workflow

Change & Release Management (CAB)

Change & Release Management (CAB) as a decision-aware workflow that runs one recurring weekly instance against the EXISTING change-management ITGC Control item in the control library (domains: secure_configuration_change_management; mapped via Control.framework to nist-800-53, cobit-2019, iso-27001, and soc1, alongside the related UC-CONFIG-02/03, UC-ACCESS-16, and UC-SDLC-06/07/08/09 controls) — it enriches that control's operating evidence each cycle, it does not create the control. Upstream it consumes the open change-request queue and the emergency-change log exported from the ticketing system, plus the prior cycle's closure export as its carry-forward backlog. It covers change intake, security and risk impact analysis, environment segregation and configuration-baseline control, acceptance testing, the single CAB authorization gate, the emergency-change path, and controlled deployment with rollback and post-implementation verification — producing the prioritized CAB agenda and authorization packet, per-change risk-assessment memos, the environment-and-baseline verification memo, acceptance-testing summaries, the deployment-and-verification record, and the archived per-cycle evidence set. In scope: application, database, infrastructure, configuration, and procedure changes across development, test, and production environments. Out of scope: authoring the change itself — this workflow governs authorization and release, not development of the underlying code or configuration. Studio ships no native Change Request item type, so per-change records live as lines in step documents and in the workflow instance rather than as items. This is a terminal workflow with no downstream handoff: closure archives the cycle evidence set in place under retention, and the next cycle's intake reads this instance's closure export as its carry-forward source.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
operate

Details

teams
  • it
  • finance
domains
  • controls
standards
  • nist-800-53
  • cobit-2019
  • iso-27001
  • soc1
sourceTemplateId
workflow-library:controls-change-release-management-operation
releaseId
sha256:bff91696eb5798d65dae1ed4785cae7e0def347c88e46ca51aa4faed126fbe9b
canonicalUrl
https://workflow-library.com/all/?w=controls-change-release-management-operation
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-CONFIG-02
    • UC-CONFIG-03
    • UC-ACCESS-16
    • UC-SDLC-07
    • UC-SDLC-06
    • UC-SDLC-08
    • UC-SDLC-09
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:bff91696eb5798d65dae1ed4785cae7e0def347c88e46ca51aa4faed126fbe9b

            Connections