What security reviews should occur during the maintenance phase of the software/system development lifecycle? In other words, what types of modifications to a SOX scoped application should cause security review & sign-off? How do you document that a “trip point” has been reached to cause the event to occur?
Thanks