1
00:00:06,570 --> 00:00:08,640
- Now in this lesson 3.2,

2
00:00:08,640 --> 00:00:10,800
we're gonna focus in on change management.

3
00:00:10,800 --> 00:00:13,290
In 3.1 we talked about
configuration management,

4
00:00:13,290 --> 00:00:16,590
and how we could only change configuration

5
00:00:16,590 --> 00:00:18,360
through the change control process.

6
00:00:18,360 --> 00:00:21,150
So let's take a look at
the change control process

7
00:00:21,150 --> 00:00:23,433
and change management in this lesson.

8
00:00:24,870 --> 00:00:26,850
Now, the objective of change management

9
00:00:26,850 --> 00:00:30,690
is to drastically minimize the
risk and impact that a change

10
00:00:30,690 --> 00:00:33,360
can have on a business operation.

11
00:00:33,360 --> 00:00:35,100
Now the change control process

12
00:00:35,100 --> 00:00:39,180
establishes standard procedures
for managing change requests

13
00:00:39,180 --> 00:00:44,177
in a secure, in a timely,
and in an efficient manner.

14
00:00:46,290 --> 00:00:48,870
So change management
applies a formal process

15
00:00:48,870 --> 00:00:51,000
to accomplish change.

16
00:00:51,000 --> 00:00:54,630
And there are a number
of areas or components

17
00:00:54,630 --> 00:00:56,040
that we need to really think about

18
00:00:56,040 --> 00:00:58,740
and take into consideration
when we think about

19
00:00:58,740 --> 00:01:00,870
any change that needs to take place.

20
00:01:00,870 --> 00:01:04,980
Prioritization, impact
analysis, testing the change,

21
00:01:04,980 --> 00:01:09,270
rollback strategies,
accountability, documentation.

22
00:01:09,270 --> 00:01:12,153
automation and implementation.

23
00:01:13,200 --> 00:01:16,980
There may be multiple changes
that are being proposed.

24
00:01:16,980 --> 00:01:20,070
It could be in a configuration
management baseline,

25
00:01:20,070 --> 00:01:22,053
or it could just be in a process,

26
00:01:22,053 --> 00:01:24,240
lots of it could be in code,

27
00:01:24,240 --> 00:01:27,270
lots of different changes could
happen in your organization.

28
00:01:27,270 --> 00:01:29,460
But they're not all equal, right?

29
00:01:29,460 --> 00:01:32,790
And so part of a change control committee,

30
00:01:32,790 --> 00:01:36,030
or a change control that
groups responsibility,

31
00:01:36,030 --> 00:01:38,580
is to say, okay, let's
prioritize these changes,

32
00:01:38,580 --> 00:01:42,150
because we have finite resources
to really evaluate them.

33
00:01:42,150 --> 00:01:43,920
So we're going to do prioritization,

34
00:01:43,920 --> 00:01:46,593
of course, in alignment
with business needs.

35
00:01:47,730 --> 00:01:49,620
We're going to do impact analysis.

36
00:01:49,620 --> 00:01:51,150
So whenever a change is proposed,

37
00:01:51,150 --> 00:01:55,309
we wanna evaluate the
risks and the benefits.

38
00:01:55,309 --> 00:01:57,720
We may wanna do some testing.

39
00:01:57,720 --> 00:02:00,270
Regression testing is testing that's done

40
00:02:00,270 --> 00:02:02,970
whenever there's been a change
made in code or software,

41
00:02:02,970 --> 00:02:05,460
just to make sure the
system works okay still,

42
00:02:05,460 --> 00:02:08,010
but also any other systems that it has to

43
00:02:08,010 --> 00:02:10,650
interoperate work with also works.

44
00:02:10,650 --> 00:02:13,560
So we want regression and
interoperability testing

45
00:02:13,560 --> 00:02:16,230
if there's a change
being made or proposed.

46
00:02:16,230 --> 00:02:17,640
We want rollback strategies.

