change-management
Safeguard articles tagged "change-management" — guides, analysis, and best practices for software supply chain and application security.
8 articles
A Required Approval Proves a Button Was Clicked, Not That Anyone Read the Code
Branch protection requires review before merge. Your audit evidence shows one on every pull request for a year. It does not show whether any of them involved a person reading the diff, and for a meaningful share, they did not.
A Feature Flag That Disables a Control Is a Control You Do Not Have
Added during an incident to skip a validation or bypass a limit, intended to be reverted that afternoon, and nothing reminds anyone. It lives in a system with weaker access control and no change record than your permission model.
The Migration Is the Riskiest Part of the Pull Request
It runs in production with the highest privileges in your system, usually unattended, and gets reviewed as an implementation detail at the bottom of the diff. It can drop a constraint that was the only thing enforcing a security property.
Your Pull Request Process Is Already Your Change Management
An auditor asks for change management evidence and the instinct is to build a change request form nobody will use. You already have the control, and it produces better evidence because it is generated by the work rather than alongside it.
Unapproved Change Risk in the Software Supply Chain
How unreviewed code, dependency, and pipeline changes create supply chain breaches like SolarWinds and XZ Utils - and how to detect them before attackers do.
SOC 2 Type II for Engineering Teams: What Auditors Actually Check
Auditors don't start with your policies — they sample your PRs, tickets, and access reviews. Here's what a SOC 2 Type II observation window actually tests, control by control.
SOX IT Controls Meet Software Controls
Sarbanes-Oxley IT general controls predate modern software delivery. Here's how change management, access, and segregation of duties controls actually look when applied to CI/CD pipelines and software components.
ISO 27001 Annex A Controls That Touch Your Build Pipeline
ISO 27001:2022 has 93 Annex A controls, and about a dozen land squarely on CI/CD. Here's the control-by-control map from clause number to pipeline artifact.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.