PCI DSS requirement 6.4.2 separation of duties between development/test environments
Posted
by
Aleksandar Ivanisevic
on Server Fault
See other posts from Server Fault
or by Aleksandar Ivanisevic
Published on 2012-03-22T10:10:45Z
Indexed on
2012/03/22
11:32 UTC
Read the original article
Hit count: 623
pci-dss
6.4.2 Is there separation of duties between personnel assigned to the development/test environments and those assigned to the production environment?
What does the separation of duties here mean? Is it in the sense of http://www.sans.edu/research/security-laboratory/article/it-separation-duties or something else? The formulation "between test and production environment" is really confusing me, it looks like they mean that one should have different sysadmins for test and production? Or do they just mean that developers shouldn't have access to production?
thanks.
© Server Fault or respective owner