YouTube2Text

Change Management - CompTIA Security+ SY0-701 - 1.3 — Transcript

by Professor Messer · 2,047 words · 305 segments · language en · Watch on YouTube

Full transcript

  1. 0:02when you're making a change to an
  2. 0:03application or an operating system that
  3. 0:05you use at home the scope of that change
  4. 0:07is usually based on a single computer
  5. 0:10but in a corporate environment or a
  6. 0:12large organization one single change
  7. 0:14could affect hundreds or even thousands
  8. 0:17of different systems if you're upgrading
  9. 0:19software or modifying an application or
  10. 0:21making a change to a router or firewall
  11. 0:24you'll need to go through a formal
  12. 0:26process to make sure that that change is
  13. 0:28going to work properly these types of
  14. 0:30changes occur constantly we know that
  15. 0:33Microsoft has updates for their
  16. 0:35operating systems every month and you
  17. 0:37might have hundreds or even thousands of
  18. 0:39applications that you use and those
  19. 0:41might have constant updates to those as
  20. 0:43well this is something that is
  21. 0:45incredibly important to stay on top of
  22. 0:47because a system that is not updated is
  23. 0:50one that is probably less secure this is
  24. 0:52why it's important to have a formal
  25. 0:54process for making changes in your
  26. 0:56environment if suddenly everyone was
  27. 0:59able to make any change they'd like
  28. 1:01whenever they would like you could run
  29. 1:03into problems with applications working
  30. 1:04properly or inconsistencies in the way
  31. 1:07that applications are able to use the
  32. 1:09operating system these processes May
  33. 1:11dictate how often you're able to make
  34. 1:13changes the type of changes that can be
  35. 1:16made and might even cover things like
  36. 1:18roll back procedures just in case you
  37. 1:20run into a problem when that change is
  38. 1:22updated many organizations already have
  39. 1:25a Change Control process and this makes
  40. 1:27it very easy to implement and control
  41. 1:29any type of change to your environment
  42. 1:31but if your organization doesn't have a
  43. 1:33formal Change Control process you may
  44. 1:36find it very difficult to implement or
  45. 1:38make changes to this corporate culture
  46. 1:41we have these formal change control
  47. 1:43processes so that we can maintain the
  48. 1:45uptime and availability of our systems
  49. 1:48we know that everyone is inform formed
  50. 1:50so there's no confusion about the
  51. 1:52changes being made and we want to be
  52. 1:53sure that no mistakes are made when
  53. 1:55people make changes to these systems
  54. 1:58here's a summary of a typical iCal
  55. 2:00Change Control process this might be a
  56. 2:02little bit different in your environment
  57. 2:04but it tends to follow a similar path
  58. 2:06regardless of where you might be the
  59. 2:08first part of the process is to fill out
  60. 2:10a formal Change Control process form
  61. 2:13this is something that everyone has to
  62. 2:14do so that all of the standard
  63. 2:16information is provided to the Central
  64. 2:18Committee that makes these decisions you
  65. 2:20would document in this form the reason
  66. 2:22that you're making this change so that
  67. 2:24everybody understands why this change is
  68. 2:26occurring you would then identify the
  69. 2:28scope of that change it might be a
  70. 2:30single system or a number of different
  71. 2:33systems and whoever's making the
  72. 2:35decision to either allow or disallow
  73. 2:37this change needs to understand what
  74. 2:39this scope would really be there would
  75. 2:41be a scheduling process so we would know
  76. 2:44exactly when the date and time for this
  77. 2:46change would be and then we would know
  78. 2:48what systems would be affected by this
  79. 2:50change and the impact of that change to
  80. 2:53be able to make a decision on whether
  81. 2:55this change should occur or not occur
  82. 2:57the Change Control Board generally needs
  83. 2:59to analyze the risk associated with the
  84. 3:01change for example this might be a
  85. 3:04significant change and it might be at a
  86. 3:06time of the year when the company is
  87. 3:08very busy so the Change Control
  88. 3:09committee would need to balance the risk
  89. 3:11of not making the change versus
  90. 3:14implementing the change and having a
  91. 3:15problem at this point the Change Control
  92. 3:17Board should have all of the information
  93. 3:19they need to make a decision on whether
  94. 3:21the change is allowed or not allowed and
  95. 3:24once the change is made you may want to
  96. 3:25have users try their systems and confirm
  97. 3:28that the change was updated without any
  98. 3:30type of problems the Change Control
  99. 3:33process usually starts with the owner of
  100. 3:35the application or the data wanting to
  101. 3:38make a change to that application or
  102. 3:40data the owner of the application or the
