TechKnowSurge
ISC2 CISSP 7.3 ISC2 CISSP 7.9 CompTIA Security+ 1.3 NIST 800-53 CM-3
VideoSecurityFree

Configuration vs Change Management

Configuration management and change management are related but distinct processes for handling modifications within an IT environment. Understanding the difference between the two is essential for managing organizational and system-level changes effectively.

Complete this video to capture a CTF flag worth 1 point.

About this video

Configuration management and change management are two distinct but heavily overlapping processes used to govern modifications within an IT environment. Despite frequent confusion between the terms, each addresses a different scope of control and follows its own formal methodology. Recognizing where they diverge — and where they intersect — is foundational knowledge for IT and cybersecurity professionals working in structured operational environments. Configuration management centers on the settings and states of systems, software, and hardware. It involves establishing baseline configurations, maintaining version control so that the history and current state of any system are always known, implementing a change control process to update configurations in a controlled manner, and conducting testing and audits to verify integrity. The goal is to ensure that every configuration change is deliberate, documented, and reversible. Change management operates at a broader organizational level, governing how any significant change — such as deploying new software or modifying infrastructure — moves through a defined lifecycle. That lifecycle typically includes a formal change request, a planning phase, evaluation, implementation, monitoring, and closure. The process applies regardless of whether the change involves configurations specifically or other operational modifications. The overlap between the two disciplines is substantial enough that the boundaries are routinely debated: change management can be viewed as a component of configuration management, and every organizational change can equally be described as a change to configuration. In most practical contexts, the two are treated as a unified body of practice under the broader label of change management, with configuration management principles applied wherever system states and settings are directly involved.

What you'll learn

What's covered

Config vs Change Management

Aligned to

ISC2 CISSP
7.3 Perform Configuration Management (CM)
7.9 Understand and participate in change management processes
CompTIA Security+
1.3 Explain the importance of change management processes and the impact to security.
NIST 800-53
CM-3 Configuration Change Control

Key terms

Configuration Management
The process of tracking and controlling changes to hardware, software, and documentation throughout a system's lifecycle.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
Change Management
A structured process for requesting, reviewing, approving, and documenting changes to IT systems or organizational procedures. Change management reduces security risk by ensuring modifications are tested and authorized before deployment.
Change Control
The subprocess within configuration or change management that governs how changes are reviewed, approved, and implemented in a controlled manner.
Versioning
A storage feature that tracks incremental changes to a file over time, recording each revision so that prior versions can be viewed or restored without maintaining separate full copies.

Topics

Configuration Management Change Management It Operations It Governance Change Control

Transcript

There is a difference between configuration management and change management.

There is quite a bit of overlap between these two terms, configuration management and change management, and I can tell you there is a lot of confusion around what these two terms mean. They are considered two separate processes, two separate approaches to managing changes within your organization. One has to do with configurations, obviously, and the other one has to do with just making changes in general. So what we're going to do is attempt to break apart these two terms and really understand what they're talking about.

Configuration Management

Just like it sounds, configuration management has to do with configuration, and this can apply to projects, it can apply to hardware, it can apply to motors, it could apply to projects, it could apply to a lot of different aspects. But what we're going to do is apply it to software, because it's the easiest for us to understand. If we are configuring software, we have a bunch of settings on that software and we are changing those settings to this software, and so this is a perfect example of configuration. How do we manage the change, and how do we manage these configurations on our devices and in our software?

So what this process might look like is that we start creating baseline configurations. We start capturing what our configurations are for this software. Then what we do is we decide that we want to create some sort of versioning with this, so that when we make changes we can address what version we're on, and we can address what is the best version for us, or where are we, where have we been and where are we going — we can address those types of questions. Then we get into the change control process: how do we implement changes to configurations in a controlled way, and make sure that versioning is happening, and make sure that our baselines are getting updated, and what that process looks like. And then how do we go through testing those configurations to make sure that they're correct, and then also maybe some sort of audit process to make sure that everything is functioning well.

Change Management

The change management process is concerned with how we make changes to the organization. Maybe we make changes to software that we're rolling out. Maybe we have a server and we're rolling out new software on it. We're not exactly configuring it in that case; in this case we're setting up all new software. So what we need to do is we need to go through a process here which starts out with a change request, goes through a planning phase, an evaluation, an implementation phase, monitoring, and change closure. So there's this process that we do to make changes.

Where the Confusion Comes In

Now, where the confusion comes in is that part of configuration management has a change management process. Well, that sounds like change management is within configuration management, and a lot of people have argued that point, that change management is a part of configuration management. And then also I would say that any change you're making is really a change to configuration, so configurations is a part of change management.

So really I feel like the two are really interrelated, and that's why we're going to actually treat them as being the same thing. Throughout this module we're just going to talk about change management. I'm going to refer to it as change management, because most of what we're going to talk about really is change management, and we're not going to get too involved into the configuration management side of it. But the biggest thing is I just want you to understand that there is a difference between these two terms. We're mainly going to talk about change management. There is a slight difference with configuration management, but we'll talk about some aspects of configuration management as we go.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →