Control · CHG-03
Developers have no standing production access; deployments via pipeline only
Change ManagementSOC 2 · ISO 27001 · ITGC · RBIRisk High
Requirement to validation
Requirement
ISO-A.8.31 · ITGC-CM-03 · RBI-ITGRCA-2023-7.4 · SOC2-CC6.1 · SOC2-CC8.1
mapped
Policy
Change Management Policy
pol-change
Control
CHG-03
Developers have no standing production access; deployments via pipeline only
Application
Amazon Web Services (ap-south-1) · GitHub Enterprise Cloud
mapped
Evidence · Q3
3 items
2 approved · 1 pending · 0 rejected
Test · Q3
Pass
TST-ITGC-CHG-03 · High confidence
Finding
F-IAQ2-CHG-03 · High
Closed
Action
Aditya Singh
REM-F-IAQ2-CHG-03 · Closed
Validation
Validated
as recorded
What should be true
Production deployments to AWS run only through the GitHub Actions pipeline with protected environments; developers have no standing write access to production accounts.
- Requirements
- ISO-A.8.31 A.8.31 · Separation of development, test and production environmentsITGC-CM-03 ITGC-CM-03 · Segregation between development and productionRBI-ITGRCA-2023-7.4 RBI-ITGRCA-2023 §7.4 · Change and patch management — documented, approved and tested changes (RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023)SOC2-CC6.1 CC6.1 · Logical access security software, infrastructure and architecturesSOC2-CC8.1 CC8.1 · Authorizes, designs, tests, approves and implements changes
- Third parties
- —
- Testing procedure
- GitHub environments + OIDC deploy role; IAM permission set design. Tests: GitHub Enterprise Cloud: Production environment requires reviewers; Amazon Web Services (ap-south-1): No developer roles with prod write. Frequency continuous.
Findings (1)
| Finding | Observation | Control | Applications | Severity | Status | Owner | Action | Validation |
|---|---|---|---|---|---|---|---|---|
| F-IAQ2-CHG-03 | Developers held standing production access | CHG-03 | Amazon Web Services (ap-south-1), GitHub Enterprise Cloud | High | Closed | Aditya Singh | REM-F-IAQ2-CHG-03 · Closed | Validated |
Evidence (5)
| Evidence | Title | Control | Source system | Collected | Status |
|---|---|---|---|---|---|
| ITGC-REQ-025 | GitHub: Production environment requires reviewers | CHG-03 | 5 Oct 2026 | Accepted | |
| ITGC-REQ-026 | AWS: No developer roles with prod write | CHG-03 | 4 Oct 2026 | Accepted | |
| Q2-EV-020 | GitHub Enterprise Cloud · system export (Q2) | CHG-03 | GitHub Enterprise Cloud | 7 Jun 2026 | Rejected |
| Q2-EV-021 | Amazon Web Services (ap-south-1) · configuration report (Q2) | CHG-03 | Amazon Web Services (ap-south-1) | 12 Jun 2026 | Rejected |
| SOC2-REQ-024 | GitHub: Production environment requires reviewers | CHG-03 | 7 Oct 2026 | Under review |
Tests (2)
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-ITGC-CHG-03 | CHG-03 · Developers have no standing production access; deployments via pipeline only | Q3 2026 Unified Program Review | 3 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit | Pass | High |
| TST-Q2-CHG-03 | CHG-03 · Developers have no standing production access; deployments via pipeline only | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |