A SOC 2 auditor tests whether the organization's change management process requires approval before deployment to production. This test most directly supports which control objective?
-
A
Ensuring system availability during updates
-
B
Preventing unauthorized or untested changes from compromising security and integrity
-
C
Validating that all changes are encrypted before deployment
-
D
Confirming that vendors are notified of all system changes