CHANGE MANAGEMENT FOR WINDOWS OS
Background Client Platform: Windows Operating System Operating System Version: Windows 8 Client Devices: desktop computers and laptops Security Software: Symantec Client Management Suite OS and software patches: installed per management policy Components: Configuration and maintenance, User interface, Applications, File systems, Core components, Services, Kernel, Security, Device drivers, Hardware devices, and APIs
Scope Version migration management from Windows 8 to Windows 10 Anti-malware software Patch management Device settings User settings Passwords – Complexity, Age, Uniqueness
Out of Scope Windows Server 2012 and Servers Mobile devices Customized application
IT Audit team members’ roles and responsibilities Name Roles Responsibilities Ugo Nwadike Project Leader The project Leader manages the process for all change management requests and reviews each request for completeness. The person in that role verifies that the stated objectives of the request can be met and are consistent with the company's best practices. He has the discretion to deny requests that are not consistent with company policy or best practices. Iyana Lester Auditor 1 The Auditor 1 - originates the request by submitting a written or online Request For Change (RFC) to the change management manager. Yijiang Li Auditor 2 Makes the necessary changes as requested in the RFC and notifies affected parties if corresponding changes need to be made. For example, changes made to Active Directory or Exchange are implemented into production by the change implementer. Hanqing Zhou Auditor 3 Monitors project execution and reports emergency IT changes to the Project Leader. Yuan Liu Auditor 4 Manages implementation notes and documents the reason for change.
Risk assessment low moderate high RISK LIKELIHOOD IMPACT Asset Management low moderate Access Management high System Downtime Over Budget of IT Projects Change Control Data loss Legacy Systems Software Threats & Vulnerabilities Unauthorized Access
Audit Hours and Phases Name Role Time allocated for each of the audit phases (Hrs) Total time (Hrs) Planning Fieldwork & Documentation Issue Discovery & Validation Reporting Drafting & Issuance Ugo Nwadike Lead Auditor 8 32 Iyana Lester Auditor 10 6 Yijiang Li Hangqing Zhou Yuan Liu 40 48 160
Key dates and deliverable Planning 26th Feb ~ 2nd Mar Fieldwork & Documentation 5th Mar ~ 9th Mar Issue Discovery & Validation 12th Mar ~ 16 Mar Report drafting & Issuance 19th Mar ~ 23th Mar
QUESTIONS
References Modern System Analysis & Design 8th Edition Joseph S. Valacich and Joey F. George http://searchwindowsserver.techtarget.com/tip/A-disciplined-approach-to-the-Windows-change-management-process http://searchwindowsserver.techtarget.com/tip/Implementing-change-management-in-the-Windows-server-environment http://www.windowstalk.org/windows8-challenges https://answers.microsoft.com/en-us/windows https://www.microsoft.com/en-us/windows/