Skip to main content

Understanding Version Control

Written by Brady Price

What is DevOps?

Version control keeps a history of code and config changes so teams can review, roll back, and prove how changes were made. Auditors often look for this as part of change management and secure development practices.

Requirements for DevOps compliance:

  • Changes are tested prior to deployment to production.

  • Changes are independently reviewed prior to deployment to production.

  • Changes are being documented and tracked.

  • Appropriate personnel have access to change repositories and source code.

  • Processes are in place for handling emergency code fixes.

Note: SOC 2 does not specifically require a second human approver on every change. Auditors look for changes that are authorized, tested, and tracked under a process you define. Solo-engineer teams often use required PRs plus green CI, with the process documented in policy. Confirm acceptance with your CPA firm. See FAQs: SOC 2 for single-engineer and zero-approval scenarios.


What DevOps tools does Secureframe integrate with?

tools.png

How to configure test start data for version control?

Since Pull Requests (PRs) should not be altered after they have been merged to production, it's likely your organization will have historical PRs that did not follow compliance requirements. When testing PRs for compliance purposes, it's best to choose a sample selection date that falls after the implementation date so you do not return outdated results.

To change the date from which our integration pulls its results, follow these steps:

  1. On the Monitoring dashboard, click Integrations in the left navbar.

  2. On the Integrations page, scroll down to find the row for the connected integration you'd like to configure.

  3. Click Settings.

  4. Click the Testing start date field to adjust the date.

Did this answer your question?