Can you expand on what, precisely, you mean by that?
Can you expand on what, precisely, you mean by that?
Okay, let's say that's your environment. How do you prevent Mole Manny (who is a legit developer in your organization) from pulling down all the files in his project (as he's entitled to do), and then copying it over to his $super_sneeky_storage_system?
We've talked a lot about this where I am and we've concluded that to ensure a super-tight environment we'd have to do a slew of really heinous lockdowns (epoxy usb ports for instance) which would likely not really do much against moles but slow down and anger legit users.
Pieces like the random number algorithm for that stuff is tightly controlled.
Another example might be Credit Card Processing software, you don't want a lot of people knowing how you generate your encryption keys.
Not always the same.
For that, you need comprehensive monitoring on every system from which the repository can be accessed that tracks what is done, and once you have that, it doesn't really matter what you do for VCS for that kind of monitoring.