A Change Workflow With a Paper Trail
Every change to a system in scope — a firewall rule, a new application, a server rebuild, an access modification — is entered as a change request describing what is changing, why, and which systems are affected. The request moves through defined states: submitted, reviewed, approved or rejected, implemented, and closed. Nothing is approved without a record of who approved it and when, and nothing is closed without confirmation that the change was completed as described.
That workflow is the difference between making changes and managing them. When an assessor examines CM.L2-3.4.3, they are looking for evidence that changes are controlled rather than ad hoc — a documented request, a review, an approval, and a log. The module produces that evidence as a byproduct of the work, not as a separate documentation exercise.