Change management
A process to assess, approve, and plan changes to IT services before implementing them.
Configuration management
An up-to-date record of the configuration items (CIs) that make up each service.
Testing and validation
Verifying that a new or modified service meets requirements before going live.
What an auditor usually asks for
- Change management process documented
- Configuration management database (CMDB) up to date
- Test plan for significant changes
- Log of approved changes and their outcome
How to cover this block in Kimobox
- 1Manage change requests as an approval workflow in Kimobox.
- 2Log configuration items as version-controlled assets.
- 3Document the outcome of each test before approving the move to production.
Every change comes with its approval, tests, and outcome documented in the same workflow.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO/IEC 20000-1:2018 — Service management system requirements ISO/IEC · September 2018
- ISO/IEC 27001:2022 — Information security ISO/IEC · 25 October 2022