Skip to main content

IT Change Management & SDLC: Fundamentals, Leading Practices, And Risk-Based Oversight

Back to Course Schedule
Date(s): Feb 09, 2027
Time: 8:00AM - 12:00PM
Registration Fee: $119.00
Cancellation Date: N/A
Location: Online

Course Description

Technology change is inevitable—but uncontrolled change is one of the fastest ways to break systems, disrupt operations, expose security gaps, and create audit findings.

This course provides a practical, end-to-end view of IT Change Management and the Software Development Life Cycle (SDLC), grounded in real-world failures, audit expectations, and leading practices. Participants will learn how technology changes should be designed, tested, approved, deployed, and monitored, and how poor change discipline directly leads to production outages, data integrity issues, and regulatory risk.

Beyond the technical mechanics, the course integrates general change management concepts—addressing why changes fail not just because of bad code, but because of poor communication, weak ownership, rushed timelines, and misaligned incentives.

The focus is not “how to code,” but how to govern, assess, and oversee change effectively, whether you sit in IT, audit, risk, compliance, or management.


Potential CPE Credits: 4.0
Technical Hours: This class meets 4.0 CPE credits of technical training in compliance with Texas Admin. Code Rule 523.102.

Instruction Type: Live
Experience Level: ALL
Category: Auditing

Course Objectives

Objectives

  • Explain the purpose and risk drivers of IT Change Management

  • Understand SDLC phases and where risks typically emerge

  • Distinguish between standard, emergency, and normal changes

  • Identify leading practices vs. common failure points

  • Evaluate change management controls from an audit and risk lens

  • Recognize the human and organizational factors that cause change breakdowns

  • Ask smarter questions during audits, reviews, and project meetings

Outline

Module 1: Why IT Change Management Exists (and Why It Fails)

  • The real cost of poor change management

  • Production outages, data corruption, security gaps

  • Why “it worked in test” is not a control

  • The false trade-off between speed and control

Module 2: IT Change Management Fundamentals

  • What constitutes an IT change?

  • Normal vs. standard vs. emergency changes

  • Change lifecycle overview:

    • Request

    • Impact assessment

    • Approval

    • Testing

    • Deployment

    • Post-implementation review

  • Segregation of duties (who should not approve their own changes)

  • Audit Lens

  • What regulators and auditors actually expect

  • Common audit findings and root causes

Module 3: SDLC Overview – From Idea to Production

  • What SDLC is (and what it is not)

  • Core SDLC phases:

    • Requirements & design

    • Development

    • Testing (unit, system, UAT)

Module 4: Risk Hotspots Across the SDLC

  • Poor or undocumented requirements

  • Inadequate testing coverage

  • Weak UAT ownership

  • Emergency changes becoming the norm

  • Lack of rollback plans

  • No post-implementation validation

  • Case Examples

  • Failed deployments

  • Broken integrations

  • Security vulnerabilities introduced by change

Module 5: General Change Management (People, Process, Behavior)

  • Why change fails even when controls exist

  • Communication breakdowns

  • Change fatigue and workarounds

  • Ownership gaps (“Everyone approved it—no one owned it”)

  • Incentives that reward speed over stability

Module 6: Governance, Oversight, and Control Design

  • Change Advisory Boards (CABs): value vs. theater

  • Risk-based approvals (not all changes are equal)

  • Evidence that matters: what to document and why

  • Metrics that actually indicate control health:

    • Emergency change rates

    • Failed change percentages

    • Post-deployment incidents

  • When automation helps—and when it hides risk

Module 7: Auditing and Assessing IT Change Management

  • Scoping a change management audit

  • Control design vs. operating effectiveness

  • Sample testing strategies

  • Red flags auditors should never ignore

  • How to challenge “that’s how Agile works” responses

Module 8: Practical Takeaways & Leading Practices

  • What “good” actually looks like

  • How to scale controls without killing delivery

  • Aligning IT, business, and audit expectations

  • Questions leaders should ask before approving change


Prerequisites

None


Instructors

Andrew Cano

Andrew Cano has 20 years of learning and development experience, having designed and led courses and workshops in a variety of academic and professional settings. He has held the following roles over his career:

  • The inaugural Literacy Liaison at a major metropolitan library.

  • Coordinator of a Quality Enhancement Plan at a regional community college.

  • Faculty-level Virtual Learning Librarian at a flagship state research university.

  • Information Security Officer at a state government agency.

Achievements include:

  • Training public library employees in serving minority populations.

  • Contributing to the development and teaching of an interdisciplinary first-year college success course.

  • Designing a virtual information literacy academic learning program.

  • Implementing an agency-wide information security awareness program.

Mr. Cano is passionate about empowering students to engage in classes, recognizing that they are active participants in the learning experience.

Having transitioned to a career in IT auditing after over a decade as an academic librarian, he is eager to help fellow career changers build upon existing knowledge and skills to achieve success in the field.

Mr. Cano possesses a wide breath of knowledge in IT, with expertise in cybersecurity governance, risk, and compliance. He has earned numerous industry-recognized certifications, including:

  • Certified Internal Auditor

  • Certified Information Security Auditor

  • Certified Information Systems Security Professional

  • Certified Technical Trainer

Mr. Cano completed his undergraduate IT and cybersecurity education at Southeast Community College (Lincoln, NE) and Bellevue University. He earned his graduate degree in cybersecurity and information assurance from Western Governors University.


Back to Course Schedule