3 ms·
Sure. So while Sarbanes Oxley doesn’t contain anything like “thou shalt not commit to a repo”, it’s pretty clear about separation of duties. This means that the
by chomp 5y ago
Sure. So while Sarbanes Oxley doesn’t contain anything like “thou shalt not commit to a repo”, it’s pretty clear about separation of duties. This means that the person who commits code cannot be the same as the person who deploys (or has access to deploy) the code.
There’s many ways to implement separation of duties that are all valid, but the compliance industry has settled on the concept of least privilege as a framework to enforce this requirement. So if a person external to a dev team wants to write to their code base, the hard rule of least privilege keeps the regulatory train on the rails, so to speak. Keeping that wall between external teams reduces risk in the company, at the cost of increased friction and reduced agility. Consider it a part of the price to pay for investor money.
If you have any other questions I’d be happy to answer!
- Cederfjard 5y agoVery interesting, thank you. I’m not based in the US, so was unaware of these regulatory requirements. I can certainly see how it increases friction, as you say.
- deleted 5y ago[deleted]