47
00:02:17,640 --> 00:02:20,910
So what if we've done all
our testing and our analysis,

48
00:02:20,910 --> 00:02:22,650
and we say, okay, yeah,
we're ready to roll.

49
00:02:22,650 --> 00:02:25,590
And then we actually implement it,

50
00:02:25,590 --> 00:02:28,590
and it turns out like, uh-oh,
something really went wrong.

51
00:02:28,590 --> 00:02:29,520
We didn't expect this,

52
00:02:29,520 --> 00:02:31,650
it didn't happen the
way we thought it would,

53
00:02:31,650 --> 00:02:33,360
it's not always going to.

54
00:02:33,360 --> 00:02:35,370
So we wanna have rollback
strategies, right?

55
00:02:35,370 --> 00:02:37,500
That's recovery to a previous state.

56
00:02:37,500 --> 00:02:39,900
Another way to think about
it is a backout plan.

57
00:02:41,010 --> 00:02:42,720
We wanna have accountability, right?

58
00:02:42,720 --> 00:02:44,310
Changes should be authorized.

59
00:02:44,310 --> 00:02:46,080
Now they'll be authorized
at different levels

60
00:02:46,080 --> 00:02:49,830
of an organization depending
upon what the change is,

61
00:02:49,830 --> 00:02:51,690
and also depending on
what the level of risk

62
00:02:51,690 --> 00:02:52,953
that might be introduced.

63
00:02:53,970 --> 00:02:56,340
We always wanna document
any changes we made,

64
00:02:56,340 --> 00:02:59,283
including diagrams and procedures.

65
00:03:00,900 --> 00:03:02,640
If we are using automation,

66
00:03:02,640 --> 00:03:04,680
we wanna make sure that those baseline

67
00:03:04,680 --> 00:03:07,833
configuration scripts
and code are updated.

68
00:03:09,000 --> 00:03:11,070
And then when we go to implement a change,

69
00:03:11,070 --> 00:03:13,950
we wanna make sure that
the scheduling considers,

70
00:03:13,950 --> 00:03:14,880
a maintenance windows,

71
00:03:14,880 --> 00:03:17,040
perhaps already scheduled
maintenance windows

72
00:03:17,040 --> 00:03:18,540
or acceptable downtime.

73
00:03:18,540 --> 00:03:20,430
And if it's an emergency change,

74
00:03:20,430 --> 00:03:22,440
really looking at when can this be done?

75
00:03:22,440 --> 00:03:25,923
Hopefully at a time when there's
the least amount of impact.

76
00:03:29,250 --> 00:03:30,630
Now the ITIL, let's see,

77
00:03:30,630 --> 00:03:33,390
Information Technology
Infrastructure Library,

78
00:03:33,390 --> 00:03:36,540
actually defines four
different types of changes.

79
00:03:36,540 --> 00:03:40,860
A standard change, a normal
change, a major change,

80
00:03:40,860 --> 00:03:43,350
and an emergency change.

81
00:03:43,350 --> 00:03:46,200
A standard change is one
that occurs frequency.

82
00:03:46,200 --> 00:03:48,042
It's generally gonna be low risk,

83
00:03:48,042 --> 00:03:51,563
and or it has pre-established procedures

84
00:03:51,563 --> 00:03:54,510
with documented tasks for completion.

85
00:03:54,510 --> 00:03:55,620
So for example,

86
00:03:55,620 --> 00:03:58,500
we're gonna be talking
about patch management.

87
00:03:58,500 --> 00:04:02,250
Patch management has a set of procedures.

88
00:04:02,250 --> 00:04:04,344
Now patch management
does introduce a change.

89
00:04:04,344 --> 00:04:06,480
But for most organizations,

90
00:04:06,480 --> 00:04:08,970
because patch management
is its own program,

91
00:04:08,970 --> 00:04:11,430
and it has its own steps
and its own procedures,

92
00:04:11,430 --> 00:04:13,984
and its own, yes, no, stop, go,

93
00:04:13,984 --> 00:04:16,170
it's considered a standard change

94
00:04:16,170 --> 00:04:17,430
and doesn't have to go through

95
00:04:17,430 --> 00:04:19,983
this additional change management process.

