Identify the policy document requiring that all custom application code changes must be reviewed.
Describe the documented processes used for reviewing custom application code changes (for example, manual or automated, or a combination of both).
Identify the documents which define processes for custom application code reviews, and confirm the documented processes require the following:
i. All custom application code changes are reviewed.
ii. Code changes are reviewed by individuals other than the original author.
iii. Code changes are reviewed by individuals who are knowledgeable in code review techniques.
iv. Code changes are reviewed by individuals who are knowledgeable in secure coding practices.
v. Code reviews ensure secure coding guidelines have been followed.
vi. Any corrections identified during the code review are implemented prior to release.
vii. Code review results are reviewed by management prior to release.
viii. Code review results are approved by management prior to release.