TechKnowSurge
CompTIA Security+ 1.3 ISC2 CISSP 7.9 NIST 800-53 CM-3 NIST NICE K1287 NIST NICE K1294
VideoSecurityFree

Evaluation and Implementation

Evaluating and implementing a change management plan requires structured review against policies, procedures, and communication standards before any change goes live. A Change Advisory Board provides independent oversight and grants final approval to ensure nothing is overlooked.

Complete this video to capture a CTF flag worth 1 point.

About this video

After a change management plan is drafted, the evaluation phase begins — and it mirrors the planning phase closely in scope. Reviewers examine whether documented procedures are accurate, whether the proposed changes align with organizational and security policies, and whether communication has reached all relevant stakeholders at the appropriate times. This thoroughness is essential because any gap in the plan at this stage can create risk during implementation. Self-evaluation has a well-known limitation: the person who created the plan is likely to overlook the same issues they missed while creating it. This is why the Change Advisory Board, or CAB, plays a central role in the process. The CAB is a cross-functional team that independently reviews the change, assesses it against all key considerations, and provides the final authorization to proceed or halt. Their approval serves as the formal gate between evaluation and execution. Once the CAB grants approval, implementation is relatively straightforward. Because the planning and evaluation phases have already accounted for procedures, risks, and stakeholder alignment, execution becomes a matter of working through the documented steps in order and confirming each one as complete. The preparation done earlier is what makes the implementation phase manageable and controlled.

What you'll learn

What's covered

Evaluate & Implement Plan

Aligned to

CompTIA Security+
1.3 Explain the importance of change management processes and the impact to security.
ISC2 CISSP
7.9 Understand and participate in change management processes
NIST 800-53
CM-3 Configuration Change Control
NIST NICE
K1287 Knowledge of change management processes
K1294 Knowledge of change management policies and procedures

Key terms

Change Advisory Board
CAB
A group that reviews and evaluates proposed changes to ensure they are appropriate for the environment and comply with organizational policies and procedures.
Configuration Management
The process of tracking and controlling changes to hardware, software, and documentation throughout a system's lifecycle.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.

Topics

Change Management Change Advisory Board It Governance Change Control Itil

Transcript

Evaluating the Plan

Once we've created a plan, it's time to have it evaluated. Really, that planning phase is going to look very similar to the evaluation phase, in the sense that we are going to evaluate everything that we talked about in the planning phase.

As we're doing this, we're also going to take a look at these procedures and what those procedures look like, and make sure the procedures are correct. We're going to measure them up against our policies and make sure that the plan meets our policies and the changes meet our policies, specifically our security policies. We're going to take a look at the communication throughout this process here and make sure that everybody that needs to be communicated to is being communicated to at the proper times.

The Change Advisory Board

Have you ever proofread your own work, or gone back and looked at what you've created? A lot of times we can identify issues with what we created, and that is fine, and we can do the same thing with this change management process. But I can tell you, you will probably overlook a lot of things if you're evaluating a plan that you've created yourself.

That's where something like a change advisory board, or a CAB, comes into place. This is a team of people that are going to look at changes, look at the plan, and evaluate the plan across all those considerations to make sure that nothing is getting overlooked. What they do is give the final approval on whether this change is accepted or not.

Implementation

Then, of course, the next phase is the implementation. At this point we've already thought through everything and have the procedures all written out, so at this point it's just a matter of going through and checking things off.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →