What to Provide
System screenshots or a system-generated list of users that have access and authority to deploy production changes.
System screenshots demonstrating that branch protection rules are in place for production repositories which require a separate approval before merging, and disallow direct commits to the branch without use of pull requests.
NOTE: If branch protection rules on production repositories are not enabled or are not configured appropriately, the audit team will validate that a sample of production software/infrastructure changes were approved by at least one individual other than the originating code author prior to production deployment. See ER-62 for guidance.
Evidence Format
Exported document in a common file type such as .docx, .csv, or .pdf or screenshots or exported images in a common image file type such as .jpg, .png, or .pdf.
Associated Unified Control ID | Associated Framework Control |
CTRL-65 | LCL-54 |