  103. 3:42data don't generally control the Change
  104. 3:44Control process and they're not usually
  105. 3:47the ones making the actual change to
  106. 3:49that application or to that data instead
  107. 3:52the owners are the ones managing the
  108. 3:54process the owner is kept informed as
  109. 3:57the Change Control process occurs and
  110. 3:59once once the change is complete the
  111. 4:01owner is responsible for testing their
  112. 4:03systems and verifying that everything is
  113. 4:05working properly for example your
  114. 4:07organization may have a department for
  115. 4:09shipping and receiving and there may be
  116. 4:11information that they've received that
  117. 4:13says their address label printers need
  118. 4:15to be upgraded in this example the
  119. 4:17shipping and receiving department is the
  120. 4:19owner of this process and they're going
  121. 4:21to hand that off to their it team to
  122. 4:24handle the actual change to the printing
  123. 4:27software another consideration for the
  124. 4:29change Control process are the
  125. 4:31stakeholders these are the individuals
  126. 4:33or departments that will be impacted by
  127. 4:35the change that you're proposing they
  128. 4:37will probably want to have input on the
  129. 4:39process and have some type of control
  130. 4:41over when this particular change occurs
  131. 4:44identifying the stakeholders may not be
  132. 4:46as obvious as you might think there are
  133. 4:48some changes that can affect a large
  134. 4:50number of people within the organization
  135. 4:52or perhaps the change is only affecting
  136. 4:54one single individual the IT team may
  137. 4:57need to research and identify any of the
  138. 5:00stakeholders who might be affected by
  139. 5:02this change let's take our previous
  140. 5:04example of upgrading software that's
  141. 5:06being used for shipping labels and you
  142. 5:08might think that this would only affect
  143. 5:10the shipping and receiving department
  144. 5:12but of course these shipping labels are
  145. 5:14also used by accounting to create
  146. 5:16reports of what has been shipped there
  147. 5:18might be product delivery time frames
  148. 5:21affected by this change especially if
  149. 5:23you're shipping directly to your
  150. 5:24customers this would in turn also affect
  151. 5:27Revenue recognition because it would
  152. 5:29affect how quickly you're able to get
  153. 5:31product into the hands of your customers
  154. 5:33and this would certainly have the
  155. 5:34visibility of the CEO this is a good
  156. 5:37example of how something that appears to
  157. 5:39be a very simple change to some printing
  158. 5:41software could ultimately have a
  159. 5:44dramatic effect to the bottom line of
  160. 5:46the company every change has a different
  161. 5:49potential impact on the organization so
  162. 5:52you need to recognize what risks may be
  163. 5:54involved when making any particular
  164. 5:56change this might be a risk value that
  165. 5:59you assign a high medium or low risk but
  166. 6:02these risks could also be very
  167. 6:04far-reaching there may be a case where
  168. 6:06you install a fix but it doesn't
  169. 6:08actually fix anything that certainly has
  170. 6:11a particular risk associated with it or
  171. 6:13maybe you install the fix and you end up
  172. 6:16breaking something else this is not
  173. 6:18entirely unheard of when patching
  174. 6:21systems there might be a failure of an
  175. 6:23operating system just because you
  176. 6:24installed this particular update or
  177. 6:26there might be Corruption of data which
  178. 6:28means you would need backups and all of
  179. 6:30these would certainly have different
  180. 6:32levels of risk you also have to consider
  181. 6:35what risks might be involved if you
  182. 6:37don't make the change for example there
  183. 6:39might be a security vulnerability and if
  184. 6:41you don't patch this application that
  185. 6:44vulnerability will be available to any
  186. 6:46attacker that may be coming across our
  187. 6:48Network this may cause an application to
  188. 6:50be unavailable if you don't patch the
  189. 6:53application or you might have other
  190. 6:55services that are no longer operating
  191. 6:58because you didn't make a change to a
  192. 7:00secondary service given these risks you
  193. 7:03may decide that you want to do a lot of
  194. 7:05testing before implementing this change
  195. 7:07into a production environment and for
  196. 7:09that we may use something like a Sandbox
  197. 7:11testing environment where you can
  198. 7:13perform as many tests as you'd like and
  199. 7:16have no effect on your production
  200. 7:18systems this is effectively a
  201. 7:20technological safe space where you can
  202. 7:22make mistakes you can try different
  203. 7:24techniques and then you can perform
  204. 7:26extensive testing after the fact to
  205. 7:28confirm that the update really did work
