Exam objective

SY0-701 1.3: Change Management and Security

Security+ Topic

Change Management and Security for Security+

This Security+ topic covers securityplus.gsc.change.process1 owns the business process elements that reduce change risk: approval process, ownership, stakeholders, impact analysis, test results, backout plan, maintenance window, and standard operating procedure; securityplus.gsc.change.technical2 owns technical implications of change: allow lists, deny lists, restricted activities, downtime, service restart, application restart, legacy applications, and dependencies; securityplus.gsc.change.docs3 owns documentation and version tracking: updating diagrams, updating policies, updating procedures, and version contro...

Start first lesson

3 lessons in this topic

Common mistakes to avoid

1

Learners often treat change management as paperwork separate from security. The shortest correction is that change controls protect confidentiality, integrity, and availability by preventing unreviewed changes, identifying impact, proving readiness, coordinati...

2

Learners often see a technical change only as the desired fix. The shortest correction is to ask what else the change can affect: access, outage, restart, legacy compatibility, and dependencies.

3

Learners often treat documentation as a final report rather than a security control. The shortest correction is that current documentation and version control preserve accurate decisions, repeatable operations, investigation evidence, and rollback options.