Source control

Source control is where the record of who changed what lives, which makes it both a security control and a target.

Its history is evidence, its access decides who can alter what ships, and its integrations frequently hold credentials to everything else. Treating it as a developer convenience rather than as a system of record is how organisations end up unable to say whether a change was authorised.

Checked against the primary source.

More on Software supply chain & DevSecOps