// CPCSC TEMPLATES · 07 OF 14

Change management policy and change request record

Last verified: 2026-10-05

A documented change process and the record that proves it ran. Satisfies 03.04.03, 03.04.04, and 03.04.05.

Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.

TPL-07 Static template

Policy

Configuration-controlled changes at [Company] include patches to enclave servers, firewall rule changes, changes to enclave group membership, new devices joining the enclave, and any change to the network diagram. Each is requested in writing, reviewed for security impact, approved by [approver role], scheduled in a change window, and recorded on completion with evidence attached. Emergency changes follow the same record after the fact, within [2 business days]. Changes are made only by [authorized roles] and only from administration workstations.

Change request record

Request ID:      CR-[YYYY]-[NNN]
Requested by:    [name, role]           Date: [date]
Change:          [what]
Systems:         [which]
Reason:          [why]
Security impact: [assessed by, finding]
Risk / rollback: [backup or snapshot taken; revert plan]
Window:          [date, start–end]
Approver:        [name, role]           Approved: [date]
Completed by:    [name]                 Completed: [date/time]
Evidence:        [report, screenshot, log attached]

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.