Change Management is an important security issue which requires controls which will monitor each phase of the change process so that management is aware of the requested change, its development, testing, approval and implementation.
Enhancements
Requests are made through the Ripple Treasury issue tracking system and assigned to the product team.
Accepted requests will be processed according to the Ripple Treasury Software Development Life Cycle (SDLC).
QA will sign off on the cycle as being complete and ready to move to other environments.
A request will be created to move the application patch to production and other environments and is assigned to the DevOps team. This only applies to non-scheduled releases.
The DevOps team will apply the patch to the requested environments according to internal procedures and notify interested parties accordingly.
Bugs
Bugs are documented in a ticket and assigned to the QA team.
The QA team will attempt to recreate the bug and, if successful, will assign the ticket to the Product team for investigation and prioritization.
Development items will be corrected and assigned back to the QA team for verification.
DevOps items will be corrected and assigned back to the requestor for verification.
Once verification has completed successfully, the ticket will be updated to request a move to the required target environment(s) and assigned to the DevOps team.
The DevOps team will schedule an appropriate time to apply the fix (based on the content, impact, availability, etc.), and apply as necessary.
The ticket will be assigned back to the requestor for closure.
Infrastructure Changes
Changes necessary for the ongoing maintenance of servers and general infrastructure will be documented in a ticket and assigned to the DevOps or IT team. Modifications necessary to facilitate the correct working of the systems and environment (such as restarting a service, rebooting a machine, etc.) in response to an alert do not require a ticket but the actions taken should be documented in the alert.
Standard changes (those that have low risk and low impact or are performed regularly e.g. windows patching) do not require approval.
Major changes (those that have high risk or high impact) require approval from DevOps/IT management.
Production Access
All Production access should be marked with a Windows event log entry identifying the reason (and ticket number if appropriate). Only the initial RDP access needs to be logged.
These event logs are automatically swept to an offsite log manager server (a service run by Alert Logic).
The Security & Compliance team will review logs daily and identify suspicious activity according to internal processes.
Any activity/access records that cannot be verified by internal logs or the Security & Compliance team are then further reviewed for a determination of whether that activity was legitimate.
Once verified, a comment is entered to justify the access/activity and the record is marked approved by the Security & Compliance team.
Copyright 2025 Ripple Labs Inc.
