Policy
Configuration-controlled changes at [Company] include patches to enclave servers, firewall rule changes, changes to enclave group membership, new devices joining the enclave, and any change to the network diagram. Each is requested in writing, reviewed for security impact, approved by [approver role], scheduled in a change window, and recorded on completion with evidence attached. Emergency changes follow the same record after the fact, within [2 business days]. Changes are made only by [authorized roles] and only from administration workstations.
Change request record
Request ID: CR-[YYYY]-[NNN]
Requested by: [name, role] Date: [date]
Change: [what]
Systems: [which]
Reason: [why]
Security impact: [assessed by, finding]
Risk / rollback: [backup or snapshot taken; revert plan]
Window: [date, start–end]
Approver: [name, role] Approved: [date]
Completed by: [name] Completed: [date/time]
Evidence: [report, screenshot, log attached]