UBC — AI Solutions

Audit — Dynamic Documentation Platform

Living documentation that stays in sync with engineering, cloud, AI, and compliance activity. Documents update themselves as the organization changes.

Back to library
SOP
Fresh

SOP-SDLC-06 — Change & Configuration Management

Controls every change to production systems through a defined change process (normal, standard, emergency).

Owner: Change ManagerApprover: Engineering DirectorVersion: 4.1Updated: 11/22/1969

1. Purpose

Ensure changes to production are assessed for risk, authorised, implemented safely, and reviewed.

2. Scope

All production changes to code, infrastructure, data, models, and prompts.

3. Definitions

  • Standard change — Pre-authorised, low-risk change with a defined runbook.
  • Normal change — A change that requires CAB assessment and approval.
  • Emergency change — A change required to restore service or address an urgent security issue.

4. Roles & Responsibilities (RACI)

ActivityRACICadence
Raise change recordChange requesterChange ManagerApproverStakeholdersPer change
Assess riskChange ManagerChange ManagerSecurity, SREOwnerPer change
Approve normal changesCABChange ManagerSMERequesterWeekly
Post-implementation reviewOwnerChange ManagerTeamCABWeekly

5. Procedure

  1. Raise a change record in the ticket system with description, risk, backout plan, and validation plan.
  2. Classify (standard / normal / emergency).
  3. Route for the required approvals; standard changes need the pre-approved runbook.
  4. Implement in a change window with monitoring in place.
  5. Validate success; on failure, execute the backout plan.
  6. Complete a Post-Implementation Review within 5 business days.

6. Inputs & Outputs

Inputs

  • Change record
  • Risk assessment
  • Backout plan

Outputs

  • Approved change
  • Implementation evidence
  • PIR outcomes

7. Controls & Metrics

MetricTarget
Changes with backout plans100%
Emergency change ratio≤ 5%

8. Exceptions & Escalation

  • Emergencies may implement without prior CAB approval but require retro-approval within 24 hours.

9. Records & Retention

RecordRetention
Change records7 years
PIRs3 years
  • SOP-SDLC-04
  • SOP-SDLC-07
  • SOP-CMMI-CM

11. References

  • ITIL 4
  • ISO 20000
  • SOC 2 CC8.1

12. Revision History

See the Versions tab for the full change history maintained by the Auto-Doc Engine.


Document code: SOP-SDLC-06 · Aligned to ITIL 4 Change Enablement / ISO 20000. Controlled document — reproduction outside the UBC QMS requires the Quality Manager's approval.

Suggested by AI
No suggestions right now.
Frameworks
ISO 9001
CMMI-DEV
SOC 2
ISO 27001