PCI DSS v4.0: the clauses the checker cites
The 4 PCI DSS v4.0 clauses behind the findings, each with the evidence an auditor asks for where it is held.
Summarised: a one-line statement of what the requirement asks. The standard's own text is not held in full here, so it is not quoted.
4 clauses
PCI DSS 6.2.3 Custom software reviewed prior to productionBespoke and custom software is reviewed before release to production by someone other than the developer who wrote it, using manual and automated methods.
A one-line statement; the standard's own text is not quoted here.
Where it usually falls short: Self-approval of pull requests; SAST not blocking on findings
Source: PCI DSS v4.0
PCI DSS 6.5.1 Change control procedures in productionChanges to system components in production follow a set procedure that records the reason for the change, its security impact, a documented approval, testing and a way back.
A one-line statement; the standard's own text is not quoted here.
Source: PCI DSS v4.0
PCI DSS 6.5.2 Requirements confirmed after a significant changeAfter a significant change, the applicable PCI DSS requirements are confirmed in place on the new or changed systems and the documentation is updated.
A one-line statement; the standard's own text is not quoted here.
Source: PCI DSS v4.0
PCI DSS 6.5.4 Roles separated between production and pre-productionRoles and functions are separated between production and pre-production so that only reviewed and approved changes are deployed.
A one-line statement; the standard's own text is not quoted here.
Source: PCI DSS v4.0