<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:evnet="http://www.mscommunities.com/rssmodule/"><channel><title>Entries for ScottWelker</title><atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/niners/scottwelker/rss/default.aspx" /><image><url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url><title>Entries for ScottWelker</title><link>http://channel9.msdn.com/Niners/scottwelker/</link></image><description>Entries, comments and threads posted by ScottWelker</description><link>http://channel9.msdn.com/Niners/scottwelker/</link><language>en-us</language><pubDate>Sun, 17 Aug 2008 15:16:10 GMT</pubDate><lastBuildDate>Sun, 17 Aug 2008 15:16:10 GMT</lastBuildDate><generator>EvNet (EvNet, Version=1.0.3170.1238, Culture=neutral, PublicKeyToken=null)</generator><item><title>Securing Developer Workstations [Securing Developer Workstations]</title><description>&lt;p&gt;I could use 9ers cogent thoughts on securing Developer Workstations. I am on a site where developers are constrained to very minimal workstation privileges AND, the infrastructure team is… well… let’s just say unresponsive. The frustration is off-the-scale.&lt;/p&gt;
&lt;p&gt;I now have the ear – Monday – of someone with the authority to fix this. I need to make a sound case.&lt;/p&gt;
&lt;p&gt;I understand and agree that the workstation must be “secured against attack” and I understand and agree with the “Least-Privileged Account” idea described here: &lt;a href="http://msdn.microsoft.com/en-us/library/aa302367.aspx"&gt;http://msdn.microsoft.com/en-us/library/aa302367.aspx&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Our infrastructure team adds that they don’t want unsupported technologies “leaking” into our applications and, they don’t want the support calls when developers “wipe-out” their workstations.&lt;/p&gt;
&lt;p&gt;I intend to propose largely keeping everything as it is now but with these additions:&lt;/p&gt;
&lt;p&gt;1) For each “trustworthy” developer do as the aforementioned article prescribes, create a secondary, seldom used, administrative account.&lt;/p&gt;
&lt;p&gt;2) Make the development team responsible for their own workstation image. If we (I) wipeout our workstation, it’s our responsibility. We won’t bother the infrastructure team.&lt;/p&gt;
&lt;p&gt;3) Establish sufficient oversight, architecture/code review, production hand-off, ??, that ensures no technology ever “leaks” into our applications.&lt;/p&gt;
&lt;p&gt;Sorry so long winded. This is the case I’ll make – with some fine tuning. &lt;/p&gt;
&lt;p&gt;Please feel free to fire holes in it or counter or bolster the arguments. &lt;/p&gt;&lt;p&gt;in reply to &lt;a href='http://channel9.msdn.com/forums/Coffeehouse/421960-Securing-Developer-Workstations/'&gt;Securing Developer Workstations&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/421960/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/forums/Coffeehouse/421960-Securing-Developer-Workstations/</comments><link>http://channel9.msdn.com/forums/Coffeehouse/421960-Securing-Developer-Workstations/</link><pubDate>Sun, 17 Aug 2008 15:14:56 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/421960-Securing-Developer-Workstations/</guid><evnet:views>963</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/421960/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>I could use 9ers cogent thoughts on securing Developer Workstations. I am on a site where developers are constrained to very minimal workstation privileges AND, the infrastructure team is… well… let’s just say unresponsive. The frustration is off-the-scale.
I now have the ear – Monday – of someone&amp;#8230;</evnet:previewtext><dc:creator>ScottWelker</dc:creator><slash:comments>25</slash:comments><wfw:commentRss>http://channel9.msdn.com/forums/Coffeehouse/421960-Securing-Developer-Workstations/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/421960/Trackback.aspx</trackback:ping></item></channel></rss>