Change Management - CompTIA Security+ SY0-701 - 1.3 — Transcript
Full transcript
- 0:02when you're making a change to an
- 0:03application or an operating system that
- 0:05you use at home the scope of that change
- 0:07is usually based on a single computer
- 0:10but in a corporate environment or a
- 0:12large organization one single change
- 0:14could affect hundreds or even thousands
- 0:17of different systems if you're upgrading
- 0:19software or modifying an application or
- 0:21making a change to a router or firewall
- 0:24you'll need to go through a formal
- 0:26process to make sure that that change is
- 0:28going to work properly these types of
- 0:30changes occur constantly we know that
- 0:33Microsoft has updates for their
- 0:35operating systems every month and you
- 0:37might have hundreds or even thousands of
- 0:39applications that you use and those
- 0:41might have constant updates to those as
- 0:43well this is something that is
- 0:45incredibly important to stay on top of
- 0:47because a system that is not updated is
- 0:50one that is probably less secure this is
- 0:52why it's important to have a formal
- 0:54process for making changes in your
- 0:56environment if suddenly everyone was
- 0:59able to make any change they'd like
- 1:01whenever they would like you could run
- 1:03into problems with applications working
- 1:04properly or inconsistencies in the way
- 1:07that applications are able to use the
- 1:09operating system these processes May
- 1:11dictate how often you're able to make
- 1:13changes the type of changes that can be
- 1:16made and might even cover things like
- 1:18roll back procedures just in case you
- 1:20run into a problem when that change is
- 1:22updated many organizations already have
- 1:25a Change Control process and this makes
- 1:27it very easy to implement and control
- 1:29any type of change to your environment
- 1:31but if your organization doesn't have a
- 1:33formal Change Control process you may
- 1:36find it very difficult to implement or
- 1:38make changes to this corporate culture
- 1:41we have these formal change control
- 1:43processes so that we can maintain the
- 1:45uptime and availability of our systems
- 1:48we know that everyone is inform formed
- 1:50so there's no confusion about the
- 1:52changes being made and we want to be
- 1:53sure that no mistakes are made when
- 1:55people make changes to these systems
- 1:58here's a summary of a typical iCal
- 2:00Change Control process this might be a
- 2:02little bit different in your environment
- 2:04but it tends to follow a similar path
- 2:06regardless of where you might be the
- 2:08first part of the process is to fill out
- 2:10a formal Change Control process form
- 2:13this is something that everyone has to
- 2:14do so that all of the standard
- 2:16information is provided to the Central
- 2:18Committee that makes these decisions you
- 2:20would document in this form the reason
- 2:22that you're making this change so that
- 2:24everybody understands why this change is
- 2:26occurring you would then identify the
- 2:28scope of that change it might be a
- 2:30single system or a number of different
- 2:33systems and whoever's making the
- 2:35decision to either allow or disallow
- 2:37this change needs to understand what
- 2:39this scope would really be there would
- 2:41be a scheduling process so we would know
- 2:44exactly when the date and time for this
- 2:46change would be and then we would know
- 2:48what systems would be affected by this
- 2:50change and the impact of that change to
- 2:53be able to make a decision on whether
- 2:55this change should occur or not occur
- 2:57the Change Control Board generally needs
- 2:59to analyze the risk associated with the
- 3:01change for example this might be a
- 3:04significant change and it might be at a
- 3:06time of the year when the company is
- 3:08very busy so the Change Control
- 3:09committee would need to balance the risk
- 3:11of not making the change versus
- 3:14implementing the change and having a
- 3:15problem at this point the Change Control
- 3:17Board should have all of the information
- 3:19they need to make a decision on whether
- 3:21the change is allowed or not allowed and
- 3:24once the change is made you may want to
- 3:25have users try their systems and confirm
- 3:28that the change was updated without any
- 3:30type of problems the Change Control
- 3:33process usually starts with the owner of
- 3:35the application or the data wanting to
- 3:38make a change to that application or
- 3:40data the owner of the application or the