96
00:04:21,750 --> 00:04:24,390
A normal change is one
that's not standard,

97
00:04:24,390 --> 00:04:26,160
but it's not an emergency.

98
00:04:26,160 --> 00:04:27,120
And that can be approved

99
00:04:27,120 --> 00:04:29,910
by a change control board or committee.

100
00:04:29,910 --> 00:04:32,520
A major change is one
that may have significant

101
00:04:32,520 --> 00:04:35,130
financial implications and, or

102
00:04:35,130 --> 00:04:37,410
introduce a high level of risk.

103
00:04:37,410 --> 00:04:39,780
Now that kind of change generally requires

104
00:04:39,780 --> 00:04:42,360
multiple levels of management approval.

105
00:04:42,360 --> 00:04:44,130
And then an emergency change

106
00:04:44,130 --> 00:04:47,040
is one that must be
assessed and implemented

107
00:04:47,040 --> 00:04:48,210
without prior authorization,

108
00:04:48,210 --> 00:04:49,980
it hasn't gone through this process

109
00:04:49,980 --> 00:04:53,310
as quickly as possible to
resolve a major incident.

110
00:04:53,310 --> 00:04:55,320
But we wanna have a lot of guard rails

111
00:04:55,320 --> 00:04:57,180
around emergency changes,

112
00:04:57,180 --> 00:04:59,223
and they should be few and far between.

113
00:05:00,810 --> 00:05:04,198
So let's look at a normal
change control workflow.

114
00:05:04,198 --> 00:05:06,438
A change request is received,

115
00:05:06,438 --> 00:05:08,880
the change might be
tested for feasibility,

116
00:05:08,880 --> 00:05:12,090
is this even gonna work,
does this make sense?

117
00:05:12,090 --> 00:05:14,433
We'll identify some rollback options.

118
00:05:15,300 --> 00:05:20,190
We'll document changes,
we'll finalize authorization,

119
00:05:20,190 --> 00:05:23,370
we'll determine the
appropriate change window,

120
00:05:23,370 --> 00:05:24,663
and then we'll implement.

121
00:05:26,670 --> 00:05:27,870
We'll wanna verify

122
00:05:27,870 --> 00:05:30,393
that whatever change we
did is working correctly.

123
00:05:31,410 --> 00:05:34,470
We'll wanna update configuration
management baseline

124
00:05:34,470 --> 00:05:37,290
if this is something that has
a, it's a configuration item,

125
00:05:37,290 --> 00:05:40,080
and it has a configuration
management baseline.

126
00:05:40,080 --> 00:05:42,900
And then we're gonna wanna
close and archive the request.

127
00:05:42,900 --> 00:05:44,430
We don't wanna throw the request away,

128
00:05:44,430 --> 00:05:46,260
we don't wanna throw all
the documentation away.

129
00:05:46,260 --> 00:05:48,210
'Cause we always wanna be
able to have this version

130
00:05:48,210 --> 00:05:50,880
and record of, okay, why
did we make that change?

131
00:05:50,880 --> 00:05:51,750
Who approved it?

132
00:05:51,750 --> 00:05:52,590
Why did we do it?

133
00:05:52,590 --> 00:05:53,520
What was the impact?

134
00:05:53,520 --> 00:05:55,497
So we wanna close that request,

135
00:05:55,497 --> 00:05:57,597
but we wanna make sure that we archive it.

136
00:06:00,150 --> 00:06:03,150
So this is a great time
to introduce you to KPIs,

137
00:06:03,150 --> 00:06:06,150
because we can look at KPIs
in terms of change management,

138
00:06:06,150 --> 00:06:07,620
and we can look at KPIs in terms of

139
00:06:07,620 --> 00:06:09,090
lots of different processes.

