Kean University IT SOP 01 – Change Management Operational Procedure


Kean University IT Change Management – Operational Procedure

Table of Contents

About This Procedure

This Standard Operating Procedure (SOP) defines the standardized operational steps for submitting, reviewing, approving, implementing, and reviewing technology and process changes at Kean University. It supports compliance with the Kean University IT Change Management Policy and promotes consistent, controlled change practices.

Scope

This procedure applies to all technology, infrastructure, application, configuration, and security changes that impact Kean University systems.

Definitions

  • Request for Change (RFC): A formal request to modify a system, service, or process.
  • Change Advisory Board (CAB): A group responsible for reviewing and approving medium- and high-risk changes.
  • Post-Implementation Review (PIR): A review conducted after a change to evaluate outcomes and lessons learned.

Roles and Responsibilities

  • Change Manager: Owns the workflow, change classification, scheduling, and CAB coordination.
  • Change Implementer: Executes approved changes and performs required testing.
  • Information Security: Reviews changes for security and compliance impact.
  • Change Advisory Board (CAB): Reviews and approves medium- and high-risk changes.
  • Chief Information Officer (CIO): Approves high-risk and emergency changes.

Change Management Procedure

1. Request for Change (RFC) Submission

The requestor submits an RFC in Freshservice.

The RFC must include:

  • Business justification
  • Risk and impact assessment
  • Testing plan
  • Backout plan
  • Proposed implementation window
2. Change Classification

The Change Manager classifies the change as one of the following:

  • Standard
  • Normal
  • Emergency
3. Risk and Security Review

Information Security reviews changes that impact restricted or regulated data, identity management, access controls, or network security.

All findings are documented in the RFC.

4. Approval
  • Standard changes follow pre-approved documentation.
  • Normal changes require CAB approval.
  • High-risk changes require CIO approval.
  • Emergency changes must complete a PIR within 72 hours.
5. Implementation
  • The Change Implementer executes the change according to the approved plan.
  • Real-time monitoring is required during deployment.
  • Any deviation from the plan must be reported to the Change Manager.
6. Post-Implementation Review (PIR)
  • PIRs are required for moderate- and high-risk changes.
  • Outcomes, issues, and lessons learned are documented.
  • PIR records are stored in Scrut.io.
  • [Link needed] KU IT 02 – Change Management Policy
  • Configuration Management Policy
  • Incident Response Plan

NIST Cybersecurity Framework (CSF) 2.0 Mapping

  • Identify: ID.RA
  • Protect: PR.IP
  • Detect: DE.CM
  • Respond: RS.MI

Metrics and Key Performance Indicators

  • Percentage of changes with completed RFCs
  • Change success rate
  • Number of emergency changes
  • PIR completion rate

Required Records and Storage Locations

  • RFCs: Freshservice
  • PIRs: Scrut.io

Revision History

  • Version 1.0: Initial operational release

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.