4 ms·
I've been in both kinds of organizations. Without fail, every place that was like "organization B" (separate development and cloud teams) had some under-the-ta
by goodells 5y ago
I've been in both kinds of organizations. Without fail, every place that was like "organization B" (separate development and cloud teams) had some under-the-table workaround. The worst I think I ever saw was _every single customer's hosted environment_ had SSH access enabled with the same key, and it was shared between developers without much regard for security. A business worth hundreds of millions of dollars...
But of course they required two-factor authentication in O365, so it was SOX2 compliant.