
Objective: To maintain the security of application system software and information.
Control
The implementation of changes shall be controlled by the use of formal change control procedures.
Control
When operating systems are changed, business critical applications shall be reviewed and tested to ensure there is no adverse impact on organizational operations or security.
Control
Modifications to software packages shall be discouraged, limited to necessary changes, and all changes shall be strictly controlled.
Control
Opportunities for information leakage shall be prevented.
Control
Outsourced software development shall be supervised and monitored by the organization.
© Copyright Castleforce 2007-2012. Web design by Theme Group