RE: Procedural Issues
- From: "Dave Lewis" <dlewis@xxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 12 Jun 2007 17:24:55 -0600
We chose AccuRev over VSS for productivity reasons which greatly
outweighed the cost. Support has been great and implementation went very
smooth.
Dave Lewis
IT Manager
Security Connections, Inc.
www.security-connect.com
-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of WALI
Sent: Tuesday, June 12, 2007 1:47 PM
To: Shahin Ansari; Kenton Smith; security-basics@xxxxxxxxxxxxxxxxx
Subject: Re: Procedural Issues
Hi
Coming back to this issue which is about 4 months old, I am at the verge
of
finalizing finer details of our SDLC lifecycle.
I am stuck at one point and seek your help. I am about to deploy Visual
SourceSafe as my Version Control tool.
I need to define databases, folders and rights within VSS. What should
they
typically be. There has to be a Configuration manager within VSS. Who
shuld
this be?
Shahin, you wrote that there are static and dynamic versions of SoD!!
Please elaborate a bit for my benefit.
Kenton, I don't have many guys on board but have just managed to higher
a
QA function. Can QA shift the code after UAT to production environment?
What are the risks associated with doing so?
At 01:02 PM 1/9/2007 -0800, Shahin Ansari wrote:
Role Based Access Control model addresses issues like this. You maywant
to grant approval power to the Development team lead using a higheror
previlage role, and not give him freedoms like deleting files, writing,
other previlage he/she normally enjoy. This is called separation ofcertainly
duties, and there is static and dynamic versions of it. Hope it helps.
Regards-
Sean
Kenton Smith <listsks@xxxxxxxx> wrote:
Security is all about mitigating risk. You're right, there are
risks associated with someone from development accessing productionaccess
servers, however that is less risk than having all developers with
to production environments. Some risks that might come up would beaccess
unauthorized changes to production, accidental deletion of files,
to confidential information.
In our company, it is our QA manager along with the VP Development that
have to sign off on the code before it moves from development todoesn't
production. We also have an integration group who are the people that
actually have acess to the production servers, so the QA manager
actually deploy the changes to production. Our company obviously has away.
bigger infrastructure and because of business reasons we do it this
However you may find that the risks are so small relative to thethe
additional staff needed that it makes more sense to put the trust in
development team lead to work with the production servers.best
It's not a simple yes/no decision, it really comes down to what works
in your environment while incurring the least amount of risk.allowed
Kenton
----- Original Message ----
From: WALI
To: security-basics@xxxxxxxxxxxxxxxxx
Sent: Monday, January 8, 2007 10:50:28 AM
Subject: Procedural Issues
In a software development environment, what risks do we have if we
software development team leader, access to Live production servers?----
Security demands that the two environments be segregated.
If I segregate the two environments, who would shift the code from
development to Live?
-----------------------------------------------------------------------
This list is sponsored by: ByteCrusherct
Detect Malicious Web Content and Exploits in Real-Time.
Anti-Virus engines can't detect unknown or new threats.
LinkScanner can. Web surfing just became a whole lot safer.
http://www.explabs.com/staging/promotions/xern_lspro.asp?loc=sfmaildete
---------------------------------------------------------------------------
----
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
-----------------------------------------------------------------------
This list is sponsored by: ByteCrusherct
Detect Malicious Web Content and Exploits in Real-Time.
Anti-Virus engines can't detect unknown or new threats.
LinkScanner can. Web surfing just became a whole lot safer.
http://www.explabs.com/staging/promotions/xern_lspro.asp?loc=sfmaildete
---------------------------------------------------------------------------
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
- Follow-Ups:
- Re: Procedural Issues
- From: security.xentek
- Re: Procedural Issues
- References:
- Re: Procedural Issues
- From: WALI
- Re: Procedural Issues
- Prev by Date: RE: MS Virtual Server- SW Development Scenario
- Next by Date: Secure file transfer
- Previous by thread: Re: Procedural Issues
- Next by thread: Re: Procedural Issues
- Index(es):
Relevant Pages
|