140
00:06:09,090 --> 00:06:11,280
But this is a good one to look at with.

141
00:06:11,280 --> 00:06:13,920
A KPI is a key performance indicator.

142
00:06:13,920 --> 00:06:15,900
KPIs are a management tool,

143
00:06:15,900 --> 00:06:19,140
they are business metrics
used to measure performance

144
00:06:19,140 --> 00:06:22,053
in relation to strategic
goals and objectives.

145
00:06:23,040 --> 00:06:26,070
And so I wanted to give
you some examples of KPIs

146
00:06:26,070 --> 00:06:29,190
that are directly tied
to the change control

147
00:06:29,190 --> 00:06:30,780
and change management process.

148
00:06:30,780 --> 00:06:35,220
Successful changes, backlog
of changes, emergency changes.

149
00:06:35,220 --> 00:06:37,110
So a KPI for successful changes

150
00:06:37,110 --> 00:06:38,370
might be the number of changes

151
00:06:38,370 --> 00:06:40,590
that have been completed successfully,

152
00:06:40,590 --> 00:06:43,830
compared to the total
number of completed changes.

153
00:06:43,830 --> 00:06:46,470
The higher the percentage,
probably the better.

154
00:06:46,470 --> 00:06:49,170
Just the number of changes
completed on their own

155
00:06:49,170 --> 00:06:51,390
doesn't really tell me very much.

156
00:06:51,390 --> 00:06:53,580
But if you tell me how
many we've completed,

157
00:06:53,580 --> 00:06:56,460
compared to how many have
been requested in the queue,

158
00:06:56,460 --> 00:06:57,750
that gives me an idea

159
00:06:57,750 --> 00:06:59,900
of how effective and
efficient we're being.

160
00:07:01,320 --> 00:07:03,090
The next is a backlog of changes.

161
00:07:03,090 --> 00:07:06,570
And that's the number of changes
that are not yet completed.

162
00:07:06,570 --> 00:07:09,150
Now, in this case, this
is an absolute number,

163
00:07:09,150 --> 00:07:11,452
but what we're looking for here is trends.

164
00:07:11,452 --> 00:07:14,160
So it's an absolute number,
and what it's gonna be

165
00:07:14,160 --> 00:07:16,170
really depends on the
size of an organization,

166
00:07:16,170 --> 00:07:17,400
the larger the organization is,

167
00:07:17,400 --> 00:07:19,770
the more backlog of
changes you might have.

168
00:07:19,770 --> 00:07:22,320
But the key is it
shouldn't grow over time.

169
00:07:22,320 --> 00:07:23,760
If it keeps growing,

170
00:07:23,760 --> 00:07:25,950
we've got other issues that
we need to be looking at.

171
00:07:25,950 --> 00:07:28,080
Are we not staffed correctly?

172
00:07:28,080 --> 00:07:31,860
Do we have bad configurations
that are causing problems?

173
00:07:31,860 --> 00:07:33,903
Are we growing too fast?

174
00:07:34,860 --> 00:07:37,980
And then lastly, emergency
changes for a KPI,

175
00:07:37,980 --> 00:07:40,590
this would be the number of
completed emergency changes.

176
00:07:40,590 --> 00:07:42,600
Again, an absolute number,

177
00:07:42,600 --> 00:07:45,330
which would depend on the
size of the organization,

178
00:07:45,330 --> 00:07:47,520
but it should not trend upward.

179
00:07:47,520 --> 00:07:49,320
So how many emergency changes do we have?

180
00:07:49,320 --> 00:07:53,400
We never wanna see those
skyrocketing or trending upward.

181
00:07:53,400 --> 00:07:57,840
So three good examples of KPIs,
Key Performance Indicators

182
00:07:57,840 --> 00:08:01,230
that we can use in the
change management area.

183
00:08:01,230 --> 00:08:03,930
And that my friends, brings us
to a three-second challenge.

184
00:08:03,930 --> 00:08:05,010
You know how to do this.

