Question:
"1. Shall the procedure for handling of emergency changes like the above be explicitly written or documented?
2. As long as each related entities understand the residual risk and accept the risk, can we just apply the above procedure by default?"
My Answer:
1) I think that the emergency change management policies, standards(if exist), and procedures must be documented and approved by the necessary stakeholders. And then, the procedures should be clearly communicated to all the parties so, the staff and the emergency change initiator will have a clear idea what to do in case of emergency. The term "emergency" should be defined very well to avoid any confusion down the road. The emergency change management policies, standards, and procedures should be written in a plain language so everyone can understand them and the document should contain some sort of revision history section. The document should be reviewed at a specific time intervals to ensure that the procedures are still valid, effective and efficient. I agree with Navi that the compliance is also important part of the process. Any deviations from the established policies and procedures should be carefully investigated. Some investigation results might be used as a feedback during the review of the policies and procedures. The statistics should be collected for each emergency change category (e.g., networks, servers, workstations, databases etc.) and any unexpected spikes (in terms of number of emergency changes) for each category could very well be a good indicator of a larger problem.
2) I would be very cautious about the assumption of the risk acceptance. Each emergency situation is usually unique. The emergency trigger should be carefully reviewed and the proposed change should be approved by at least another person. The communication is also very critical for emergency changes to keep all other stakeholders in the loop.
No comments:
Post a Comment