Change Request(s)

A change request is the usual mechanism for proposing a modification to the project or product. It remains pending and has no effect until it is formally reviewed and approved.

Key Points

  • Used to propose changes to scope, schedule, cost, quality, requirements, deliverables, or project documents.
  • Should be documented with justification and impact analysis, then routed through the agreed change control process (e.g., CCB or product governance).
  • Status is tracked (submitted, under review, approved, rejected, deferred); only approved requests are implemented and baselines updated.
  • In agile environments, approved changes often become prioritized backlog items; governance still applies before altering commitments or baselines.

Example

A stakeholder asks mid-project to add a new compliance report. The project manager logs a change request, the team estimates schedule and cost impact, and the CCB reviews it. After approval, the plan and baselines are updated and the work is scheduled for the next iteration; if rejected, no change is made.

PMP Example Question

Which statement best describes a change request?

  1. It is implemented immediately to avoid delays.
  2. It is a formal proposal that must be reviewed and approved before any change is made.
  3. It is used only when defects are found during testing.
  4. It is optional documentation for minor scope adjustments.

Correct Answer: B — A formal proposal requiring approval before implementation

Explanation: Change requests are formal proposals and have no effect until approved; they are not immediate, not limited to defects, and are not optional for minor changes unless governance explicitly allows it.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Lead with clarity, influence, and outcomes.

HK School of Management offers a practical Leadership for Project Managers course for real projects, tight deadlines, and cross-functional teams. Learn to set direction, align stakeholders, and drive commitment without relying on title. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Learn More