Change Control Procedures Manual
Change Control Procedures Manual
Add new
networks.
Add segments
of networks
Add networks
wireless
Install new
Appliance
Update of
Firmware
Update of
Controllers
Programs 1. Implementation of
Applications and new ones programs
Systems applications.
2. Implementation
new
functionalities o
Improvements to the System.
5.3.2. Changes Requiring Authorization
The change control group must authorize these changes that require having been completed.
with all the activities of the present procedure on the different platforms
administered by the ILO members, have all the established documentation and the
authorizations to proceed with a change in a production environment.
If the action to be taken is not included in the following list, it is necessary to review.
its risk level to confirm if it should be considered a change and included in this
list.
[Link]. Hardware
Involves:
Computer equipment configuration, firmware update, modification of
parameters.
Operating system updates.
Replacement of components in computing equipment such as network cards, hard drives,
peripherals.
Horizontal or vertical scaling of computing equipment to provide a platform
more robust.
Maintenance of computer equipment.
MANUAL OF PROCEDURES ADMINISTRATION OF CHANGE CONTROL IN
TECHNOLOGICAL INFRASTRUCTURE INTERNAL WORK GROUP OF
TECHNOLOGICAL DEVELOPMENT Page 6 of 10 Code P15200-01/14.V2 Date Dec. 2014
UNCOPY CONTROLLED
Generate a ticket indicating the change that is going to be made and the asset that will be
impact
2. Fill out the Change Control Form developed for these purposes.
3. Is a budget required to make the change?
4. No, no budget is required; Move on to activity No. 12
5. Yes, a budget is required;
6. Does the change have an assigned budget?
7. Yes, the change has an assigned budget; it moves to activity No. 12.
8. No, the change does not have a budget assigned; it links with the Procedure of
Budgets and Costs.
9. Was the budget approved in a special session of the Board of Directors?
10. No, the budget was not approved in the special session; it moves to activity No. 23.
11. Yes, the budget was approved in a special session; It is linked with the
Purchasing Procedure.
12. The test of the change is authorized.
13. Test the change in the testing environment.
14. Was the test satisfactory?
15. No, it has not been the satisfactory test; Please make the necessary corrections.
return to activity No. 13.
16. Yes, it has been the satisfactory test; Update the Change Manual to
Infrastructure.
17. Review and approve the updated Infrastructure Change Manual.
18. The implementation in the production environment is approved.
19. Implement the changes according to the maintenance window defined in the
service agreements.
20. Certify the implementation of the changes.
21. It performs constant monitoring of the network and the operation of the equipment.
22. Prepare a project completion report for the IT Manager.
23. Record the lessons learned, attach the scanned form, close the ticket and
complete the procedure.
[Link]. Software
Applications:
Implementation of new application programs.
Implementation of new functionalities or improvements to the System.
Network (LAN/WAN):
Changes in network hardware configuration.
Installation/uninstallation of equipment.
Changes in IP Addressing.
Changes in routing protocols or routed protocols.
Contingency tests.
Software Management Update.
Maintenance of equipment and channels.
Security:
Configuration changes.
Updates or modifications of platforms.
Installation and uninstallation of new equipment.
Implementation of new policies in the domain, firewall
Maintenance of equipment or software.
Data center access.
Power supply shutdown of the Computing Center.
Maintenance of air conditioning units.
Data center
Air Conditioning and Precision Maintenance
Maintenance of the Fire Control System.
°Maintenance of the Moisture Detection System.
Rack Relocation.
Local repairs.
New electrical or logical connection facilities.
Maintenance and relocation of the Closed Circuit television system.
Addition of new equipment in the Computing Center.
Maintenance or relocation of UPS
MANUAL OF PROCEDURES FOR CHANGE CONTROL ADMINISTRATION IN
TECHNOLOGICAL INFRASTRUCTURE INTERNAL WORKING GROUP OF
TECHNOLOGICAL DEVELOPMENT Page 7 of 10 Code P15200-01/14.V2 Date Dec. 2014
UNCOPYRIGHTED COPY
Workstations
Mass software installations or updates and/or changes that affect the configuration
of computer equipment.
Preventive and corrective maintenance.
The retention periods of the records will be those determined in the tables of
document retention of the Office of Information Technology and Telecommunications
For hardware changes, procedures involve configuration of computer equipment, firmware updates, replacement of components, and scaling of computing equipment. For software applications, it includes the implementation of new programs, functionalities, improvements, and updates. Both require documenting and authorizing following change control guidelines, but hardware changes often include physical alterations and scaling which aren't typically involved in software changes .
Post-implementation monitoring involves constantly observing network and equipment operations to ensure that changes have the desired effect without negative impacts. This step is crucial as it validates change success, identifies unforeseen issues, and ensures continuity of service .
The steps involved in implementing a change in a production environment, as per the described change control procedures, include generating a ticket indicating the change and the asset impacted, filling out the Change Control Form, ensuring approval and budget allocation, testing the change in a testing environment, updating and reviewing the Change Manual, approving and implementing the change according to service agreements, and certifying and monitoring the network and equipment operation post-change .
Relocating racks involves planning for space, connectivity, power, and cooling needs, as well as ensuring minimal disruption during the transition. This fits into change management as it requires thorough documentation, evaluation of impacts, testing, and coordination to prevent operational disturbances .
A budget requires approval in a special session of the Board of Directors when significant financial investment is needed for a change not pre-approved in the budget or when the change exceeds existing budget allocations. This ensures oversight and alignment with strategic goals .
Maintenance activities include air conditioning and precision maintenance, fire control systems, moisture detection systems, and power supply management. These actions are critical to ensure the operational efficiency, safety, and reliability of computing centers, preventing downtime and potential system failures .
The contingencies considered include changes in network hardware configuration, changes in IP addressing, routing protocols, conducting contingency tests, and the maintenance of equipment and channels. These contingencies aim to ensure the network's reliability and performance post-modification .
Linking changes without an assigned budget to the Procedure of Budgets and Costs is necessary to ensure financial viability and approval. This step ensures that resources are available and that changes align with organizational financial plans, avoiding potential budget overruns or unauthorized spending .
The Change Control Form documents the specifics of the change, ensuring all necessary approvals and considerations are captured. If the change has no budget assigned, it is linked with the Procedure of Budgets and Costs to obtain necessary financial resources and organizational approval, ensuring compliance with financial processes .
Lessons learned are documented in a project completion report, alongside any scanned forms and closing tickets. This documentation is crucial as it captures insights and improvements for future change processes, contributing to organizational learning and process optimization .