1
00:00:00,000 --> 00:00:00,900
In this lesson,

2
00:00:00,900 --> 00:00:03,270
we're going to discuss documenting changes.

3
00:00:03,270 --> 00:00:05,580
Now, documenting our changes is one of the cornerstones

4
00:00:05,580 --> 00:00:07,920
of an effective change management process.

5
00:00:07,920 --> 00:00:09,930
When we document our changes, we're not focused

6
00:00:09,930 --> 00:00:12,030
on just introducing a change into our environment,

7
00:00:12,030 --> 00:00:14,220
but we're also going to be focused on creating a clear record

8
00:00:14,220 --> 00:00:17,220
of what was done, when it was done, and why it was done,

9
00:00:17,220 --> 00:00:18,840
to ensure that we have both accountability

10
00:00:18,840 --> 00:00:21,150
and a roadmap for our future reference.

11
00:00:21,150 --> 00:00:23,040
Now, when it comes to documenting changes,

12
00:00:23,040 --> 00:00:24,090
we're going to be looking to ensure

13
00:00:24,090 --> 00:00:26,160
that version control is actually happening,

14
00:00:26,160 --> 00:00:28,590
that proper documentation updates are being performed,

15
00:00:28,590 --> 00:00:30,660
and that maintenance of various associated records

16
00:00:30,660 --> 00:00:33,030
is being completed as needed.

17
00:00:33,030 --> 00:00:35,070
Now, first, we have version controls.

18
00:00:35,070 --> 00:00:36,180
Each change we implement

19
00:00:36,180 --> 00:00:37,890
can carry with it numerous other changes,

20
00:00:37,890 --> 00:00:40,230
or impacts on your systems and networks.

21
00:00:40,230 --> 00:00:42,420
Version control is the safety net that ensures

22
00:00:42,420 --> 00:00:44,700
our changes do not create more chaos.

23
00:00:44,700 --> 00:00:46,800
Every document, software, and other files,

24
00:00:46,800 --> 00:00:48,360
should use version control

25
00:00:48,360 --> 00:00:50,910
to prevent us from losing sight of the big picture.

26
00:00:50,910 --> 00:00:52,920
Version control is basically just a system

27
00:00:52,920 --> 00:00:55,740
that tracks and manages changes to our documents, software,

28
00:00:55,740 --> 00:00:57,390
and other collections of information

29
00:00:57,390 --> 00:00:59,520
to allow multiple users to work collaboratively

30
00:00:59,520 --> 00:01:02,640
and revert back to a previous version whenever it's needed.

31
00:01:02,640 --> 00:01:04,650
Now, by maintaining different versions of documents,

32
00:01:04,650 --> 00:01:06,180
software, and other files,

33
00:01:06,180 --> 00:01:07,920
cybersecurity professionals like us

34
00:01:07,920 --> 00:01:10,080
can track the evolution of a given project

35
00:01:10,080 --> 00:01:11,760
and its associated changes.

36
00:01:11,760 --> 00:01:12,840
If an error occurs

37
00:01:12,840 --> 00:01:15,480
or implementing the rollback plan becomes necessary,

38
00:01:15,480 --> 00:01:17,040
version control allows our teams

39
00:01:17,040 --> 00:01:19,290
to revert to a previous more stable version

40
00:01:19,290 --> 00:01:20,760
of a given piece of software,

41
00:01:20,760 --> 00:01:23,460
system configuration, or network architecture.

42
00:01:23,460 --> 00:01:24,870
Our goal with version control

43
00:01:24,870 --> 00:01:27,840
is not to simply preserve the past iterations or history,

44
00:01:27,840 --> 00:01:29,610
but it gives us a centralized place

45
00:01:29,610 --> 00:01:31,380
where we can help ensure the continuity

46
00:01:31,380 --> 00:01:34,350
and stability of our environment over time.

47
00:01:34,350 --> 00:01:37,200
Second, we have the need for proper documentation.

48
00:01:37,200 --> 00:01:38,910
Now, whenever a change is being implemented,

49
00:01:38,910 --> 00:01:41,520
its accompanying documentation should also be updated

50
00:01:41,520 --> 00:01:44,010
to reflect the implementation of that change.

51
00:01:44,010 --> 00:01:45,270
Regardless of whether we're changing

52
00:01:45,270 --> 00:01:46,710
a minor configuration setting,

53
00:01:46,710 --> 00:01:48,420
or we're performing a major overhaul

54
00:01:48,420 --> 00:01:49,920
of our network infrastructure,

55
00:01:49,920 --> 00:01:52,620
every change needs to be properly documented and recorded

56
00:01:52,620 --> 00:01:53,880
by updating our diagrams,

57
00:01:53,880 --> 00:01:55,770
revising our policies and procedures,

58
00:01:55,770 --> 00:01:56,940
and updating change requests

59
00:01:56,940 --> 00:01:59,070
at any associated trouble tickets.

60
00:01:59,070 --> 00:02:01,260
Updating our diagrams is an important step

61
00:02:01,260 --> 00:02:02,730
because these diagrams provide us

62
00:02:02,730 --> 00:02:04,230
with a visual representation,

63
00:02:04,230 --> 00:02:06,120
like a flow chart or network diagram

64
00:02:06,120 --> 00:02:07,500
that provides us with a snapshot

65
00:02:07,500 --> 00:02:09,300
of our system's architecture.

66
00:02:09,300 --> 00:02:10,770
After any change is implemented,

67
00:02:10,770 --> 00:02:13,680
you and your team must take the time to update your diagrams

68
00:02:13,680 --> 00:02:15,270
to ensure they still accurately reflect

69
00:02:15,270 --> 00:02:17,250
the current state of your systems.

