Processes: Change & Configuration Management
No processes match the current filters.
ChaRM Change Review by Quality and Validation Unit
Change & Configuration Management
ID: P024
Defines Quality Assurance and CSV/Validation Unit involvement during ChaRM (Change Request Management) workflow in SAP Solution Manager for Normal, Admin, and Urgent change types. Specifies review sequence and status transitions for GxP and non-GxP relevant changes. Urgent changes require retrospect
Source Documents (1)
Mapped Citations (4)
Artifacts (2)
Change and Configuration Management for Computerized Systems
Change & Configuration Management
ID: P025
Governs the request, assessment, approval, and implementation of changes and enhancements to validated computerized systems, including supplier-initiated and infrastructure changes. Ensures the validated state of the system is maintained and configuration items are updated per SOP-0109167.
Source Documents (1)
Mapped Citations (38)
- 16.5 Use Up-to-Date and Trusted Third-Party Software Compone...
- 2.2 Ensure Authorized Software is Currently Supported
- 7.3 Perform Automated Operating System Patch Management
- 7.4 Perform Automated Application Patch Management
- CCC-01 Change Management Policy and Procedures
- CCC-03 Change Management Technology
- CCC-05 Change Agreements
- CEK-05 Encryption Change Management
- Change Approval
- Change Impact Assessment
- Change Management
- Change management
- Configuration management
- Continuous Vulnerability Management
- DE.CM-06
- Deploy Automated Operating System Patch Management Tools
- ID.RA-07
- Management of technical vulnerabilities
- Managing information security in the information and communi...
- Monitoring, review and change management of supplier service...
- Only Use Up-to-date And Trusted Third-Party Components
- PP.164.316.b2-iii
- PR.PO-P2
- PR.PS-01
- PR.PS-02
- PR.PS-05
- Patch Exceptions
- Secure Configuration for Hardware and Software on Mobile Dev...
- Secure Configuration for Network Devices, such as Firewalls,...
- Security Patch Assessment
- Security Patch Review
- System Documentation Ctrl
- TVM-05 External Library Vulnerabilities
- UEM-07 Operating Systems
- Validation Documentation (Change control and Deviations)
- Vendor Documentation
- Vendor Update Assessment
- Verify That Acquired Software is Still Supported
Roles (2)
Artifacts (2)
Configuration Control
Change & Configuration Management
ID: P027
Determines control mechanisms for updating CI Records as changes occur over the Configuration Item lifecycle, including creation, maintenance, relationship updates, and retirement. Defined in SOP-0303612 with compliance rules for GxP-relevant services.
Source Documents (1)
Mapped Citations (16)
- 4.1 Establish and Maintain a Secure Configuration Process
- 4.2 Establish and Maintain a Secure Configuration Process fo...
- 4.6 Securely Manage Enterprise Assets and Software
- CCC-06 Change Management Baseline
- Configuration management
- Deploy System Configuration Management Tools
- Document Traffic Configuration Rules
- Establish Secure Configurations
- Maintain Standard Security Configurations for Network Device...
- PR.PO-P1
- PR.PO-P2
- PR.PS-01
- PS.164.310.d2-iii
- Secure Configuration for Hardware and Software on Mobile Dev...
- Secure Configuration for Network Devices, such as Firewalls,...
- System Documentation Ctrl
Artifacts (1)
Configuration Identification
Change & Configuration Management
ID: P028
Determines the scope and selection criteria for Configuration Items to be created in the CMDB as CI Records, ensuring they are manageable and traceable throughout their lifecycle. Defined in SOP-0303612, this process covers planning, creation, relationship configuration, and activation of CI Records
Source Documents (1)
Mapped Citations (23)
- 1.1 Establish and Maintain Detailed Enterprise Asset Invento...
- 2.1 Establish and Maintain a Software Inventory
- 4.1 Establish and Maintain a Secure Configuration Process
- 4.2 Establish and Maintain a Secure Configuration Process fo...
