Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: Procedural Issues

Subject: Re: Procedural Issues
Date: Fri, 15 Jun 2007 22:30:50 +0400
It's not noise kurt, the issue indeed started about 4 months ago but I am still stuck with some finer details and hence re-posted under the same thread.

Thanks for the reply.

Mine is not near to even a mid-scale production environment with about 6 people in all but working on a highly sensitive inhouse financial/HR application.

Auditors demand that bring about some controls of duties within our development environment. I am trying to do the best and then declare the accepted risk.


At 02:39 PM 6/13/2007 -0700, Kurt Buff wrote:
Sorry for the noise - I was looking in my gmail threaded view, and
didn't notice the dates.

Kurt

On 6/13/07, Kurt Buff <kurt.buff@gmail.com> wrote:
In a full-on, large-scale production environment, code moves something
like this:

Dev
Test
Staging
Production

Each stage has its own set of admins/support staff, who are
responsible for placing the approved software from the previous stage
into their environment, according to their individual requirements.

Kurt

On 1/8/07, WALI <hkhasgiwale@gmail.com> wrote:
> In a software development environment, what risks do we have if we allowed
> software development team leader, access to Live production servers?
>
> Security demands that the two environments be segregated.
>
> If I segregate the two environments, who would shift the code from
> development to Live?
>
>
> ---------------------------------------------------------------------------
> This list is sponsored by: ByteCrusher
>
> Detect Malicious Web Content and Exploits in Real-Time.
> Anti-Virus engines can't detect unknown or new threats.
> LinkScanner can. Web surfing just became a whole lot safer.
>
> http://www.explabs.com/staging/promotions/xern_lspro.asp?loc=sfmaildetect
> ---------------------------------------------------------------------------
>
>

<Prev in Thread] Current Thread [Next in Thread>