ISO 27001:2022
Technological controls – ISO 27001:2022

ISO 27001:2022 8.32: Change management

Every change to information systems and processing facilities is to pass through the change management procedures. Purpose (stated in ISO/IEC 27002:2022): preserves information security when changes are executed. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.32.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 152 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 18 controls

  • AC-2(1) Automated System Account Management
  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-3 Configuration Change Control
  • CM-3(2) Testing, Validation, and Documentation of Changes
  • CM-3(4) Security and Privacy Representatives
  • CM-4 Impact Analyses
  • CM-4(2) Impact Analyses | Verification of Controls (CM-4(2))
  • CM-5 Access Restrictions for Change
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))
  • MA-3 Maintenance Tools (MA-3)
  • PL-8 Security and Privacy Architectures
  • SA-10 Developer Configuration Management
  • SA-22 Unsupported System Components (SA-22)
  • SA-3 System Development Life Cycle
  • SI-6 Security and Privacy Function Verification (SI-6)
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(1) Integrity Checks
  • SI-7(7) Integration of Detection and Response

FedRAMP Moderate · 18 controls

  • AC-2(1) Automated System Account Management
  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-3 Configuration Change Control
  • CM-3(2) Testing, Validation, and Documentation of Changes
  • CM-3(4) Security and Privacy Representatives
  • CM-4 Impact Analyses
  • CM-4(2) Impact Analyses | Verification of Controls (CM-4(2))
  • CM-5 Access Restrictions for Change
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))
  • MA-3 Maintenance Tools (MA-3)
  • PL-8 Security and Privacy Architectures
  • SA-10 Developer Configuration Management
  • SA-22 Unsupported System Components (SA-22)
  • SA-3 System Development Life Cycle
  • SI-6 Security and Privacy Function Verification (SI-6)
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(1) Integrity Checks
  • SI-7(7) Integration of Detection and Response

PCI DSS 4.0 · 18 controls

  • 1.2.2 1.2.2 Network connection and NSC changes under change control
  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.5.2 11.5.2 Change detection on critical files
  • 11.6.1 11.6.1 Payment page tamper detection
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.5.3 12.5.3 Scope review after significant organisational change
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.6 2.2.6 System security parameters configured against misuse
  • 6.2.3.1 6.2.3.1 Manual code review independence and approval
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 6.4.3 6.4.3 Payment page script management
  • 6.5.1 6.5.1 Change control procedure for production
  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change
  • 6.5.3 6.5.3 Separate pre-production from production
  • 6.5.4 6.5.4 Separate roles between production and pre-production

NIST SP 800-53 Rev 5 · 13 controls

SOC 2 · 7 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SOC2-PI1.2 PI1.2 Controls over system inputs
  • SOC2-PI1.3 PI1.3 Controls over system processing
  • SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs

CIS Controls v8 · 6 controls

  • CIS-12.3 Securely Manage Network Infrastructure
  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-18.4 Validate Security Measures
  • CIS-2.7 Allowlist Authorized Scripts
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-7.2 Establish and Maintain a Remediation Process

ISO 27701:2019 · 6 controls

  • 5.8 Improvement
  • 6.11 Systems acquisition, development and maintenance
  • 6.11.1 Security requirements of information systems
  • 6.9 Operations security
  • 6.9.1 Operational procedures and responsibilities
  • 6.9.5 Control of operational software
  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

CMMC 2.0 · 5 controls

ISO 22301:2019 · 5 controls

  • 10.1 Nonconformity and corrective action
  • 6.1 Actions to address risks and opportunities
  • 6.3 Planning changes to the business continuity management system
  • 8.1 Operational planning and control
  • 8.4.5 Recovery

ISO/IEC 42001:2023 · 5 controls

  • 8.3 AI risk treatment
  • A.6 AI system life cycle
  • A.6.2.5 AI system deployment
  • A.7.5 Data provenance
  • A.9.4 Intended use of the AI system

C5 (Germany) · 4 controls

  • C5-DEV-03 Policies for changes to information systems
  • C5-DEV-05 Risk assessment, categorisation and prioritisation of changes
  • C5-DEV-07 Logging of changes
  • C5-DEV-09 Approvals for provision in the production environment

ISO 27001:2013 · 4 controls

  • A.12.1.2 Change management
  • A.14.2.2 System change control procedures
  • A.14.2.3 Technical review of applications after operating platform changes
  • A.14.2.4 Restrictions on changes to software packages

NIST SP 800-218 · 4 controls

  • AM-2 Use only approved services
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • DS-6 Enforce security of workload throughout DevOps lifecycle

COBIT 2019 · 3 controls

  • BAI03.10 BAI03.10 Maintain solutions
  • BAI06.01 BAI06.01 Evaluate, prioritize and authorize change requests
  • BAI06.02 BAI06.02 Manage emergency changes

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

  • SEC01-BP06 Automate deployment of standard security controls
  • SEC11-BP06 Deploy software programmatically

EU AI Act · 2 controls

ISO 27002:2022 · 2 controls

  • 8.32 Change management
  • 8.9 Configuration management
  • E8-APP-ML2 Application Control (ML2)
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • CPS230-9 Management of the Full Range of Operational Risks
  • CFTC-SS-5 Systems Development and Quality Assurance Category

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure

NIST SP 800-172 · 1 control

  • 3.1.1e Dual Authorization for Sensitive System Operations

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 8.32 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 152 it maps to, and the evidence behind each claim, over MCP and REST.