185
00:08:05,010 --> 00:08:08,070
Five challenge questions,
three seconds each.

186
00:08:08,070 --> 00:08:08,910
I know you can do this,

187
00:08:08,910 --> 00:08:10,470
and I bet you're gonna
get these all right.

188
00:08:10,470 --> 00:08:11,703
Are you ready? Let's go.

189
00:08:12,990 --> 00:08:17,100
This ITIL term describes
changes that are required

190
00:08:17,100 --> 00:08:18,780
in the normal course of business,

191
00:08:18,780 --> 00:08:21,813
and have established
policies and procedures.

192
00:08:23,250 --> 00:08:26,013
One, two, three.

193
00:08:28,080 --> 00:08:29,580
That's gonna be a standard change.

194
00:08:29,580 --> 00:08:30,990
And I wasn't trying to trip you up

195
00:08:30,990 --> 00:08:32,906
by using the word normal in there.

196
00:08:32,906 --> 00:08:35,940
So don't sometimes think
you need to read too much

197
00:08:35,940 --> 00:08:37,380
into a question when you get it.

198
00:08:37,380 --> 00:08:39,390
I really wasn't trying
to either give you a hint

199
00:08:39,390 --> 00:08:41,130
or trip you up.

200
00:08:41,130 --> 00:08:43,130
So again, the answer is standard change.

201
00:08:44,010 --> 00:08:46,800
This change management KPI
tracks the number of changes

202
00:08:46,800 --> 00:08:48,243
that are not yet completed.

203
00:08:50,250 --> 00:08:52,443
One, two, three.

204
00:08:54,180 --> 00:08:55,380
That would be a backlog.

205
00:08:56,880 --> 00:08:57,870
Number three,

206
00:08:57,870 --> 00:09:00,810
this configuration management
element should be updated

207
00:09:00,810 --> 00:09:03,903
if the change occurs to all
current and future systems.

208
00:09:05,280 --> 00:09:07,050
One, two, three.

209
00:09:07,050 --> 00:09:08,973
Think back to our last lesson.

210
00:09:10,110 --> 00:09:11,823
That's a baseline configuration.

211
00:09:13,320 --> 00:09:15,870
Number four, this type of testing ensures

212
00:09:15,870 --> 00:09:18,690
an application still functions as expected

213
00:09:18,690 --> 00:09:22,053
after any code change
updates or improvements.

214
00:09:23,970 --> 00:09:26,490
I give you a hint, it
starts with the letter R.

215
00:09:26,490 --> 00:09:28,473
One, two, three.

216
00:09:30,180 --> 00:09:31,623
This is regression testing.

217
00:09:32,730 --> 00:09:34,590
And lastly, number five,

218
00:09:34,590 --> 00:09:37,380
this strategy may be
employed if there's a problem

219
00:09:37,380 --> 00:09:39,510
with the change implementation.

220
00:09:39,510 --> 00:09:42,723
So uh-oh, something's
gone wrong, what do I do?

221
00:09:43,710 --> 00:09:45,993
One, two, three.

222
00:09:47,220 --> 00:09:50,553
That's gonna be our rollback
strategy or our backup plan.

223
00:09:52,200 --> 00:09:54,480
All right, that brings us
to a security-in-action,

224
00:09:54,480 --> 00:09:56,460
so you can apply your knowledge.

225
00:09:56,460 --> 00:09:59,460
Our case study is about change management.

226
00:09:59,460 --> 00:10:01,410
The IT department is balking

227
00:10:01,410 --> 00:10:04,620
at having to follow change
management procedures.

228
00:10:04,620 --> 00:10:07,230
They contend that they
know what they're doing,

229
00:10:07,230 --> 00:10:10,980
and if something goes wrong,
they'll take care of it.

230
00:10:10,980 --> 00:10:12,780
So they're a little outta joint, right?

231
00:10:12,780 --> 00:10:13,980
It's like they're saying, hey,

232
00:10:13,980 --> 00:10:15,570
we don't need these change
management procedures.

