PCI DSS requirement 6.4.2 separation of duties between development/test environments

Posted by Aleksandar Ivanisevic on Server Fault See other posts from Server Fault or by Aleksandar Ivanisevic
Published on 2012-03-22T10:10:45Z Indexed on 2012/03/22 11:32 UTC
Read the original article Hit count: 588

Filed under:

6.4.2 Is there separation of duties between personnel assigned to the development/test environments and those assigned to the production environment?

What does the separation of duties here mean? Is it in the sense of http://www.sans.edu/research/security-laboratory/article/it-separation-duties or something else? The formulation "between test and production environment" is really confusing me, it looks like they mean that one should have different sysadmins for test and production? Or do they just mean that developers shouldn't have access to production?

thanks.

© Server Fault or respective owner

Related posts about pci-dss