2 ms·
> When we went for SOX compliance our auditors were pretty firm that having developers being the ones pushing to prod and not a separate team was a security iss
by seneca 3y ago
> When we went for SOX compliance our auditors were pretty firm that having developers being the ones pushing to prod and not a separate team was a security issue.
That's surprising to hear. That's a very out of date take on SOX, in my experience. I've worked in thoroughly audited FedRAMP environments where the it's devs pushing and reviewing that triggers pipelines for prod release.