Course Information
IT Change Management & SDLC: Fundamentals, Leading Practices, And Risk-Based Oversight
Course Description
Technology change is inevitable—but uncontrolled change is one of the fastest ways to break systems, disrupt operations, expose security gaps, and create audit findings.
This course provides a practical, end-to-end view of IT Change Management and the Software Development Life Cycle (SDLC), grounded in real-world failures, audit expectations, and leading practices. Participants will learn how technology changes should be designed, tested, approved, deployed, and monitored, and how poor change discipline directly leads to production outages, data integrity issues, and regulatory risk.
Beyond the technical mechanics, the course integrates general change management concepts—addressing why changes fail not just because of bad code, but because of poor communication, weak ownership, rushed timelines, and misaligned incentives.
The focus is not “how to code,” but how to govern, assess, and oversee change effectively, whether you sit in IT, audit, risk, compliance, or management.
Course Objectives
Objectives
Explain the purpose and risk drivers of IT Change Management
Understand SDLC phases and where risks typically emerge
Distinguish between standard, emergency, and normal changes
Identify leading practices vs. common failure points
Evaluate change management controls from an audit and risk lens
Recognize the human and organizational factors that cause change breakdowns
Ask smarter questions during audits, reviews, and project meetings
Outline
Module 1: Why IT Change Management Exists (and Why It Fails)
The real cost of poor change management
Production outages, data corruption, security gaps
Why “it worked in test” is not a control
The false trade-off between speed and control
Module 2: IT Change Management Fundamentals
What constitutes an IT change?
Normal vs. standard vs. emergency changes
Change lifecycle overview:
Request
Impact assessment
Approval
Testing
Deployment
Post-implementation review
Segregation of duties (who should not approve their own changes)
Audit Lens
What regulators and auditors actually expect
Common audit findings and root causes
Module 3: SDLC Overview – From Idea to Production
What SDLC is (and what it is not)
Core SDLC phases:
Requirements & design
Development
Testing (unit, system, UAT)
Module 4: Risk Hotspots Across the SDLC
Poor or undocumented requirements
Inadequate testing coverage
Weak UAT ownership
Emergency changes becoming the norm
Lack of rollback plans
No post-implementation validation
Case Examples
Failed deployments
Broken integrations
Security vulnerabilities introduced by change
Module 5: General Change Management (People, Process, Behavior)
Why change fails even when controls exist
Communication breakdowns
Change fatigue and workarounds
Ownership gaps (“Everyone approved it—no one owned it”)
Incentives that reward speed over stability
Module 6: Governance, Oversight, and Control Design
Change Advisory Boards (CABs): value vs. theater
Risk-based approvals (not all changes are equal)
Evidence that matters: what to document and why
Metrics that actually indicate control health:
Emergency change rates
Failed change percentages
Post-deployment incidents
When automation helps—and when it hides risk
Module 7: Auditing and Assessing IT Change Management
Scoping a change management audit
Control design vs. operating effectiveness
Sample testing strategies
Red flags auditors should never ignore
How to challenge “that’s how Agile works” responses
Module 8: Practical Takeaways & Leading Practices
What “good” actually looks like
How to scale controls without killing delivery
Aligning IT, business, and audit expectations
Questions leaders should ask before approving change
Prerequisites
None
Instructors
Andrew Cano has 20 years of learning and development experience, having designed and led courses and workshops in a variety of academic and professional settings. He has held the following roles over his career:
The inaugural Literacy Liaison at a major metropolitan library.
Coordinator of a Quality Enhancement Plan at a regional community college.
Faculty-level Virtual Learning Librarian at a flagship state research university.
Information Security Officer at a state government agency.
Achievements include:
Training public library employees in serving minority populations.
Contributing to the development and teaching of an interdisciplinary first-year college success course.
Designing a virtual information literacy academic learning program.
Implementing an agency-wide information security awareness program.
Mr. Cano is passionate about empowering students to engage in classes, recognizing that they are active participants in the learning experience.
Having transitioned to a career in IT auditing after over a decade as an academic librarian, he is eager to help fellow career changers build upon existing knowledge and skills to achieve success in the field.
Mr. Cano possesses a wide breath of knowledge in IT, with expertise in cybersecurity governance, risk, and compliance. He has earned numerous industry-recognized certifications, including:
Certified Internal Auditor
Certified Information Security Auditor
Certified Information Systems Security Professional
Certified Technical Trainer
Mr. Cano completed his undergraduate IT and cybersecurity education at Southeast Community College (Lincoln, NE) and Bellevue University. He earned his graduate degree in cybersecurity and information assurance from Western Governors University.