{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Secure Development (SDLC) & Application Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-07","description":"Evaluate, prioritize, and authorize all IT changes, including emergency changes, before implementation, with documented impact and risk assessment. Establish acceptance criteria, perform acceptance testing in an environment representative of production, obtain business and IT approval, and promote releases through a controlled, auditable transition with fallback plans and post-implementation review.","details":{"control_category":"administrative","control_type":"preventive","domain":"Secure Development (SDLC) & Application Security","guidance":[],"members":[{"control_id":"BAI06","coverage":"full","framework":"cobit-2019","relationship":"superset_of"},{"control_id":"BAI07","coverage":"full","framework":"cobit-2019","relationship":"superset_of"}],"statement":"Evaluate, prioritize, and authorize all IT changes, including emergency changes, before implementation, with documented impact and risk assessment. Establish acceptance criteria, perform acceptance testing in an environment representative of production, obtain business and IT approval, and promote releases through a controlled, auditable transition with fallback plans and post-implementation review.","title":"Approve, test, and accept changes before production release","unified_id":"UC-SDLC-07"},"id":"uc:UC-SDLC-07","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-07","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"UC-SDLC-07 — Approve, test, and accept changes before production release","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:01001ca64d4a07b32dc70644efba5e9d543b11d2731d0225ae79ebdb10d7a0c4","properties":{"rationale":"Authorizing, impact-assessing and acceptance-testing every change before implementation directly prevents unapproved/untested changes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:04d6465fc189092981deb68deb58d39bf183a1e7c2645782f00afca09a7553c1","properties":{"rationale":"Acceptance criteria and testing against business/IT specifications catch defective designs before release.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/risk-ops-product-flaws-design-model-error-0c5e23f4.json","targetId":"risk:ops-product-flaws-design-model-error","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3118846bde05925832b05ae30e8a080af657a12ebc16ac71aaa70906f2d77059","properties":{},"sourceDetailPath":"/data/v1/records/wf-c75-3dd1badd.json","sourceId":"wf:C75","targetDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","targetId":"uc:UC-SDLC-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5c387d2afbbbdc6643c54027a7bb08b33da3636e9f9637df65639f0dc1b9546a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c77-2c09e1aa.json","sourceId":"wf:C77","targetDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","targetId":"uc:UC-SDLC-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b77867031d10a61002e0f22ef08c77ce0a0f60840dd00a21b7063be0d2787f8","properties":{},"sourceDetailPath":"/data/v1/records/wf-c79-423d98cd.json","sourceId":"wf:C79","targetDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","targetId":"uc:UC-SDLC-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8fdc7830079a5918f12dfa65dd2161ce222fcb194b0dc79ac6ab41841a9a5717","properties":{"control_id":"BAI06","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai06-306e8a70.json","targetId":"ctrl:cobit-2019:BAI06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:923389049fc97b8dff556664779a88dad851800b75a3c5ad33c406b921fa29a1","properties":{"rationale":"Pre-release acceptance testing catches functional and security defects before production.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:96fe8cd5e6550663eb4ec5bf19b88679bf108221016937cf868e836905365c8f","properties":{"control_id":"BAI07","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai07-dcabfa26.json","targetId":"ctrl:cobit-2019:BAI07","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c1979d510e8abd1d9d5e1d1405a0c98748c0a808e93046c5145769722259af35","properties":{"rationale":"Acceptance testing in a production-representative environment catches interface mismatches and integration config errors, but is not the operative defense against emergent, test-unpredictable AI behaviour.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/risk-ai-emergent-integration-risk-8490271c.json","targetId":"risk:ai-emergent-integration-risk","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c288b5fa59af264e81367eb93f76842e6cb8849271e703a0f26e6f15a9c30406","properties":{"rationale":"Acceptance testing in a production-representative environment plus fallback plans prevent failed releases and release-induced outages.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/risk-tech-software-system-failure-2e2c5364.json","targetId":"risk:tech-software-system-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb6788d6960de6d8961af645a8f1e3b138fb9c8dff5eeab9926f9359797e7faa","properties":{},"sourceDetailPath":"/data/v1/records/wf-s5-a655abf2.json","sourceId":"wf:S5","targetDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","targetId":"uc:UC-SDLC-07","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f2c816489faa7b3d7c854a41723a32f75cb9decb7945ab3b3dde36825745dbd2","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","targetId":"uc:UC-SDLC-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff8dabc6f297d93840a289d21d8c8d9e1bc7ae983cde983730b0d0506d394e86","properties":{"rationale":"A mandatory acceptance-test gate prevents inadequately-tested software from reaching production.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"}],"schemaVersion":1}
