Safeguard
Tag

change-management

Safeguard articles tagged "change-management" — guides, analysis, and best practices for software supply chain and application security.

8 articles

DevSecOps

A Required Approval Proves a Button Was Clicked, Not That Anyone Read the Code

Branch protection requires review before merge. Your audit evidence shows one on every pull request for a year. It does not show whether any of them involved a person reading the diff, and for a meaningful share, they did not.

Sep 18, 20266 min read
DevSecOps

A Feature Flag That Disables a Control Is a Control You Do Not Have

Added during an incident to skip a validation or bypass a limit, intended to be reverted that afternoon, and nothing reminds anyone. It lives in a system with weaker access control and no change record than your permission model.

Sep 18, 20266 min read
Application Security

The Migration Is the Riskiest Part of the Pull Request

It runs in production with the highest privileges in your system, usually unattended, and gets reviewed as an implementation detail at the bottom of the diff. It can drop a constraint that was the only thing enforcing a security property.

Sep 18, 20266 min read
Compliance

Your Pull Request Process Is Already Your Change Management

An auditor asks for change management evidence and the instinct is to build a change request form nobody will use. You already have the control, and it produces better evidence because it is generated by the work rather than alongside it.

Sep 18, 20266 min read
Software Supply Chain Security

Unapproved Change Risk in the Software Supply Chain

How unreviewed code, dependency, and pipeline changes create supply chain breaches like SolarWinds and XZ Utils - and how to detect them before attackers do.

Jul 7, 20268 min read
Compliance

SOC 2 Type II for Engineering Teams: What Auditors Actually Check

Auditors don't start with your policies — they sample your PRs, tickets, and access reviews. Here's what a SOC 2 Type II observation window actually tests, control by control.

Mar 18, 20266 min read
Regulatory Compliance

SOX IT Controls Meet Software Controls

Sarbanes-Oxley IT general controls predate modern software delivery. Here's how change management, access, and segregation of duties controls actually look when applied to CI/CD pipelines and software components.

Feb 27, 20267 min read
Compliance

ISO 27001 Annex A Controls That Touch Your Build Pipeline

ISO 27001:2022 has 93 Annex A controls, and about a dozen land squarely on CI/CD. Here's the control-by-control map from clause number to pipeline artifact.

Feb 19, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.