Sarbanes-Oxley: IT Issues
Currently there is discussion within my organization about testing and dealing with system failures. Right now we are dealing with a vendor that does not give a Dev environment to work on before implementation onto the live production environment. They seem to be of the belief that testing on a live system is ok. Crazy i know, what im looking for is documentation or a link to a best practice site that i can grab information on controls that need to be in place for Application deployment.
I know this is a retarded request, but im just not sure how to explain this in more detail to the vendor other than screaming in there face "DEV and even a QA environment is a must!!!!!"

Any help will be apprecited.

