SOX Change Log Checker
Clause text

PCI DSS v4.0: the clauses the checker cites

The 4 PCI DSS v4.0 clauses behind the findings, each with the evidence an auditor asks for where it is held.

Summarised: a one-line statement of what the requirement asks. The standard's own text is not held in full here, so it is not quoted.

4 clauses

PCI DSS 6.2.3 Custom software reviewed prior to production

Bespoke and custom software is reviewed before release to production by someone other than the developer who wrote it, using manual and automated methods.

A one-line statement; the standard's own text is not quoted here.

Evidence an auditor expects: Pull request review evidence with reviewer name; SAST scan results per release; Code review checklist; Issue tracker showing remediation; Approval gate before deployment
Where it usually falls short: Self-approval of pull requests; SAST not blocking on findings
Source: PCI DSS v4.0
PCI DSS 6.5.1 Change control procedures in production

Changes to system components in production follow a set procedure that records the reason for the change, its security impact, a documented approval, testing and a way back.

A one-line statement; the standard's own text is not quoted here.

The evidence list held against this requirement belongs to a different control, so none is shown.
Source: PCI DSS v4.0
PCI DSS 6.5.2 Requirements confirmed after a significant change

After a significant change, the applicable PCI DSS requirements are confirmed in place on the new or changed systems and the documentation is updated.

A one-line statement; the standard's own text is not quoted here.

The evidence list held against this requirement belongs to a different control, so none is shown.
Source: PCI DSS v4.0
PCI DSS 6.5.4 Roles separated between production and pre-production

Roles and functions are separated between production and pre-production so that only reviewed and approved changes are deployed.

A one-line statement; the standard's own text is not quoted here.

The evidence list held against this requirement belongs to a different control, so none is shown.
Source: PCI DSS v4.0