Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« 10 Tips for Minimizing Complexity to Improve Security | Main | Web 2.0 Is Coming And So Are The Security Headaches »

Improving Security with ITIL: Change Management

IT infrastructure is dynamic and keeping up with business requirements means we have to be pretty agile when it comes to configuring, redeploying and managing software and hardware assets. ITIL takes this problem head on by addressing change management.

Change management can be reduced to 5 key processes:

• Planning – managers and system administrators need to plan roles and responsibilities, establish polices for change management and create a centralized configuration management database (CMDB).
• Identifying assets – we need to keep a detailed inventory of the assets, both hardware and software; the information should be tracked in the CMDB.
• Establishing controls on the CMDB – the asset inventory in the CMDB is the basis for streamlining management which in turn supports better security. Keep the CMDB locked down and update it using only established and tested procedures.

• Monitoring the status of assets. Automation is critical here; log files can grow too quickly to analyze without tools for identifying significant events.
• Auditing change management procedures to make sure they are followed.

In addition to the 5 processes, change management in any but the smallest organizations is going to require a centralized repository, the CMDB. The CMDB track information on configuration items (CI). Each CI entry should track:

• Technical data about the item, like hardware description, version numbers, serial numbers, etc.
• Organization information, such as who owns the asset, who manages it, and documentation on the asset
• Relationship data about how the asset fits with other assets.

For more on change mangagement, see the ITIL main site as well as The Definitive Guide to Enterprise Change Management and The Definitive Guide to Service Oriented Systems Management

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/196

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net