70
00:02:17,250 --> 00:02:19,140
Many people simply ignore this step

71
00:02:19,140 --> 00:02:20,280
because they think they're going to remember

72
00:02:20,280 --> 00:02:21,750
all these changes in their head,

73
00:02:21,750 --> 00:02:23,190
but I can tell you from experience,

74
00:02:23,190 --> 00:02:25,410
this is a recipe for disaster.

75
00:02:25,410 --> 00:02:27,450
Remember, this isn't just a small home network

76
00:02:27,450 --> 00:02:28,620
that you're going to be working on,

77
00:02:28,620 --> 00:02:30,720
it could be a network that spans across your city,

78
00:02:30,720 --> 00:02:33,570
your state, your country, or even across the world.

79
00:02:33,570 --> 00:02:35,310
To run networks on that scale,

80
00:02:35,310 --> 00:02:36,930
you're going to be working as part of a team,

81
00:02:36,930 --> 00:02:39,150
and so if something isn't properly documented,

82
00:02:39,150 --> 00:02:40,290
then nobody else on the team

83
00:02:40,290 --> 00:02:41,940
will know what changes you've implemented,

84
00:02:41,940 --> 00:02:43,830
and this can lead to a lot of misunderstandings

85
00:02:43,830 --> 00:02:45,630
and misconfigurations.

86
00:02:45,630 --> 00:02:47,220
After you implement your changes,

87
00:02:47,220 --> 00:02:48,750
you should then stop and ask yourself,

88
00:02:48,750 --> 00:02:50,250
did everything go perfectly?

89
00:02:50,250 --> 00:02:51,720
What could we have done better?

90
00:02:51,720 --> 00:02:52,920
This is an important step

91
00:02:52,920 --> 00:02:55,230
because not all changes are going to occur smoothly

92
00:02:55,230 --> 00:02:58,050
and without incident, so if there's any issues,

93
00:02:58,050 --> 00:02:59,580
you may need to go back and revise

94
00:02:59,580 --> 00:03:01,320
or update your policies and procedures

95
00:03:01,320 --> 00:03:03,000
to account for those issues.

96
00:03:03,000 --> 00:03:05,400
Whenever you find an issue in your change implementation,

97
00:03:05,400 --> 00:03:06,960
it is important that you don't just rectify

98
00:03:06,960 --> 00:03:09,270
the immediate issue, but also take some time

99
00:03:09,270 --> 00:03:10,260
to go back and figure out

100
00:03:10,260 --> 00:03:13,020
how you can revise the associated policies or procedures

101
00:03:13,020 --> 00:03:14,880
to prevent the same kind of issue from happening

102
00:03:14,880 --> 00:03:15,930
in the future.

103
00:03:15,930 --> 00:03:17,430
This form of continuous improvement

104
00:03:17,430 --> 00:03:19,440
relies on the iterative process improvement

105
00:03:19,440 --> 00:03:22,110
that is going to ensure your past mistakes remain in the past,

106
00:03:22,110 --> 00:03:23,820
and that your future changes are smoother

107
00:03:23,820 --> 00:03:26,010
and easier to implement moving forward.

108
00:03:26,010 --> 00:03:28,200
Now, once your change is successfully implemented,

109
00:03:28,200 --> 00:03:30,360
the associated change request or trouble ticket

110
00:03:30,360 --> 00:03:32,940
should also be updated to reflect the successful completion

111
00:03:32,940 --> 00:03:34,500
of that proposed change.

112
00:03:34,500 --> 00:03:36,480
This is not just a bureaucratic step though,

113
00:03:36,480 --> 00:03:37,770
because it's actually going to provide you with a way

114
00:03:37,770 --> 00:03:40,260
to create a clear timeline of the change actions

115
00:03:40,260 --> 00:03:41,730
and to ensure that all of your stakeholders

116
00:03:41,730 --> 00:03:43,290
are being informed of the change,

117
00:03:43,290 --> 00:03:45,030
and that there's a record of the change history

118
00:03:45,030 --> 00:03:46,440
for future reference.

119
00:03:46,440 --> 00:03:48,300
So remember, documenting changes

120
00:03:48,300 --> 00:03:50,400
is more than just an administrative task,

121
00:03:50,400 --> 00:03:53,070
it's a vital component of effective change management.

122
00:03:53,070 --> 00:03:54,780
To effectively document our changes,

123
00:03:54,780 --> 00:03:56,970
we must ensure that version control is occurring,

124
00:03:56,970 --> 00:03:59,250
proper documentation updates are being performed,

125
00:03:59,250 --> 00:04:01,200
and the maintenance of various associated records

126
00:04:01,200 --> 00:04:03,210
is being completed to ensure clarity

127
00:04:03,210 --> 00:04:05,700
and accountability of our change actions.

128
00:04:05,700 --> 00:04:06,690
In our modern systems

129
00:04:06,690 --> 00:04:08,610
that rely on massive amounts of interconnections

130
00:04:08,610 --> 00:04:10,770
through partnerships and the use of APIs,

131
00:04:10,770 --> 00:04:12,900
the proper documentation is going to allow us

132
00:04:12,900 --> 00:04:15,150
to be able to be guided as cybersecurity professionals

133
00:04:15,150 --> 00:04:16,769
through the intricate maze of systems,

134
00:04:16,769 --> 00:04:18,480
applications, and configurations

135
00:04:18,480 --> 00:04:20,010
that we use on a daily basis

136
00:04:20,010 --> 00:04:22,440
so that every change, no matter how minor it is,

137
00:04:22,440 --> 00:04:24,360
will be clearly and precisely implemented

138
00:04:24,360 --> 00:04:26,110
within our organization's networks.

