← PCI DSS 4.0.1 · Req 6 — Secure systems and software

6.5 — Change management and separation of environments

high change-managementsegregation

Requirement

Changes to system components are made through documented change procedures including impact assessment, approval, testing and back-out; pre-production environments are separated from production with access controls; and live PANs are not used in pre-production environments.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
change managementchange controlchange requestchanges to productionproduction changespull requestchange procedureschange proceduredocumented change
Required element 2 — any one of
approv…testedtestingback-outrollbackroll backimpact
Required element 3 — any one of
separat…pre-productionpreproductionstagingtest environmentlive panlive card dataproduction data
Supporting terms — specificity signals
6.5.16.5.36.5.56.5.6separation of dutiestest data
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

live card data is used in testing production card data in test

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
SOC 2 CC3.4 Assessment of significant change change-management
SOC 2 CC8.1 Authorised change management change-management
ISO 27001 A.5.3 Segregation of duties segregation
ISO 27001 A.8.22 Segregation of networks segregation
ISO 27001 A.8.31 Separation of development, test and production environments segregation
ISO 27001 A.8.32 Change management change-management
GLBA 314.4(c)(7) Change management change-management
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorised logical access segregation