UHUBS POLICY

Change Control and Configuration Management Policy

Last reviewed on 30 October 2025
This policy outlines the procedures for change control and configuration management. It includes user access reviews, monitoring and detection practices, system drills, risk assessment, test environment validation, rollout and monitoring, recording change management, and a 3-step rollback process for unexpected issues.

1. User Access Review and 'Least Privilege' Policy:

1.1 Quarterly Access Review:

Uhubs to conduct quarterly reviews of user access and permissions across all tools and software. This ensures that access aligns with job responsibilities and follows the principle of 'least privilege,' where team members are granted the fewest necessary permissions for their roles.

2. Monitoring and Detection:

2.1 Comprehensive Monitoring:

Uhubs to monitor performance utilizing our Application Performance Monitoring (Sentry) tool, in-house monitoring systems, and smoke tests. This combination allows for the early detection of deviations from expected system behavior.

2.2 Emergency Notification System:

In the event of a major problem, Uhubs has implemented an emergency notification system to alert Critical Service Contacts (CSCs). This ensures swift communication and coordinated response to critical incidents.

3. System Drills and Rollback Preparedness:

3.1 Regular Drills:

Uhubs to conduct regular drills on all key systems to ensure the ability to perform rollbacks quickly and effectively in case of a major disruption. These drills contribute to maintaining the resilience of the system and refining the rollback process.

4. Managing Risks of Changing Core Systems/Infrastructure:

4.1 Risk Assessment:

Before making changes to core systems or infrastructure, conduct a thorough risk assessment. Identify potential risks, their impact, and likelihood. Classify risks based on severity and prioritize mitigation strategies.

4.2 Test Environment Validation:

Before implementing changes in the production environment, validate changes in a controlled test environment. Ensure that the proposed changes function as intended and do not introduce unforeseen issues.

4.3 Rollout and Monitoring:

Implement changes gradually, monitoring their impact in real-time. This approach allows for early detection of any adverse effects, enabling prompt intervention if necessary.

5. Recording Change Management:

5.1 Detailed Documentation:

Record all changes systematically, maintaining detailed documentation. This includes the rationale for the change, implementation steps, and results of post-implementation reviews. This documentation serves as a reference for future assessments and audits.

6. 3-Step Rollback Process:

6.1 Identification of Issues:

In case of unexpected issues or adverse effects post-implementation, promptly identify the root cause of the problem.

6.2 Rollback Decision:

Based on the severity of the issues, make a decision to initiate the rollback process. This decision should involve cross-functional collaboration to assess the impact on operations.

6.3 Execution of Rollback:

Execute the rollback process following the documented steps. Perform thorough QA on affected features and general smoke tests. Communicate the rollback status to stakeholders, and conduct a post-rollback review to identify lessons learned for continuous improvement.

7. Regular Policy Review and Updates:

7.1

Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence.

No items found.