Somebody recently asked, on the CISSPforum, for some kind of reference supporting the concept that it was a good idea not to do development or testing on production systems.
I think Mim Britt said it best:
Somebody said we should make that into a sigquote, or blog it.  Mim said she’d be flattered if anyone did.  I think it’s a great idea.
