SOX Change Log Checker
Framework

COBIT: what it asks of a production change

COBIT is where the change-management detail behind a SOX IT general control is written down: BAI06 (manage IT changes) and BAI07 (manage change acceptance and transitioning), with DSS06.03 for roles and segregation of duties. It shows whenever SOX 404 is ticked.

Our statement of each clause, read against the copy we hold and cited to it; it is not the instrument's verbatim wording.

The findings it sits behind

9 clauses cited
FindingClause
No independent approvalCOBIT BAI06.01
Approved after it shippedCOBIT BAI06.01 · COBIT BAI07.06
Automated author, no human approvalCOBIT BAI06.01 · COBIT BAI03.08
Deployed their own changeCOBIT DSS06.03 · COBIT BAI07.06
One person, three rolesCOBIT DSS06.03
Emergency, no approval afterCOBIT BAI06.02
Deployment with no matching changeCOBIT BAI06.03 · COBIT BAI10.03
No ticket referenceCOBIT BAI06.01 · COBIT BAI06.04
Approver not on the listCOBIT DSS06.03
No test evidenceCOBIT BAI07.05 · COBIT BAI03.08

Every COBIT 2019 clause the checker cites

Run the specimen Check your own change log