3 ms·
Part of Sarbanes-Oxley is to make sure IT systems are not manipulated. This includes regulating access to systems and controlling software development. Mainly t
by _Codemonkeyism 8y ago
Part of Sarbanes-Oxley is to make sure IT systems are not manipulated. This includes regulating access to systems and controlling software development. Mainly this means, people who write code can't push code into production systems on their own.
One person writes a requirement, this needs to be OKed by another person, then a third person writes this code and it's pushed to production. Controls are setup - e.g. checking JIRA tickets in git logs - that no code without proper authorization (corrrect JIRA status) is pushed and deployed.
People need to be able to trace every code change to the requirement and the OK.
In the core this only applies to systems that are in one way or the other relevant to financial data (like ordering), but auditors usually want to be better safe than sorry. But Tesla might have a SOX-IT and non-SOX-IT.
- gnode 8y ago> Part of Sarbanes-Oxley is to make sure IT systems are not manipulated. I would expect that there are limits to this. If a rogue employee engages in fraudulent behaviour against you, using "false usernames" to subvert your security as this employee reportedly did, then I don't see how the organisation could be considered responsible.
- londons_explore 8y agoI'm gonna guess they use github and this guy just pinged an admin to have a few new github users called things like "Legolas66" added to the organisation. Many orgs don't track github usernames to real human mappings well or at all, mostly because the single sign on version of github is 3x the price.