# Change and Patch Management Procedure | Document information | Value | |-----------------------|------| | Document type | Procedure instruction (VA-04) | | Scope | {{ISMS_SCOPE}} | | Organisation | {{ORG_NAME}} | | Process owner | {{ROLE_IT_LEAD}} | | Approved by | {{ROLE_ISB}} | | Version | {{DOC_VERSION}} | | Date | {{DOC_DATE}} | | Status | {{DOC_STATUS}} | ## 1. Purpose This procedure governs planned changes to IT systems as well as the risk-oriented installation of patches. It operationalises the associated policy ({{LINK:R10}}). ## 2. Scope Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}). ## 3. Trigger Need for change, available patch or identified vulnerability (VA-06). ## 4. Inputs - Change/patch request - Risk assessment - Patch SLA (BL-OPS-01) ## 5. Process 1. Request & classify the change (standard/normal/emergency) in {{TOOL_TICKET}}. 2. Risk/impact assessment incl. rollback plan. 3. Approval by CAB/responsible role. 4. Test in a separate environment (BL-OPS, R10). 5. Implementation in production in accordance with the patch SLA (critical {{PATCH_SLA_CRIT}}). 6. Verification & documentation of the result in {{TOOL_TICKET}}. ## 6. RACI | # | Step | R (Execution) | A (Accountable) | C (Consulted) | I (Informed) | |---|---------|------------------|------------------|-----------------|----------------| | 1 | Request & classify the change | Requester | {{ROLE_IT_LEAD}} | - | - | | 2 | Risk/impact assessment incl. rollback | {{ROLE_IT_LEAD}} | {{ROLE_IT_LEAD}} | {{ROLE_ISB}} | - | | 3 | Approval by CAB/responsible role | {{ROLE_IT_LEAD}} | {{ROLE_IT_LEAD}} | {{ROLE_ISB}} | - | | 4 | Test in a separate environment | {{ROLE_IT_LEAD}} | {{ROLE_IT_LEAD}} | - | - | | 5 | Implementation in production per patch SLA | {{ROLE_IT_LEAD}} | {{ROLE_IT_LEAD}} | - | Affected parties | | 6 | Verification & documentation of the result | {{ROLE_IT_LEAD}} | {{ROLE_ISB}} | - | - | ## 7. Result & evidence Documented, approved and verified change/patch in {{TOOL_TICKET}}. Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}). ## 8. Key performance indicators (KPI) - Patch compliance per criticality - Share of successful changes (without rollback) - Lead time of critical patches ## 9. Related documents - Associated policy: {{LINK:R10}} - {{LINK:VA-06}} - Technical security baseline: {{LINK:BASELINE}} - ISA mapping matrix: {{LINK:ISA_MAPPING}}