San Francisco Chapter San Francisco Chapter
Introduction to Change Introduction to Change Management Management
Tuesday, September 23, 2008 Mark Lundin Steve Owyoung Partner Manager KPMG LLP, IT Advisory KPMG LLP, IT Advisory
Introduction to Change Introduction to Change Management - - PowerPoint PPT Presentation
San Francisco Chapter San Francisco Chapter Introduction to Change Introduction to Change Management Management Tuesday, September 23, 2008 Mark Lundin Steve Owyoung Partner Manager KPMG LLP, IT Advisory KPMG LLP, IT
San Francisco Chapter San Francisco Chapter
Tuesday, September 23, 2008 Mark Lundin Steve Owyoung Partner Manager KPMG LLP, IT Advisory KPMG LLP, IT Advisory
San Francisco Chapter San Francisco Chapter 2
Why change management and its significance Types of changes in production environment Change management controls Impact of weak change management control Integrity management Change management leading practices Software Development Life Cycle (SDLC)
San Francisco Chapter San Francisco Chapter 3
Why change management and its significance? Change management controls Impact of weak change control Integrity management Change management leading practices Types of changes in production environment
2 3 4 5 6 1 Organization 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 4
The total fraud losses in the United States
Off all the computer crimes reported
Women 32% Minorities 43% Ages 21-35 67%
Source: Association of Certified Fraud Examiners and National Center For Computer Crime
Managers 11% 14% 18% 12% 31%
Others
Application Programmers Clerical Users Students
Computer fraud Occupation
75% - 90%
computer crime committed by former or current employees (knowledgeable insiders) Why change management and its significance? Change management controls Impact of weak change control Integrity management Change management leading practices Types of changes in production environment
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 5
Change management – it is
Adapting to change Controlling change Effecting change
Why change management and its significance? Change management controls Impact of weak change control Integrity management Change management leading practices Types of changes in production environment
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 6
Types of changes in production environment Change management controls Impact of weak change control Integrity management Change management leading practices Why change management and its significance?
2 3 4 5 6 1
Network Equipment
Internet
Physical Control
7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 7
Applying OS patches
Re-imaging
Types of changes in production environment Change management controls Impact of weak change control Integrity management Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 8
Software changes
Configuration Changes
Hardware changes
Types of changes in production environment Change management controls Impact of weak change control Integrity management Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 9
Company specific application change
Database changes
Types of changes in production environment Change management controls Impact of weak change control Integrity management Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 10
Physical access to datacenter
Types of changes in production environment Change management controls Impact of weak change control Integrity management Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 11
OS Access Change
Application Access Change
Network Access Change
Types of changes in production environment Change management controls Impact of weak change control Integrity management Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 12
Planned/routing maintenance changes procedure and controls Planned/routing maintenance changes procedure and controls
Change management controls Types of changes in production environment Impact of weak change control Integrity management Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 13
Emergency/System Recovery change procedure and controls Emergency/System Recovery change procedure and controls
Change management controls Types of changes in production environment Impact of weak change control Integrity management Change management leading practices Why change management and its significance?
2 3 4 5 6 1
San Francisco Chapter San Francisco Chapter 14
Potential for system outages
Prone to unplanned
Causes unexplained additional problems or
Causes unplanned changes as problems are troublesome to resolve due to the prior undocumented changes
Impact of weak change control Types of changes in production environment Change management controls Integrity management Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 15
Prone to system attack
Misuse of resource
Causes legal implication
Losing a customer/ business
Impact of weak change control Types of changes in production environment Change management controls Integrity management Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 16
– Preventing, detecting and responding to changes in production systems detecting and responding to changes in production systems
Prevention
Integrity management Types of changes in production environment Change management controls Impact of weak change control Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 17
– Preventing, detecting and responding to changes in production systems detecting and responding to changes in production systems
critical network configuration, data files, customer database files, documents and spreadsheets
Integrity management Types of changes in production environment Change management controls Impact of weak change control Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 18
– Preventing, detecting and responding to changes in production systems detecting and responding to changes in production systems
Recovery
Integrity management Types of changes in production environment Change management controls Impact of weak change control Change management leading practices Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 19
Change management policy,
Change result management Change request management Deployment management Approval process Monitor application and networks
Change management leading practices Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 20
Production Environmen t
Change management leading practices Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 21
Change management policy, procedure and standard Change management policy, procedure and standard
What is change management policy
Change management leading practices Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 22
Change management policy, procedure and standard Change management policy, procedure and standard
Better assess the cost of proposed changes before
they are incurred
Reduce adverse impact of changes on the quality of
services and on Service Level Agreements (SLA)
Integrate with and communicate to IT and
management
Roles and responsibilities
process
Change management leading practices Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 23
Change Request Analysis
Change Request Management Change Request Management
Change management leading practices Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 24
Change Request Reporting
Change Request Management Change Request Management
Change management leading practices Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 6 1
San Francisco Chapter San Francisco Chapter 25
Appropriate approval should be obtain
Management approval should be documented
Approval Process Approval Process
Change management leading practices Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 26
Logical environment (separate)
Deployment process
Technology leverage
Deployment Management Deployment Management
Change management leading practices Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 27
Key Performance Indicators (KPI) about the
Use the KPIs (by management) to make
Post change implementation monitoring
Result management Result management
Change management leading practices Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 28
Integrity checks
Periodic reviews
Monitor application and networks Monitor application and networks
Change management leading practices Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 6 1 7
Software Development Life Cycle
San Francisco Chapter San Francisco Chapter 29
Relationship between change management and SDLC Relationship between change management and SDLC
Software Development Life Cycle Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 7 1 6
Change management leading practices
San Francisco Chapter San Francisco Chapter 30
Iterative model
Relationship between change management and SDLC Relationship between change management and SDLC
Software Development Life Cycle Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 7 1 6
Change management leading practices
Illustration courtesy of Rational Unified Process
San Francisco Chapter San Francisco Chapter 31
Iterative model
Relationship between change management and SDLC Relationship between change management and SDLC
Software Development Life Cycle Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 7 1 6
Change management leading practices
Illustration courtesy of Rational Unified Process
San Francisco Chapter San Francisco Chapter 32
Waterfall model
Relationship between change management and SDLC Relationship between change management and SDLC
Software Development Life Cycle Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 7 1 6
Change management leading practices
San Francisco Chapter San Francisco Chapter 33
Prototyping
Relationship between change management and SDLC Relationship between change management and SDLC
Software Development Life Cycle Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 7 1 6
Change management leading practices Mange Change
San Francisco Chapter San Francisco Chapter 34
V Model
Relationship between change management and SDLC Relationship between change management and SDLC
Software Development Life Cycle Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 7 1 6
Change management leading practices
San Francisco Chapter San Francisco Chapter 35
Audit areas:
systems relevant to each area
based on definition V Model
Relationship between change management and SDLC Relationship between change management and SDLC
Software Development Life Cycle Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 7 1 6
Change management leading practices
San Francisco Chapter San Francisco Chapter 36
Tools to manage changes better Tools to manage changes better
Software Development Life Cycle Types of changes in production environment Change management controls Impact of weak change control Integrity management Why change management and its significance?
2 3 4 5 7 1 6
Change management leading practices
Illustration courtesy of Rational Unified Process
San Francisco Chapter San Francisco Chapter