- 3:42data don't generally control the Change
- 3:44Control process and they're not usually
- 3:47the ones making the actual change to
- 3:49that application or to that data instead
- 3:52the owners are the ones managing the
- 3:54process the owner is kept informed as
- 3:57the Change Control process occurs and
- 3:59once once the change is complete the
- 4:01owner is responsible for testing their
- 4:03systems and verifying that everything is
- 4:05working properly for example your
- 4:07organization may have a department for
- 4:09shipping and receiving and there may be
- 4:11information that they've received that
- 4:13says their address label printers need
- 4:15to be upgraded in this example the
- 4:17shipping and receiving department is the
- 4:19owner of this process and they're going
- 4:21to hand that off to their it team to
- 4:24handle the actual change to the printing
- 4:27software another consideration for the
- 4:29change Control process are the
- 4:31stakeholders these are the individuals
- 4:33or departments that will be impacted by
- 4:35the change that you're proposing they
- 4:37will probably want to have input on the
- 4:39process and have some type of control
- 4:41over when this particular change occurs
- 4:44identifying the stakeholders may not be
- 4:46as obvious as you might think there are
- 4:48some changes that can affect a large
- 4:50number of people within the organization
- 4:52or perhaps the change is only affecting
- 4:54one single individual the IT team may
- 4:57need to research and identify any of the
- 5:00stakeholders who might be affected by
- 5:02this change let's take our previous
- 5:04example of upgrading software that's
- 5:06being used for shipping labels and you
- 5:08might think that this would only affect
- 5:10the shipping and receiving department
- 5:12but of course these shipping labels are
- 5:14also used by accounting to create
- 5:16reports of what has been shipped there
- 5:18might be product delivery time frames
- 5:21affected by this change especially if
- 5:23you're shipping directly to your
- 5:24customers this would in turn also affect
- 5:27Revenue recognition because it would
- 5:29affect how quickly you're able to get
- 5:31product into the hands of your customers
- 5:33and this would certainly have the
- 5:34visibility of the CEO this is a good
- 5:37example of how something that appears to
- 5:39be a very simple change to some printing
- 5:41software could ultimately have a
- 5:44dramatic effect to the bottom line of
- 5:46the company every change has a different
- 5:49potential impact on the organization so
- 5:52you need to recognize what risks may be
- 5:54involved when making any particular
- 5:56change this might be a risk value that
- 5:59you assign a high medium or low risk but
- 6:02these risks could also be very
- 6:04far-reaching there may be a case where
- 6:06you install a fix but it doesn't
- 6:08actually fix anything that certainly has
- 6:11a particular risk associated with it or
- 6:13maybe you install the fix and you end up
- 6:16breaking something else this is not
- 6:18entirely unheard of when patching
- 6:21systems there might be a failure of an
- 6:23operating system just because you
- 6:24installed this particular update or
- 6:26there might be Corruption of data which
- 6:28means you would need backups and all of
- 6:30these would certainly have different
- 6:32levels of risk you also have to consider
- 6:35what risks might be involved if you
- 6:37don't make the change for example there
- 6:39might be a security vulnerability and if
- 6:41you don't patch this application that
- 6:44vulnerability will be available to any
- 6:46attacker that may be coming across our
- 6:48Network this may cause an application to
- 6:50be unavailable if you don't patch the
- 6:53application or you might have other
- 6:55services that are no longer operating
- 6:58because you didn't make a change to a
- 7:00secondary service given these risks you
- 7:03may decide that you want to do a lot of
- 7:05testing before implementing this change
- 7:07into a production environment and for
- 7:09that we may use something like a Sandbox
- 7:11testing environment where you can
- 7:13perform as many tests as you'd like and
- 7:16have no effect on your production
- 7:18systems this is effectively a
- 7:20technological safe space where you can
- 7:22make mistakes you can try different
- 7:24techniques and then you can perform
- 7:26extensive testing after the fact to
- 7:28confirm that the update really did work
