<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data Science Secure Setup in Threats</title>
    <link>https://community.isc2.org/t5/Threats/Data-Science-Secure-Setup/m-p/42751#M248</link>
    <description>&lt;P&gt;Guys, I would like some suggestions to deploy a safe setup for a data scientist profile within the organization.&lt;BR /&gt;&lt;BR /&gt;This professional has a profile very similar to development: Python programming, uses Jupyter notebooks and Pandas. At the end of the day it means that he uses Linux and needs to install applications freely, and should be free to download apps and source codes.&lt;BR /&gt;&lt;BR /&gt;How to securely provide a workstation where the user can freely install applications for development purposes?&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:46:35 GMT</pubDate>
    <dc:creator>yurirbraz</dc:creator>
    <dc:date>2023-10-09T09:46:35Z</dc:date>
    <item>
      <title>Data Science Secure Setup</title>
      <link>https://community.isc2.org/t5/Threats/Data-Science-Secure-Setup/m-p/42751#M248</link>
      <description>&lt;P&gt;Guys, I would like some suggestions to deploy a safe setup for a data scientist profile within the organization.&lt;BR /&gt;&lt;BR /&gt;This professional has a profile very similar to development: Python programming, uses Jupyter notebooks and Pandas. At the end of the day it means that he uses Linux and needs to install applications freely, and should be free to download apps and source codes.&lt;BR /&gt;&lt;BR /&gt;How to securely provide a workstation where the user can freely install applications for development purposes?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:46:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Data-Science-Secure-Setup/m-p/42751#M248</guid>
      <dc:creator>yurirbraz</dc:creator>
      <dc:date>2023-10-09T09:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Data Science Secure Setup</title>
      <link>https://community.isc2.org/t5/Threats/Data-Science-Secure-Setup/m-p/42758#M249</link>
      <description>&lt;P&gt;There should be limits to letting an individual have free reign over a corporate device. Once an "image" is built according to the users specification then Admin access should be controlled and provisioned carefully. There is a lot that can go wrong with a backend data scientist's workstation having access to corporate data. That is too big of a risk IMHO.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 03:07:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Data-Science-Secure-Setup/m-p/42758#M249</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2021-01-23T03:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Data Science Secure Setup</title>
      <link>https://community.isc2.org/t5/Threats/Data-Science-Secure-Setup/m-p/42777#M251</link>
      <description>&lt;P&gt;Have you considered a server/client setup? So MIS manage the server and client just access the server to run task?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 21:25:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Data-Science-Secure-Setup/m-p/42777#M251</guid>
      <dc:creator>sergeling</dc:creator>
      <dc:date>2021-01-23T21:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Data Science Secure Setup</title>
      <link>https://community.isc2.org/t5/Threats/Data-Science-Secure-Setup/m-p/42835#M252</link>
      <description>&lt;P&gt;Seems like a good candidate for separate dev and prod systems.&amp;nbsp; In dev, the Data Scientist get full control over the system, but with access to only simulated data.&amp;nbsp; In prod, they get production data, but on a machine built/maintained to approved specs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And, ideally, separation of duties would come into play at some point.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 23:14:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Data-Science-Secure-Setup/m-p/42835#M252</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2021-01-25T23:14:04Z</dc:date>
    </item>
  </channel>
</rss>

