Test · TST-Q2-CHG-03
CHG-03 · Developers have no standing production access; deployments via pipeline only
FailQ2 2026 Unified Program ReviewTested 18 Jun 2026 by Farah Khan, Vikram Mehta · Meridian Internal Audit
Requirement to validation
Requirement
ISO-A.8.31 · ITGC-CM-03 · RBI-ITGRCA-2023-7.4 · SOC2-CC6.1 · SOC2-CC8.1
mapped
Policy
Change Management Policy
pol-change
Control
CHG-03
Developers have no standing production access; deployments via pipeline only
Application
Amazon Web Services (ap-south-1) · GitHub Enterprise Cloud
mapped
Evidence · Q3
3 items
2 approved · 1 pending · 0 rejected
Test · Q3
Pass
TST-ITGC-CHG-03 · High confidence
Finding
F-IAQ2-CHG-03 · High
Closed
Action
Aditya Singh
REM-F-IAQ2-CHG-03 · Closed
Validation
Validated
as recorded
Procedure and result
- Procedure
- GitHub environments + OIDC deploy role; IAM permission set design. Tests: GitHub Enterprise Cloud: Production environment requires reviewers; Amazon Web Services (ap-south-1): No developer roles with prod write. Frequency continuous.
- Sample
- 25 items sampled (Q2 baseline)
- Expected
- Production deployments to AWS run only through the GitHub Actions pipeline with protected environments; developers have no standing write access to production accounts.
- Observed
- Five developers retained console access to the production EKS cluster outside the deployment pipeline.
- Confidence
- High