Policy 02  PRIORITY

Change Management Policy
PCI DSS Req 6.5  ·  the rule Revique must follow
← All 21 policies
This page is the rule, not the implementation. It states what Revique must do, at or above the PCI DSS minimum. How Revique actually does it today — the real AWS configuration, the current values, and where an auditor logs in to verify them — is in Procedure 02. Values shown as [X] are placeholders still to be set.

Purpose

To ensure that every change to Revique's applications, systems, and infrastructure is reviewed, approved, tested, and documented before it reaches production — preventing unauthorized, untested, or destabilizing changes.

Scope

Applies to all changes to code, configuration, infrastructure, and network components across UAT and production environments, made by any employee, contractor, or automated pipeline.

Policy statements

Each statement below is mandatory. The bolded must marks the obligation.

1Every change must have a documented request describing the change, its reason, and its impact before implementation.
2Every change to production must receive documented approval from an authorized approver before deployment.
3Production deployments must pass through a defined pipeline with a manual approval gate; no change may bypass this gate.
4Every change must be tested in a non-production (UAT) environment before promotion to production, where feasible.
5Every change record must include a rollback or back-out plan.
6Emergency changes must follow an expedited but still-documented approval process and be reviewed retrospectively within [X] business days.
7All change records must be retained for at least [X] months for audit purposes.

Roles & responsibilities

RoleResponsibility
Change RequesterSubmit a complete, documented change request with impact and rollback plan.
Change ApproverReview and formally approve or reject changes before production deployment.
DevOps / EngineeringImplement approved changes through the controlled pipeline only.

Enforcement

This policy is issued under the authority of Policy 01 — Information Security Policy and is mandatory for everyone in scope. Compliance is verified through the controls and evidence described in the linked procedure. Failure to comply may result in withdrawal of access and disciplinary action. This policy is reviewed at least annually, or sooner on significant change.

⚙️See the Procedure for this policyHow Revique implements this rule today, the current values, the gaps, and the auditor verification path→
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.