6.3.2.a Obtain and review policies to confirm that all custom application code changes must be reviewed (using either manual or automated processes) as follows:
Code changes are reviewed by individuals other than the originating code author, and by individuals who are knowledgeable in code review techniques and secure coding practices.
Code reviews ensure code is developed according to secure coding guidelines (see PCI DSS Requirement 6.5).
Appropriate corrections are implemented prior to release.
Code review results are reviewed and approved by management prior to release.