TechKnowSurge
ISC2 CISSP 7.9 CompTIA Security+ 1.3 NIST CSF RC.RP-06 NIST 800-53 CM-3
VideoSecurityFree

Monitoring, Documentation, and Closure

After a change is implemented, IT teams must monitor the environment for adverse effects and complete all final documentation before officially closing out the change request. Proper closure ensures system configurations, updated procedures, and approval records are all captured and the originating ticket or request is formally resolved.

Complete this video to capture a CTF flag worth 1 point.

About this video

After a change is deployed to a production environment, monitoring is a critical phase that should not be skipped. Some problematic changes cause immediate failures, while others introduce issues that surface only after time has passed, making sustained observation necessary. The monitoring period confirms two things: that the intended change was applied successfully, and that no adverse effects have emerged as a result. Documentation is a thread that runs through the entire change management lifecycle, from the initial request and planning stages through approval and implementation. At closure, all of that documentation must be finalized. The Change Control document should be updated to reflect completed tasks, any procedures that were modified during the process need to be recorded, and updated system configurations must be captured so there is an accurate record of the current state of affected systems. The final action in the change closure process is returning to however the change was originally requested — whether that was a ticketing system or an email chain — and formally closing it out. That closure serves as the official record that the change has been implemented, monitored, and wrapped up according to the approved plan. Consistent, thorough documentation at every stage protects the organization and provides a clear audit trail for future reference.

What you'll learn

What's covered

Change Management Wrap-Up

Aligned to

ISC2 CISSP
7.9 Understand and participate in change management processes
CompTIA Security+
1.3 Explain the importance of change management processes and the impact to security.
NIST CSF
RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed.
NIST 800-53
CM-3 Configuration Change Control

Key terms

Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
Configuration Management
The process of tracking and controlling changes to hardware, software, and documentation throughout a system's lifecycle.
Change Request
A formal submission from a user, customer, or stakeholder initiating the process to make a change within an IT environment.
Change Control Document
A record that captures the details, approval, implementation steps, and final status of a change throughout the change management process.
Adverse Effects Monitoring
The observation of a system after a change is implemented to detect any unintended negative impacts on performance or availability.
Change Closure
The final step of the change management process in which documentation is finalized and the originating change request or ticket is officially closed.

Topics

Change Management Post Implementation Review Change Documentation Incident Monitoring Itil Change Request Closure It Operations

Transcript

Once we've implemented the change, there could be a monitoring period where we make sure that the change has been rolled out successfully. Then it's time to wrap up this process.

Monitoring

Once we've implemented the change, it's time to move on to monitoring. I've implemented bad changes before that instantly brought down the network. I've also implemented bad changes before that took a while before you saw their bad effects. Really, you're not quite sure when those are going to crop up sometimes.

So one thing we need to do is we need to do proper monitoring for a proper period of time. What we're looking for is, number one, did we make the change that we wanted to make, did it roll out successfully? And the other thing that we're looking for is, does it cause any adverse effects? So we're going to monitor it for that period of time after we've implemented it.

Documentation

During this whole process we've been documenting everything along the way. For instance, the change request that came in was documented — maybe it was through email, maybe it's a ticket in the system; there was some sort of documentation. We created a plan; that's a document that we created outlining everything. They got approved, so the documentation was approved. When we implemented it, maybe there's a check off and we went through the check off to make sure everything was done well — we've got documentation there. So we should be documenting things throughout this whole process.

There is a wrap-up that needs to happen here though. At the end here we need to finish up our documentation. So there's the change control document that we created, the plan that we had, and if there is anything on there that we need to update and say yes, we've done this and everything is rolled out, then we need to do that.

We need to document any procedures that we changed along the way, so make sure that's rolled into there, and so then we would have a record of that. We've changed the systems, the configurations of these systems, so we need to make sure that gets documented.

Closure

And once again, this could have been started all with a request that came in, maybe through a ticketing system or through email, so we need to respond back to that email or that ticketing system and close out the ticket. Usually that closing out the ticket is the last thing you do as part of this change.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →