Change Request

An official, documented request to alter a project document, a deliverable, or an approved baseline.

Key Points

  • Must be documented and submitted for review through the change control process.
  • May propose corrective or preventive actions, defect repairs, or updates to project documents.
  • Changes to a baseline require approval before implementation.
  • Should include impact analysis on scope, schedule, cost, quality, and risk.

Example

After scope is baselined, a client asks for an extra reporting feature. The project manager prepares a change request detailing impacts on schedule and cost and submits it to the change control board for a decision before any work begins.

PMP Example Question

A stakeholder asks to add functionality after the scope baseline is approved. What should the project manager do next?

  1. Implement the change if it increases business value.
  2. Have the team estimate and start the work immediately.
  3. Submit a formal change request for evaluation through change control.
  4. Update the risk register and proceed with the change.

Correct Answer: C — Submit a formal change request

Explanation: Once baselines are approved, any modification must go through the formal change control process and be approved before implementation.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course