Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> Re: Back and a Question

Re: Back and a Question

From: <ryan_gaffuri_at_comcast.net>
Date: Wed, 16 Aug 2006 13:51:46 +0000
Message-Id: <081620061351.7747.44E322F2000C996B00001E432207024553079D9A00000E09A1020E979D@comcast.net>


if it doesn't state in SOX that developers can't have access to production data, how do the auditors determine what is a violation?

Not having access to PROD data is a real problem for ETL systems that recieve external data feeds. You can have alot of validation checks when you get the file, but you will never catch everything and sometimes you get bad data. You need to people to check it.

I guess the other option is to 'promote' a developer to systems administrator and put him on the production team so he can look at the data?

> From where I stand, it's exactly like Ryan described:
> we got SOx-audited last year and again this year and in both
> occasions access to production by developers came up as an
> absolute no-no and something we simply cannot allow.
> Which I tend to agree with, BTW. ;-)
>
>
> --
> Cheers
> Nuno Souto
> from sunny Sydney
>
>
>
> Quoting David Aldridge :
>
> > Tsh, is there any lie that those operations people won't tell in order
> > to keep us out of their sandbox?
> >
> > Seriously though, I don't think that SOX is that detailed, and I don't
> > believe any STIG is either. It sounds like that rule is more along the
> > lines of an _interpretation_ of the regulations, or a quoting of the
> > regulations to justify a rule (depending on your degree of cynicism).
> >
> > ryan_gaffuri_at_comcast.net wrote:
> > >
> > > I did DOD befoer this. I am doing financial now. The federal government
> > > actually passed security laws for financial companies as part of
> > > Sarbanes-Oxley(SOX). I was told by operations that one of the rules is
> > > that development cannot have access to production data. That is a
> > > problem for production support when you get data issues.
> --
> http://www.freelists.org/webpage/oracle-l
>
>

--
http://www.freelists.org/webpage/oracle-l
Received on Wed Aug 16 2006 - 08:51:46 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US