- 7:30properly inside of the sandbox we can
- 7:33load a duplicate environment to our
- 7:36production systems and then we can try
- 7:38the upgrade apply a patch make the
- 7:40change and see what effect that has to A
- 7:43system that is identical to what your
- 7:45users are using in production this is
- 7:48also a good time to test your
- 7:49contingency plan you can implement the
- 7:52change and even if the change was
- 7:53operational in your test environment you
- 7:56may want to test your backout procedures
- 7:58just to make sure that if something does
- 8:00go wrong in production you have a
- 8:02documented series of steps that brings
- 8:04everything back to the way it was before
- 8:07you made the change there are many
- 8:10documented cases through the years where
- 8:12someone thought that a change was very
- 8:13minor they make that change into an
- 8:16environment without even thinking that
- 8:18they would need to be able to revert
- 8:19back to a previous config and that
- 8:21change ends up bringing down their
- 8:23entire network this is why you need a
- 8:26backout plan you should have a way to
- 8:28reverse back to the original
- 8:30configuration or something that would be
- 8:32very similar to what you started with
- 8:35before the change took place in some
- 8:37cases this is a very simple process you
- 8:39simply uninstall the patch that you
- 8:41installed and confirm that the original
- 8:43files are back in place but some changes
- 8:46are very difficult to revert so you may
- 8:48need to have different techniques and
- 8:50ideas about how you can bring those
- 8:52systems back to their original form if
- 8:55something does go wrong this is why we
- 8:58often say that before you make make any
- 8:59change to A system that you have a full
- 9:02and complete backup of that system that
- 9:05way if you do make the change and run
- 9:06into a problem and then you try your
- 9:08backout plan and have a problem you can
- 9:11always go back to your backup you may
- 9:14find that the process for approval of
- 9:17the change is the easy part the
- 9:19difficult part is finding time to
- 9:22implement the change this is something
- 9:24that has to be planned and considered
- 9:26before making any significant change to
- 9:28production
- 9:29for example you may not want to make
- 9:31change during the workday when everybody
- 9:33is on their systems and performing their
- 9:36work instead you may want to have off
- 9:38hours or maintenance hours where you can
- 9:40make changes without having significant
- 9:43impact to users this is why you often
- 9:45see the it folks coming in on weekends
- 9:48and holidays and very early in the
- 9:50morning just so they can make change
- 9:52without any type of disruption to the
- 9:54network this can be especially
- 9:56challenging if you work in an
- 9:57environment that is 24 4 hours a day and
- 9:597 days a week where you have very little
- 10:02time available to make any changes in
- 10:05those systems you might also need to
- 10:07consider what time of the year you're
- 10:09making these changes take for example a
- 10:12company that is very retail-based and
- 10:14their busiest times of the year are
- 10:16between Thanksgiving and New Years in
- 10:19those environments it's not uncommon for
- 10:21all of their systems to be completely
- 10:23Frozen during that time frame and no
- 10:26changes would be allowed whatsoever only
- 10:28after after the New Year are you now
- 10:30able to reintroduce some type of Change
- 10:33Control and begin the process of
- 10:35updating your systems hopefully you can
- 10:37see now that change management is a
- 10:40critical part of your policies and
- 10:41procedures for security and it affects
- 10:44every single person in your organization
- 10:47in almost every environment this Change
- 10:48Control process is well documented and
- 10:51anyone in the company can read through
- 10:52the documentation on their internet this
- 10:55should be part of your standard
- 10:56operating procedures and no one should
- 10:58be able to make changes on your network
- 11:00without receiving this approval and of
- 11:03course your Change Control process is
- 11:05going to be updated over time to make it
- 11:07more efficient and fit the best with the
- 11:09requirements of the
- 11:20company
About this transcript
This page contains the full transcript of Change Management - CompTIA Security+ SY0-701 - 1.3 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 2,047 words across 305 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.