I was wondering if it was an SRE when the original story came out.
I'd be interested in seeing perspectives on how you avoid this scenario. While you could isolate data access by team in many models, you're still going to have engineers who have access to valuable data. Random access audits? But what about the scenario where your database lives on someone else's hardware?
I guess you could always decide you want to use your cloud providers FedRAMP-compliant offerings.
Comments
I was wondering if it was an SRE when the original story came out.
I'd be interested in seeing perspectives on how you avoid this scenario. While you could isolate data access by team in many models, you're still going to have engineers who have access to valuable data. Random access audits? But what about the scenario where your database lives on someone else's hardware?
I guess you could always decide you want to use your cloud providers FedRAMP-compliant offerings.