Re: Developers Access in PROD

From: lindawie (lindawie@my-deja.com)
Date: 05/31/02


From: "lindawie" <lindawie@my-deja.com>
Date: Fri, 31 May 2002 00:27:31 -0700


Dinky,

> In your SQL Server shop, what kind of access has been
> given to application developers? ie. db_reader,
> db_owner, public etc...

Developers should only have as many permissions as they need.
If the development organization owns the development servers,
then developers can be in the db_owner role. They should not
have the sa password. This just causes more problems than
it solves. The QA organization decide how much access they
want to give to developers for the servers they own.

If I'm in charge of production, developers will not have
any access at all to production servers. If they have done
their jobs properly they don't need it, anyway. I'm willing
to make production backups available on a share for them to
copy over to their own servers. If the database contains any
sensitive data (financial, personal, business intelligence),
then the database goes through a "scrambler" first to replace
the real data with nonsense stuff, or developers don't get it.
Developers are a significant security risk in any organization,
so network administrators and dbas need to factor that into
their security model.

Linda



Relevant Pages

  • Re: VS 2005 questions
    ... can't use VS 2005 for a few years, but at least our developers can prepare ... because the applications must be hosted on military servers over which we ... Microsoft software is among the most mission-critical for them, ... because then developers could adopt VS 2005 more quickly. ...
    (microsoft.public.vsnet.general)
  • Re: warnings or -w ?
    ... my own stations are one under Windows and the second under ... developer send his work to all other developers for final check and (it ... And the Linux servers on which problem ... that in these Komodo settings, he (surely not volontarily because it has ...
    (comp.lang.perl.misc)
  • Re: Quality of FreeBSD
    ... >> I know the developers don't hear it often enough, ... Mainly NFS and Samba servers, ... Some special kind words go to Soren Schmidt here. ...
    (freebsd-stable)
  • Re: Windows 2000 - Read only access for developers.
    ... In the internal domain developers can already see the Event Viewer and COM+ ... need to see would typically have access denied from say the guest account. ... servers in order to effect this. ...
    (microsoft.public.win2000.general)
  • Re: P4 Xeon compatibility with 5.0.5
    ... How come it's so far behind Linux then, ... AND hardware support and SCO ... >the middle of the sweet spot of most developers interest. ... organiser, through 486 based robots, phones, up to 16 way servers (I ...
    (comp.unix.sco.misc)