← Home

Change Management

Change management (also called change control) minimises safety and downtime risk by ensuring change requests are recorded, evaluated, authorised, prioritised, planned, tested, implemented, documented and reviewed in a controlled way. In ISA/IEC 62443-2-1, change control sits in Security Program Element SPE 2 (CM 1.4). Vulnerability and patch work must follow the same process.

Teaching note: Paraphrased for learning from IACS cybersecurity course material and industry practice. Process safety Management of Change (MOC) may be regulated (for example OSHA PSM in the US); this page does not replace site MOC procedures.

Related: IEC 62443-2-1 SPE 2 | Asset Inventory | Patch Management | System Hardening | Cybersecurity Acceptance Testing | IEC 61508


What counts as a change


Change request content

Requests should support assessment of goals, cost and risk:

In process industries, multi-disciplinary review (Management of Change / MOC) reduces the chance of missing a hazard — including cyber-induced process hazards.


Priority guidance

Priority Typical trigger
Immediate Life at risk; significant revenue or environmental impact — treat as emergency
High Safety systems affected or production continuity threatened
Medium No severe impact yet, but cannot wait for the next planned shutdown
Low Justified change that can wait for the next scheduled shutdown

Emergency changes still need documentation — often after the fact — plus a test plan and a rollback path if the change fails.


Key takeaways