Test · TST-ITGC-CHG-03
CHG-03 · Developers have no standing production access; deployments via pipeline only
PassQ3 2026 Unified Program ReviewTested 3 Oct 2026 by Vikram Mehta, Farah Khan · Meridian Internal Audit
Requirement to validation
Requirement
ISO-A.8.31 · ITGC-CM-03 · RBI-ITGRCA-2023-7.4 · SOC2-CC6.1 · SOC2-CC8.1
mapped
Policy
Change Management Policy
pol-change
Control
CHG-03
Developers have no standing production access; deployments via pipeline only
Application
Amazon Web Services (ap-south-1) · GitHub Enterprise Cloud
mapped
Evidence · Q3
3 items
2 approved · 1 pending · 0 rejected
Test · Q3
Pass
TST-ITGC-CHG-03 · High confidence
Finding
F-IAQ2-CHG-03 · High
Closed
Action
Aditya Singh
REM-F-IAQ2-CHG-03 · Closed
Validation
Validated
as recorded
Procedure and result
- Procedure
- GitHub environments + OIDC deploy role; IAM permission set design. Tests: GitHub Enterprise Cloud: Production environment requires reviewers; Amazon Web Services (ap-south-1): No developer roles with prod write. Frequency continuous.
- Sample
- 2 items sampled (reperformance)
- Expected
- Production deployments to AWS run only through the GitHub Actions pipeline with protected environments; developers have no standing write access to production accounts.
- Observed
- Operating effectiveness confirmed for GitHub, AWS; no exceptions in 2 sample(s).
- Confidence
- High
- Evidence
- ITGC-REQ-025ITGC-REQ-026