7 ms·
"staging environment to experiment with, that is an exact copy of your production database?" This seems to be problematic in several compliance schemes. Most w
by _Codemonkeyism 9y ago
"staging environment to experiment with, that is an exact copy of your production database?"
This seems to be problematic in several compliance schemes. Most will make sure developers,QA etc. do not get access to production data.
- craigkerstiens 9y agoCraig from Citus here. In situations where compliance is an issue you would absolutely want to obfuscate the data. You could do this after the fact in a few ways, but have a data set that imitates the distribution and size of your production database even in those cases is still useful. Given only the engineers with production access would be the ones forking before they handed it off they could put the right tooling in place to obfuscate. All that said it's helpful feedback and something we could definitely look at building more into the product.
- _Codemonkeyism 9y agoThis would definitely help. Although I think SOX (my compliance days are long gone) is mostly concerned about controls to change data, it might be relevant to access production data. Not sure about PCI and HIPAA.
- Artemis2 9y agoDefinitely not good for PCI DSS. Requirement 6.4 reads: Examine policies and procedures to verify the following are defined: • Development/test environments are separate from production environments with access control in place to enforce separation. • A separation of duties between personnel assigned to the development/test environments and those assigned to the production environment. • Production data (live PANs) are not used for testing or development. • Test data and accounts are removed before a production system becomes active. • Change control procedures related to implementing security patches and software modifications are documented.
- _Codemonkeyism 9y agoThanks, now I remember from my PCI DSS days.