March 21, 2023, 2:42 p.m. | /u/Strider755

cybersecurity www.reddit.com

I work with STIGs as part of my job. My first team lead had the mindset that systems should be locked down and developers should have to work within those constraints. If the devs' code didn't work because of the security settings, that was their problem, not hers. After I shifted to a different program, my new team lead said that that approach is wrong.

Which is the correct approach? Should developers have to defer to the security standard, or …

code constraints cybersecurity developers down important job locked mindset problem program security settings system systems team work

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Engineer 2

@ Oracle | BENGALURU, KARNATAKA, India

Oracle EBS DevSecOps Developer

@ Accenture Federal Services | Arlington, VA

Information Security GRC Specialist - Risk Program Lead

@ Western Digital | Irvine, CA, United States

Senior Cyber Operations Planner (15.09)

@ OCT Consulting, LLC | Washington, District of Columbia, United States

AI Cybersecurity Architect

@ FactSet | India, Hyderabad, DVS, SEZ-1 – Orion B4; FL 7,8,9,11 (Hyderabad - Divyasree 3)