The IS auditor should review the processes for making changes to cloud environment specifications, as these are the inputs for the predefined automated procedures that deploy and configure the application infrastructure. The IS auditor should verify that the changes are authorized, documented, tested, and approved before they are applied to the cloud environment. The IS auditor should also check that the changes are aligned with the business requirements and do not introduce any security or performance issues. References ISACA CISA Review Manual, 27th Edition, page 254 Configuration Management in Cloud Computing - ScienceDirect Cloud Configuration Management - BMC Software