7 ms·
The is the obvious next step for the industry/technology. I think a better answer is to maximally reduce the potential fallout from a compromised employee. Thi
by pc_edwin 3y ago
The is the obvious next step for the industry/technology. I think a better answer is to maximally reduce the potential fallout from a compromised employee.
This is easier said then done and if you go the direction of complicated procedures employees will usually just try to bypass procedures entirely.
However I think there is a middle ground or a sweet spot here. The tech has come a long way in the past decade or so. Its pretty easy to have a set up where almost no employee can deploy to production from their local machine.
Its also the easiest its ever been to have a sandboxed production environment and a near parallel staging environment.
- ahhfgshando6698 3y agoStepping back for a second...do we have evidence that these sorts of issues are actually the cause of a significant number of breaches rather than paranoia on the part of people that are paid to be paranoid? That's not a rhetorical question, I 'm actually curious to find out. The reason I ask is that of all the big security breaches that end up in the news, I cannot recall a single case where these sorts of issues (for instance, not locking down deployment to production) was the root cause.