Skip to content
arrow_back
search
ISM-1419 policy ASD Information Security Manual (ISM)

Ensure Software Changes Occur in Development Environments

Software changes should only be done in a development environment to prevent issues in production.

record_voice_over

Plain language

When a company changes its software, it should only do so in a special area called a 'development environment' and not directly on the software that everyone uses every day. This is important because making changes on the live system can lead to unexpected problems or even outages, potentially costing money and reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Development and modification of software only takes place in development environments.
policy ASD Information Security Manual (ISM) ISM-1419
priority_high

Why it matters

Making software changes directly in production increases outage and data-loss risk and can bypass testing and approvals, causing service disruption and reputational damage.

settings

Operational notes

Restrict code changes to development environments; require change records and CI/CD promotion to test/UAT before production, and monitor for unauthorised production edits.

Mapping detail

Mapping

Direction

Controls