  206. 7:30properly inside of the sandbox we can
  207. 7:33load a duplicate environment to our
  208. 7:36production systems and then we can try
  209. 7:38the upgrade apply a patch make the
  210. 7:40change and see what effect that has to A
  211. 7:43system that is identical to what your
  212. 7:45users are using in production this is
  213. 7:48also a good time to test your
  214. 7:49contingency plan you can implement the
  215. 7:52change and even if the change was
  216. 7:53operational in your test environment you
  217. 7:56may want to test your backout procedures
  218. 7:58just to make sure that if something does
  219. 8:00go wrong in production you have a
  220. 8:02documented series of steps that brings
  221. 8:04everything back to the way it was before
  222. 8:07you made the change there are many
  223. 8:10documented cases through the years where
  224. 8:12someone thought that a change was very
  225. 8:13minor they make that change into an
  226. 8:16environment without even thinking that
  227. 8:18they would need to be able to revert
  228. 8:19back to a previous config and that
  229. 8:21change ends up bringing down their
  230. 8:23entire network this is why you need a
  231. 8:26backout plan you should have a way to
  232. 8:28reverse back to the original
  233. 8:30configuration or something that would be
  234. 8:32very similar to what you started with
  235. 8:35before the change took place in some
  236. 8:37cases this is a very simple process you
  237. 8:39simply uninstall the patch that you
  238. 8:41installed and confirm that the original
  239. 8:43files are back in place but some changes
  240. 8:46are very difficult to revert so you may
  241. 8:48need to have different techniques and
  242. 8:50ideas about how you can bring those
  243. 8:52systems back to their original form if
  244. 8:55something does go wrong this is why we
  245. 8:58often say that before you make make any
  246. 8:59change to A system that you have a full
  247. 9:02and complete backup of that system that
  248. 9:05way if you do make the change and run
  249. 9:06into a problem and then you try your
  250. 9:08backout plan and have a problem you can
  251. 9:11always go back to your backup you may
  252. 9:14find that the process for approval of
  253. 9:17the change is the easy part the
  254. 9:19difficult part is finding time to
  255. 9:22implement the change this is something
  256. 9:24that has to be planned and considered
  257. 9:26before making any significant change to
  258. 9:28production
  259. 9:29for example you may not want to make
  260. 9:31change during the workday when everybody
  261. 9:33is on their systems and performing their
  262. 9:36work instead you may want to have off
  263. 9:38hours or maintenance hours where you can
  264. 9:40make changes without having significant
  265. 9:43impact to users this is why you often
  266. 9:45see the it folks coming in on weekends
  267. 9:48and holidays and very early in the
  268. 9:50morning just so they can make change
  269. 9:52without any type of disruption to the
  270. 9:54network this can be especially
  271. 9:56challenging if you work in an
  272. 9:57environment that is 24 4 hours a day and
  273. 9:597 days a week where you have very little
  274. 10:02time available to make any changes in
  275. 10:05those systems you might also need to
  276. 10:07consider what time of the year you're
  277. 10:09making these changes take for example a
  278. 10:12company that is very retail-based and
  279. 10:14their busiest times of the year are
  280. 10:16between Thanksgiving and New Years in
  281. 10:19those environments it's not uncommon for
  282. 10:21all of their systems to be completely
  283. 10:23Frozen during that time frame and no
  284. 10:26changes would be allowed whatsoever only
  285. 10:28after after the New Year are you now
  286. 10:30able to reintroduce some type of Change
  287. 10:33Control and begin the process of
  288. 10:35updating your systems hopefully you can
  289. 10:37see now that change management is a
  290. 10:40critical part of your policies and
  291. 10:41procedures for security and it affects
  292. 10:44every single person in your organization
  293. 10:47in almost every environment this Change
  294. 10:48Control process is well documented and
  295. 10:51anyone in the company can read through
  296. 10:52the documentation on their internet this
  297. 10:55should be part of your standard
  298. 10:56operating procedures and no one should
  299. 10:58be able to make changes on your network
  300. 11:00without receiving this approval and of
  301. 11:03course your Change Control process is
  302. 11:05going to be updated over time to make it
  303. 11:07more efficient and fit the best with the
  304. 11:09requirements of the
  305. 11:20company

About this transcript

This page contains the full transcript of Change Management - CompTIA Security+ SY0-701 - 1.3 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 2,047 words across 305 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.