← PCI DSS 4.0.1 · Req 6 — Secure systems and software
6.5 — Change management and separation of environments
Requirement
Changes to system components are made through documented change procedures including impact assessment, approval, testing and back-out; pre-production environments are separated from production with access controls; and live PANs are not used in pre-production environments.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| SOC 2 | CC3.4 | Assessment of significant change | change-management |
| SOC 2 | CC8.1 | Authorised change management | change-management |
| ISO 27001 | A.5.3 | Segregation of duties | segregation |
| ISO 27001 | A.8.22 | Segregation of networks | segregation |
| ISO 27001 | A.8.31 | Separation of development, test and production environments | segregation |
| ISO 27001 | A.8.32 | Change management | change-management |
| GLBA | 314.4(c)(7) | Change management | change-management |
| NIST CSF 2.0 | PR.IR-01 | Networks and environments are protected from unauthorised logical access | segregation |