Change Control Policy

POLICY #: CR 26-8

DATE OF BOARD OF TRUSTEES APPROVAL: 9/28/2026

RESOLUTION #: 26-8

Purpose:

The purpose of this policy is to ensure that all changes to College Informational Technology (IT) resources minimize any potential negative impact on services and users.

Scope:

This policy and all policies referenced herein, shall apply to all members of the College community, including employees, students, alumni, authorized guests, and independent vendors who use, access, or otherwise employ, locally or remotely, the College’s IT Resources, whether individually controlled, shared, stand-alone, or networked.

Definitions:

  • Change Control Process: A systematic approach to managing changes to all College IT resources. The purpose is to ensure that changes are necessary, properly documented, appropriately reviewed and authorized, and implemented in a manner that minimizes service disruptions and promotes the efficient use of College resources.
  • IT Resources: Includes computing, networking, communications, application, and telecommunications systems and infrastructure; hardware and software; data and databases; personnel; procedures; physical facilities; cloud-based and Software as a Service (SaaS) vendors; and other related materials, services, and resources.

IT Resource Change Process:

  • All changes to College IT Resources must be documented and managed in accordance with the Change Control Process.
  • All changes to College IT Resources must receive appropriate review and approval and be adequately planned, tested, and executed to minimize disruption to College operations.
  • Change requests may not be required for changes to non-production environments unless the change is expected to have a significant impact on users, systems, services, or security.
  • Production changes must be successfully implemented and complete required user acceptance testing before being considered complete.
  • Prior to submitting a change request for a production environment, the proposed change must undergo an impact assessment. The assessment must consider:
    • The potential impact on business services, including the likelihood of widespread outages, loss of connectivity, or loss of functionality for specific users or groups.
    • The risk associated with not implementing the change.
    • The risk that the change may not produce the intended outcome or may not proceed as planned.
    • The anticipated outcome and potential consequences of the change.
    • All changes must be evaluated for potential security implications.
    • Significant changes to the user experience must be presented to the Change Approval Board and communicated in advance, as appropriate, to affected users and the IT Helpdesk.
    • When an incident occurs during or because of a change, a lessons-learned review must be conducted to identify contributing factors, corrective actions, and opportunities to improve the Change Control Process.