System Change Policy
Purpose and Scope
This information security policy defines how changes to information systems are planned and implemented.
This policy applies to the entire information security program at Userflow (i.e. to all information and communications technology, as well as related documentation).
All employees, contractors, part-time and temporary workers, service providers, and those employed by others to perform work for Userflow, or who have been granted to Userflow’s information and communications technology, must comply with this policy.
This policy defines specific requirements to ensure that changes to systems and applications are properly planned, evaluated, reviewed, approved, communicated, implemented, documented, and reviewed, thereby ensuring the greatest probability of success. Where changes are not successful, this document provides mechanisms for conducting post-implementation review such that future mistakes and errors can be prevented.
Any changes to the security architecture or customer data handling of a system must be formally requested in writing to Userflow’s Information Security Manager (ISM), and approved by the ISM and the Chief Information Officer (CIO).
All change requests must be documented.
All change requests must be prioritized in terms of benefits, urgency, effort required, and potential impacts to Userflow’s operations.
All implemented changes must be communicated to relevant users.
Change management must be conducted according to the following procedure:
: plan the change, including the implementation design, scheduling, and implementation of a communications plan, testing plan, and roll-back plan.
: evaluate the change, including priority level of the service and risk that the proposed change introduces to the system; determine the change type and the specific step-by-step process to implement the change.
: review the change plan amongst the CIO, ISM, Engineering Lead, and, if applicable, Business Unit Manager.
: the CIO must approve the change plan.
: communicate the change to all users of the system.
: test and implement the change.
: record the change and any post-implementation issues.
: conduct a post-implementation review to determine how the change is impacting Userflow, either positively or negatively. Discuss and document any lessons learned.