Framework
ISO/IEC 27001:2022: what it asks of a production change
Annex A of ISO/IEC 27001:2022 carries change management (8.32), segregation of duties (5.3), secure development (8.25), separation of environments (8.31), access to source code (8.4), configuration management (8.9), software installation (8.19) and security testing (8.29).
Our statement of each clause, read against the copy we hold and cited to it; it is not the instrument's verbatim wording.