ISO 18788 - Clause 10.2.2 - SOMS Change management
ISO 18788:2015 Clause 10.2.2 addresses the requirement for Change Management within the Security Operations Management System (SOMS). Change management is a critical aspect of maintaining the effectiveness and integrity of the security operations. Here's an explanation of the key elements of this clause:
Clause 10.2.2 - SOMS Change Management:
1. Change Identification: The organization should have a process in place to identify and recognize changes that may impact the security operations management system. This includes changes in policies, procedures, personnel, equipment, or any other relevant factors.
2. Impact Assessment: When a change is identified, the organization should conduct an impact assessment. This involves evaluating how the change might affect the security operations, including potential risks, vulnerabilities, and consequences.
3. Change Authorization: Changes to the SOMS should not be implemented without proper authorization. There should be a formal process for obtaining approval for proposed changes. This typically involves assessing whether the benefits of the change outweigh the risks.
4. Documentation: All changes, along with their impact assessments and authorizations, should be documented systematically. This documentation provides a clear record of changes made to the SOMS and the rationale behind those changes.
5. Communication: Once a change is authorized, there should be a communication plan in place to inform relevant stakeholders about the change. This ensures that everyone is aware of and prepared for the change.
6. Testing and Validation: In some cases, changes may need to be tested and validated before full implementation. This is especially important for changes that could affect security operations or the integrity of the SOMS.
7. Monitoring and Review: After a change is implemented, it should be monitored and reviewed to ensure that it has the intended effect and does not introduce unexpected risks or vulnerabilities.
8. Continuous Improvement: The organization should use the information gathered from change management processes to drive continuous improvement of the SOMS. This includes learning from past changes to make future changes more effective and efficient.
In summary, Clause 10.2.2 of ISO 18788 emphasizes the importance of a structured and systematic approach to managing changes within the Security Operations Management System. This helps organizations maintain security, identify and mitigate risks, and continuously improve their security operations.
Please note that specific procedures and documentation related to change management should be developed and implemented in accordance with the organization's needs and the requirements of ISO 18788.