graphgrc

SCF - HRS-12 - Incompatible Roles

Mechanisms exist to avoid incompatible development-specific roles through limiting and reviewing developer privileges to change hardware, software and firmware components within a production/operational environment.

Mapped framework controls

ISO 27002

Control questions

Does the organization avoid incompatible development-specific roles through limiting and reviewing developer privileges to change hardware, software and firmware components within a production/operational environment?