IVS-05: Are production and non-production environments separated?
Separation of the environments may include: • Stateful inspection firewalls • Domain/realm authentication sources • Clear segregation of duties for personnel accessing these environments as part of their job duties
Apply sanitization routines on data before loading into non-production, and define environmental boundaries.
Production workloads should be isolated from the lower environments (e.g., development, testing) when possible.
Control implemented
Control ownership
Description
Separate production and non-production environments.