free page hit counter
Click the banner for the site map  of NoticeBored.com, the information security awareness service
Change management & patching

Dave Barry quote

General change management resources

Good reading An outstanding collection of papers and quotes on change management includes many pithy pieces by Peter de Jager.

Good reading Pioneering research by Elisabeth Kubler-Ross inspired the ‘grieving curve’ used in some of the NoticeBored materials on change management. Until her own death, Dr Kubler-Ross was a psychiatrist and world authority on the psychological effects of grieving. The grieving curve resonates with our own experience of major changes and incidents, and has interesting applications in understanding and predicting the effects of changes on individuals and organizations.

Good reading Another inspirational pioneer was Kurt Lewin who died five decades ago. The classic ‘unfreeze-change -refreeze’ model of change is one of Kurt’s legacies. ‘Motivation for change must be generated before change can occur’ he said.

Change Management 101, a general primer on change management, introduces specialist terms and the main themes from this field of study.

The Emotional Intelligence Consortium publishes fascinating books and reports on the application of emotional intelligence techniques in the workplace. Emotional intelligence concerns our ability to perceive and utilize emotions and ‘gut feel’, and complements our conventional understanding of intelligence (measured by IQ). Empathy, for instance, is an important emotional intelligence capability for managers and those engaged in change projects dealing with people, yet is seldom even recognized let alone explicitly valued in the hiring and selection process.

The Journal of Organizational Behavior is a good way to keep up with academic research relating to change management.

Interviewed in the McKinsey Quarterly, the CEO of P&G discussed various aspects of leading and managing change across the entire organization. For example, targets that stretch too far risk demotivating people [whilst those that don’t stretch enough are lame]. Difficult concepts such as ‘core business’ have to be explained patiently and frequently to some people. Similarly, the CEO of D&B said of his change strategy “The primary focus was to repair the brand, change the business model to get funds to pay for the repairs, and create a new culture. Creating a new culture was fundamental to the new strategy.” [There are clear implications for security awareness programs here.]

IT change management

The Institute of Internal Auditors’ final draft guide to change and patch management controls is “about managing risks that are a growing concern to those involved in the governance process. Like information security, management of IT changes is a fundamental process that can cause damage to the entire enterprise and easily disrupt operations if it is not performed well. This enterprisewide impact makes change management of interest to many audit committees and, as a result, to top management. The objective of this guide is to convey how effective and efficient IT change and patch management contribute to organizational success.” The guide is part of IIA’s Global Technology Audit Guide GTAG.

Network World claimed that [US] hospitals are rebelling against restrictions from device manufacturers on software updates over fears about security. It seems, reading between the lines, there is a power battle underway between the FDA and the device manufacturers. The manufacturers claim to need months to test the effects of operating system updates on their software, for fear that the devices might not operate correctly (in other words, a health and safety risk). Hospitals, meanwhile, are concerned that not applying the operating system patches in a timely manner would be an unacceptable information security risk. 

Configuration management & version control

The description of ‘revision control’ at Wikipedia reads a lot like what is commonly called ‘version control’ or Software Configuration Management (SCM), but is interesting nonetheless. The wiki itself provides an object lesson in revision control: users are invited to make changes to the wiki, with the system automatically retaining checkpoints in case something goes wrong or otherwise has to be reversed and optionally notifying other users that changes have been made.

Configuration management has its roots in engineering methods, largely predating software engineering but incorporated and updated in professional engineering and CAD-CAM (Computer Aided Design - Computer Aided Manufacture) software. Product Data Management (PDM) and Product Information Management (PIM ) are techniques for formally controlling engineering information about aircraft parts and so forth.


Related NoticeBored links collections

Bugs!, integrity, IT Ops, governance, accountability and responsibility, IT audit, information security management and contingency planning.


NB: we do not necessarily endorse or agree with the third party websites accessible through the links. Use at your own risk. Please let us know about new or broken links.


NB homeLinks collection > Changes & patches >

Copyright © 2008 IsecT Ltd.