The Visual Effects industry in my case. Reason is unreleased content, for example, the new iPhone commercial or a new Marvel movie that hasn't been announced yet.
Did you have to audit all the vendor code? If so, how much time was spent on that?
Yes, from days to weeks. It was a separate department.
Do you think this kind of practices actually improve any security?
Yes, if your computers do not touch the internet and you do not have physical access to the device then you cannot easily leak content.
I am sure someone could take their phones outs and picture every screen of what they were working on.. but it is a bigger barrier.
If there is no internet, how do you search for a solution to an immediate problem or look up documentation?
We had a separate computer (a windows box served through guacamole) that we could search things.
How is the testing culture like in these orgs?
Nothing too different from others, the only real big difference is that you cannot reach to the internet from where you're developing software.
If there is no internet, how do you search for a solution to an immediate problem or look up documentation?
Several DoE labs in the US were attacked around 2010. Jefferson Lab was cut off from the internet for several months (or maybe over a year?), and the only on-site access to the internet as a whole was a limited set of machines which weren't on the rest of the network. If you needed to look something up you'd go use one of those machines instead.
Comments
Interesting to know. Thanks for replying.
Curious which ones?
Did you have to audit all the vendor code? If so, how much time was spent on that?
Do you think this kind of practices actually improve any security?
If there is no internet, how do you search for a solution to an immediate problem or look up documentation?
How is the testing culture like in these orgs?
The Visual Effects industry in my case. Reason is unreleased content, for example, the new iPhone commercial or a new Marvel movie that hasn't been announced yet.
Yes, from days to weeks. It was a separate department.
Yes, if your computers do not touch the internet and you do not have physical access to the device then you cannot easily leak content.
I am sure someone could take their phones outs and picture every screen of what they were working on.. but it is a bigger barrier.
We had a separate computer (a windows box served through guacamole) that we could search things.
Nothing too different from others, the only real big difference is that you cannot reach to the internet from where you're developing software.
Several DoE labs in the US were attacked around 2010. Jefferson Lab was cut off from the internet for several months (or maybe over a year?), and the only on-site access to the internet as a whole was a limited set of machines which weren't on the rest of the network. If you needed to look something up you'd go use one of those machines instead.