233
00:10:15,570 --> 00:10:16,650
We know what we're doing,

234
00:10:16,650 --> 00:10:18,450
and if it turns out there's a problem,

235
00:10:18,450 --> 00:10:21,510
we'll fix it, we're
always the one to fix it.

236
00:10:21,510 --> 00:10:24,810
Well, you have been given
that unenviable task

237
00:10:24,810 --> 00:10:29,250
explaining to them why following
the process is important.

238
00:10:29,250 --> 00:10:32,340
So why the change management
process is important.

239
00:10:32,340 --> 00:10:35,910
So my question to you is, what
are your key talking points?

240
00:10:35,910 --> 00:10:37,230
What are you gonna tell them?

241
00:10:37,230 --> 00:10:40,030
Great time to put me on pause
and write down some notes.

242
00:10:41,910 --> 00:10:44,460
Well, here might be
your key talking points,

243
00:10:44,460 --> 00:10:46,860
that a consistent change
management program

244
00:10:46,860 --> 00:10:49,953
is really a value add
for both the organization

245
00:10:49,953 --> 00:10:52,740
and the individual.

246
00:10:52,740 --> 00:10:54,360
The process is gonna assure that

247
00:10:54,360 --> 00:10:56,700
changes are aligned with
business strategies,

248
00:10:56,700 --> 00:10:58,680
and that responses are prioritized,

249
00:10:58,680 --> 00:11:00,360
so we don't have business unit managers

250
00:11:00,360 --> 00:11:02,043
yelling at us all the time.

251
00:11:02,970 --> 00:11:06,810
Testing rollback strategies
and change windows

252
00:11:06,810 --> 00:11:10,050
are gonna reduce potential
disruption and downtime.

253
00:11:10,050 --> 00:11:13,230
And we all know how stressful and costly

254
00:11:13,230 --> 00:11:15,057
and just absolutely awful,

255
00:11:15,057 --> 00:11:19,110
whenever we've caused any kind
of disruption or downtime,

256
00:11:19,110 --> 00:11:20,403
how awful it is.

257
00:11:21,360 --> 00:11:24,810
And I would really stress
that overall change management

258
00:11:24,810 --> 00:11:27,870
really does contribute to a less stressful

259
00:11:27,870 --> 00:11:30,060
and a more productive environment.

260
00:11:30,060 --> 00:11:32,310
It's not about not
trusting their judgment,

261
00:11:32,310 --> 00:11:35,100
it's not about them not
being able to do their job.

262
00:11:35,100 --> 00:11:36,810
Matter of fact, what
we're really trying to do

263
00:11:36,810 --> 00:11:41,190
is lift a burden from them
by really putting this into

264
00:11:41,190 --> 00:11:43,890
a standardized process that you know,

265
00:11:43,890 --> 00:11:45,600
that they don't always have
to be making decisions,

266
00:11:45,600 --> 00:11:47,845
they don't always have
to be being reactive,

267
00:11:47,845 --> 00:11:51,990
and being have their
phones ringing off the hook

268
00:11:51,990 --> 00:11:53,220
by different business units,

269
00:11:53,220 --> 00:11:55,980
it is now a very organized process.

270
00:11:55,980 --> 00:11:57,000
And I think all in all,

271
00:11:57,000 --> 00:11:59,580
it will make a much better
working condition for them.

272
00:11:59,580 --> 00:12:02,580
And being able to explain
it and convince them,

273
00:12:02,580 --> 00:12:04,713
that my friends is security-in-action.

274
00:12:06,270 --> 00:12:08,820
There's your word cloud,
you know what to do.

275
00:12:08,820 --> 00:12:10,200
And when you're ready,

276
00:12:10,200 --> 00:12:12,390
we're gonna have another quiz deep drive,

277
00:12:12,390 --> 00:12:14,160
specifically for lesson three.

278
00:12:14,160 --> 00:12:15,260
So I'll see you there.
