unified
UC-ACCESS-16 — Authorize, test, and approve changes and development
Changes to applications and infrastructure, and new system development, follow a documented lifecycle: authorized request, risk-assessed design, testing in non-production environments, documented approval, and controlled migration to production by personnel independent of development. Emergency changes are ratified retrospectively, and evidence of each gate is retained.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Configuration & Change Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-16
- title
- Authorize, test, and approve changes and development
- statement
- Changes to applications and infrastructure, and new system development, follow a documented lifecycle: authorized request, risk-assessed design, testing in non-production environments, documented approval, and controlled migration to production by personnel independent of development. Emergency changes are ratified retrospectively, and evidence of each gate is retained.
- domain
- Secure Configuration & Change Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- soc1
- control_id
- SOC1-2
- coverage
- full
- relationship
- superset_of
- framework
- soc1
- control_id
- SOC1-3
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Security Control Assessment & POA&M Remediation tests UC-ACCESS-16 — Authorize, test, and approve changes and development
- SOX ITGC Testing tests UC-ACCESS-16 — Authorize, test, and approve changes and development
- UC-ACCESS-16 — Authorize, test, and approve changes and development maps_to SOC1-3 — Program development / SDLC — controls provide reasonable assurance that new systems and applications are developed, tested, approved, and implemented in accordance with management's intent.
- framework
- soc1
- control_id
- SOC1-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- SSAE 18 (current AICPA SOC suite)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-16 — Authorize, test, and approve changes and development mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- Requiring authorized, documented changes reduces the unauthorized changes that drive drift, though baseline monitoring is the operative control.
- Change & Release Management (CAB) operates UC-ACCESS-16 — Authorize, test, and approve changes and development
- UC-ACCESS-16 — Authorize, test, and approve changes and development mitigates Emergent behaviour and unsafe AI system integration
- strength
- primary
- rationale
- Pre-production testing and approval gates catch legacy-integration interface mismatches and configuration errors before they reach production.
- ITGC Change & Provisioning Testing tests UC-ACCESS-16 — Authorize, test, and approve changes and development
- UC-ACCESS-16 — Authorize, test, and approve changes and development mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Mandatory testing in non-production before approval/migration directly prevents releasing inadequately tested software to production.
- UC-ACCESS-16 — Authorize, test, and approve changes and development maps_to SOC1-2 — Change management — controls provide reasonable assurance that changes to applications and infrastructure are authorized, tested, approved, and migrated to production appropriately.
- framework
- soc1
- control_id
- SOC1-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- SSAE 18 (current AICPA SOC suite)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-16 — Authorize, test, and approve changes and development mitigates Absent or weak change-control procedures
- strength
- primary
- rationale
- The authorize->test->approve->independent-migration gate IS the change-control process, directly preventing unapproved or untested changes.