OPS-01Secure Operations
Change management
Changes to production are requested, reviewed, tested and recorded, with emergency changes reconciled afterwards.
Why it exists
Undocumented change is the most common cause of unexplained outage.
What usually proves it
Change records, approvals, emergency change log.
Smaller organizations
Pull request review plus a release note is enough.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC8.1
- Fully addressedISO/IEC 27001 Annex A · A.8.32
- Fully addressedNIST Cybersecurity Framework · PR.PS-01
- Fully addressedPCI DSS · 6.5.1
- Partially addressedHIPAA Security Rule · 164.308(a)(8) — Through periodic evaluation.
- Deliberately absentGDPR — Not addressed; change discipline is implied only through security of processing.
- Partially addressedEU AI Act · Art. 43(4) — Substantial modification triggers reassessment.
- Partially addressedNIST AI Risk Management Framework · MANAGE 4.1 — Post-deployment monitoring of changes.