspects of the systems they control and the tools and processes over which they exert control. The right set of automation can greatly assist in this, while providing the metrics to determine what improvements are being achieved.
As with many processes, what organizations say they do and how they actually manage their operations are often different.
An organization can generally judge the effectiveness of its change management practices by the level of deviation exhibited by the production environment.
Other ways to determine whether the change management practice is effective is by tracking the number of exceptions to baselines that are granted. An increasing number of exceptions to the baselines indicates that the baselines are not addressing the business needs of the organization and that the baselines themselves should be reevaluated.
Senior management remains the key to enforcing good change management practices.
If senior management exempts themselves from compliance, or if they are unwilling to enforce organizational standards, the message to the organization is clear: change management does not matter. If they do, organizations can expect the consistent application of security controls to their information environment.
