Explanation Change control is the process of ensuring that changes to an information system are authorized, tested, documented and implemented in a controlled manner. Inadequate change control can result in deficient technical security controls, such as missing patches, misconfigurations, vulnerabilities or errors in the new application. References = CISM Review Manual, 27th Edition, Chapter 4, Section 4.3.2, page 2291