3 ms·
> So one of the requirements for SOX compliance is that no one person can unilaterally push code to prod. [...] many risk averse companies who want to be certai
by Rule35 6y ago
> So one of the requirements for SOX compliance is that no one person can unilaterally push code to prod. [...] many risk averse companies who want to be certain to be in compliance is dev and ops are kept separate
Here's an example of compliance setting a user back for no real benefit.
I'm in an organization that did this separation before we were forced to put our socks on. What we realized is that only a dev can usefully check a dev. Gating of code into prod needs to be by a dev, and the gating of infra changes needs to be gated by ops people. But that individuals, and the role, are best as combined as dev+ops.
So we implemented the separation, but not by splitting our worked into two separate groups and putting a wall between. We had other teams so we moved the review inter-team. I develop, maintain, and manage my piece of my team's service, but also do release-review for pieces of an entirely separate project that I have no access to other than to read the code.
- didibus 6y agoThat seems a lot better to me. Also, I don't know anything about SOX compliance, but couldn't you have another dev on the same team do a review? Or is there a part of it about the reviewer needing to be without context or something of that sort?