SOX Change Log Checker
Framework

PCI DSS v4.0: what it asks of a production change

Requirement 6 of PCI DSS v4.0 covers bespoke software review (6.2.3) and change control in production (6.5.1 to 6.5.4). It applies to the systems in the cardholder data environment; name them in the preamble and PCI DSS clauses show on those rows only.

Summarised: a one-line statement of what the requirement asks. The standard's own text is not held in full here, so it is not quoted.

The findings it sits behind

4 clauses cited
FindingClause
No independent approvalPCI DSS 6.5.1 ยท PCI DSS 6.2.3
Approved after it shippedPCI DSS 6.5.4
Automated author, no human approvalPCI DSS 6.2.3
Deployed their own changePCI DSS 6.5.4
One person, three rolesPCI DSS 6.5.4
Emergency, no approval afterPCI DSS 6.5.1
Deployment with no matching changePCI DSS 6.5.2
No ticket referencePCI DSS 6.5.1
Approver not on the listPCI DSS 6.5.4
No test evidencePCI DSS 6.2.3

Every PCI DSS v4.0 clause the checker cites

Run the specimen Check your own change log