- Associate Active Ports, Services and Protocols to Asset Inve...
- CCC-06 Change Management Baseline
- Configuration management
- Deploy System Configuration Management Tools
- ID.AM-01
- ID.AM-02
- ID.AM-03
- ID.AM-04
- ID.AM-07
- Integrate Software and Hardware Asset Inventories
- Inventory and Control of Hardware Assets
- Maintain Asset Inventory Information
- Maintain Detailed Asset Inventory
- Maintain an Inventory of Network Boundaries
- OS-1.A.1
- PR.PO-P1
- PR.PS-01
- PR.PT-P2
- Track Software Inventory Information
Artifacts (1)
Configuration Reporting
Change & Configuration Management
ID: P029
Determines CI Record traceability over the Configuration Item lifecycle by analyzing CMDB reports, identifying required updates, and executing corrective actions. Defined in SOP-0303612, this process ensures CI Record ownership, status, attributes, and relationships remain accurate.
Source Documents (1)
Mapped Citations (5)
Artifacts (2)
Configuration Verification and Audit
Change & Configuration Management
ID: P030
Determines conformity between Configuration Items and CI Records when a verification request is received, reconciling any discrepancy between the CI inventory and the CMDB. Defined in SOP-0303612, it covers verification analysis, action planning, and remediation execution.
Source Documents (1)
Mapped Citations (12)
- 1.2 Establish and Maintain Detailed Enterprise Asset Invento...
- 2.3 Address Unauthorized Software
- Address Unauthorized Assets
- Address unapproved software
- CCC-07 Detection of Baseline Deviation
- Configuration Monitoring
- Configuration management
- ITSM Reconciliation
- Implement Automated Configuration Monitoring Systems
- PR.DS-P6
- PR.DS-P8
- Use Automated Tools to Verify Standard Device Configurations...
Emergency Change
Change & Configuration Management
ID: P037
An expedited change management process defined in SOP-0304218 for immediate action required to resolve Major Incidents or issues threatening product quality, patient safety, or data integrity. Steps may be performed retrospectively to allow immediate service restoration, but all documentation must b
Source Documents (1)
Mapped Citations (13)
Artifacts (1)
Installation Verification Execution
Change & Configuration Management
ID: P054
A controlled procedure for executing, verifying, and signing off a standard change to a validated system (doc 18470290). Covers pre-requisite checks, database-level installation steps, post-installation verification, rollback readiness, and multi-role sign-off in a GxP-compliant deployment workflow.
Source Documents (1)
Mapped Citations (4)
Normal Change Management
Change & Configuration Management
ID: P057
The full change management lifecycle for Normal Changes as defined in SOP-0304218. Covers creation, assessment, authorization, build/test scheduling, implementation authorization, execution, and post-implementation review and closure of changes to services and infrastructure. Ensures all changes are
Source Documents (1)
Mapped Citations (26)
- AIS-07 Application Vulnerability Remediation
- Access to source code
- CCC-01 Change Management Policy and Procedures
- CCC-02 Quality Testing
- CCC-03 Change Management Technology
- CCC-04 Unauthorized Change Protection
- CCC-09 Change Restoration
- CEK-05 Encryption Change Management
- Change Approval
- Change Description
- Change Impact Assessment
- Change Management
- Change SoD
- Change Testing
- Change management
- ID.RA-07
- PR.DS-P7
- PR.MA-P1
- PR.MA-P2
- PR.PO-P2
- PR.PS-05
- Pre-Production Testing
- Production Migration Approval
- Segregation Of duties
- System Locking/Unlocking
- TVM-03 Vulnerability Remediation Schedule
Standard Change
Change & Configuration Management
ID: P067
A streamlined change management process defined in SOP-0304218 for changes with clearly defined scope and proven repeatable procedures established via approved templates. Standard Pre-Authorized changes proceed directly to implementation; Standard With Authorization changes include build/test coordi
Source Documents (1)
Mapped Citations (1)