Security review of code is formally required before it is released to production
Among A.5.1's topic-specific policies, Sekit's Secure code review policy requires a security-focused review of every code change before it reaches production.
This policy facet requires a security-focused review on every code change before release, one of the concrete practices A.8.25 expects.
The Sekit policy requires a security-focused review before release, one of the testing activities this ISO control requires during development and before acceptance.