To ensure that every change to Revique's applications, systems, and infrastructure is reviewed, approved, tested, and documented before it reaches production — preventing unauthorized, untested, or destabilizing changes.
Applies to all changes to code, configuration, infrastructure, and network components across UAT and production environments, made by any employee, contractor, or automated pipeline.
Each statement below is mandatory. The bolded must marks the obligation.
| Role | Responsibility |
|---|---|
| Change Requester | Submit a complete, documented change request with impact and rollback plan. |
| Change Approver | Review and formally approve or reject changes before production deployment. |
| DevOps / Engineering | Implement approved changes through the controlled pipeline only. |
This policy is issued under the authority of Policy 01 — Information Security Policy and is mandatory for everyone in scope. Compliance is verified through the controls and evidence described in the linked procedure. Failure to comply may result in withdrawal of access and disciplinary action. This policy is reviewed at least annually, or sooner on significant change.
⚙️See the Procedure for this policyHow Revique implements this rule today, the current values, the gaps, and the auditor verification path→