Re: Securing Development in a production environment



On 2007-08-30 Anthony Cogan wrote:
We have a number of issues over the past year where developers were
running FTP servers, anonymous file shares (with confidential data
and no ACL's) and other very insecure methods.

Their workstations are in the process of being replaced and are being
provided a locked down (least privilege user) environment. A small
vocal group says they can not work this way and MUST have local
administrative rights to their box.

They're right. Developers should have local admin privileges on their
workstations. Their workstations, however, should be placed in a
separate network segment with NO access whatsoever to the production
network.

They have been provided virtual machines running W2k03 Server joined
to our production domain (yeah, I said that right).

Bad idea. Really, REALLY bad idea. Don't do it. Developers should be
provided a testing environment that resembles your production
environment closely enough, but never EVER mix development and
production environment.

Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq



Relevant Pages

  • How to limit access to production data from non-production code?
    ... We also have production and test databases. ... The developers are allowed to write into the user-testing directories, ... user-test environment to try new code. ... The history here is the developers would put new code in the user-test ...
    (comp.os.vms)
  • Re: Development - Production Data Access
    ... Development (developers have extensive access levels) ... Production ... I fully agree with David's view that you need a test environment ...
    (comp.databases.ms-sqlserver)
  • Re: Development - Production Data Access
    ... Development (developers have extensive access levels) ... Production ... > Our environment and budget only allows for items 1 and 3. ...
    (comp.databases.ms-sqlserver)
  • Re: Application "deployment" tool?
    ... ties in with SVN would be fantastic. ... environment and how things are managed. ... a UAt/QA/testing environment and the production ... create a release tag when new code is bundled up for promotion to uat ...
    (comp.databases.oracle.server)
  • Re: Splitting an DFSMShsm environment
    ... restore on the test system to an empty newly created HSM environment to ... I like this one as it leaves your production ... For IBM-MAIN subscribe / signoff / archive access instructions, ... send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO ...
    (bit.listserv.ibm-main)