4 ms·
I get what you are saying but I also think the parent has a point, if it was that easy to do an end run around the scanning (accidentally or otherwise) then it'
by VBprogrammer 6y ago
I get what you are saying but I also think the parent has a point, if it was that easy to do an end run around the scanning (accidentally or otherwise) then it's not really suitable for auditing external parties. For your internal teams you can probably have some level of confidence they will fix it in good faith.
- ownagefool 6y agoYeah it's complicated. Scanning is useful to automate a "thing" but your audit is multifaceted and should probably require peer review (pull/merge requests). In simple terms, scanning should _hopefully_ help a dev who wants to do the right thing, but it won't help a malicious dev, so you're gonna need something else. Peer review, least privileged access, protective monitoring, etc.