Most “mandatory requirements” in corporations are imaginary
121–130 of 405 posts
Re: Most “mandatory requirements” in corporations are imaginary
#122In 1605 there was an attempt to blow up the British Parliament during the state opening by placing explosives in the cellars. 415 years later they still search the cellars for barrels of explosives, using oil lanterns and armed with swords. I feel that so many organisations are doing the same thing, maintaining an old solution for a problem that no longer exists. So I think it's just as, or more, important to apply t…
Re: Most “mandatory requirements” in corporations are imaginary
#123Re: Most “mandatory requirements” in corporations are imaginary
#124Earlier quoted context omitted.
I believe it's all about Security (C-I-A). To mitigate this issue, on paper, an (usually) HR policy writes "do not do non-work related stuff with your work computer". And since many people ignore this rule, because "why have a second laptop?", the next best thing is to route all traffic from your laptop through the company, and weed out the GigHubs and GitLabs of this world (in the same manner that they block all sex…
> You can't blame a company for wanted to protect itself against a disgruntled employee that wants to push the (example - not applicable to your company) ebanking software code out in the open. The thing is, they can't, not if my PC is still usable for day to day work. For a legitimate user, the ways to extricate data are endless (e.g. tunnel out via DNS, embed into video streams (for customer training or something),…
But most employees would never know how to do this and even if, the threshold is high to go to such lengths. Most companies primarily want to prevent users from sending out data by mistake or via malware, since these are probably >99% of the reasons for data loss.
I also dislike companies restricting employees. But I also know people from our IT department and the incidents they have to fight on a daily basis. If you don't restrict your network and company computers, you'll very quickly end up with malware, randsomware, leaked data etc.
Re: Most “mandatory requirements” in corporations are imaginary
#125Re: Most “mandatory requirements” in corporations are imaginary
#126Earlier quoted context omitted.
> but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. The issue is that all the policy documents often only contain the One True Way to achieve their goals, while the goals remain unstated. The documents should always come with a rationale. And appending "exceptions may be granted for equivalent or better processes"…
several levels of auditors were effectively asking us to downgrade to comply with their policy without even understanding the difference The auditors' policy? Are you sure? An auditor's job is to check if you're doing what you say you should be doing. If you're arguing with an auditor then you're essentially arguing with your own organisation without any hope winning the argument.
An auditor's job is often to check if you're doing what an external standard says you should be doing (SOC 2 => AICPA trust principles; FedRAMP => NIST 800-53, etc.).
Unfortunately, these external standards may be written vaguely and while you may have policies that define X as Y, the auditor doesn't have to accept your answers. For example, when PCI requirement 5 says "Deploy anti-virus software on all systems commonly affected by malicious software (particularly personal computers and servers).", your policy may say "antivirus is not required inside containers that run on platforms like GKE, as these are not commonly affected by malicious software." It's very likely you'll have a discussion about your interpretation of that requirement.
Re: Most “mandatory requirements” in corporations are imaginary
#127Earlier quoted context omitted.
I believe it's all about Security (C-I-A). To mitigate this issue, on paper, an (usually) HR policy writes "do not do non-work related stuff with your work computer". And since many people ignore this rule, because "why have a second laptop?", the next best thing is to route all traffic from your laptop through the company, and weed out the GigHubs and GitLabs of this world (in the same manner that they block all sex…
> That said.. why would a person use the corporate computer for their (allow me the use of the word) 'hobby'? Because my work computer is around 100 times faster than my personal one.
Re: Most “mandatory requirements” in corporations are imaginary
#128Earlier quoted context omitted.
When circumstances change, risk profiles and trade offs change. News at 11. I mean you can rage about the unlikeliness of people concocting explosives from various liquids, but that is entirely besides the point here.
I, personally, would prefer to rage at the fact that the TSA has managed to export that liquid rule to everyone else in the world. I don't see why, when flying from Ontatio to Quebec, I need to follow the TSA's security theatre. Though I agree that's also besides the point.
Also see https://medium.com/incerto/the-most-intolerant-wins-the-dict...
Re: Most “mandatory requirements” in corporations are imaginary
#129Earlier quoted context omitted.
> but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. The issue is that all the policy documents often only contain the One True Way to achieve their goals, while the goals remain unstated. The documents should always come with a rationale. And appending "exceptions may be granted for equivalent or better processes"…
several levels of auditors were effectively asking us to downgrade to comply with their policy without even understanding the difference The auditors' policy? Are you sure? An auditor's job is to check if you're doing what you say you should be doing. If you're arguing with an auditor then you're essentially arguing with your own organisation without any hope winning the argument.
Re: Most “mandatory requirements” in corporations are imaginary
#130In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…
> Chesterton's fence Is there a "reverse" version of this where you do understand the reasoning, explain clearly why it doesn't apply anymore, but the other side just refuses to think for themselves and just sticks with the status quo because it must've been done with good reason and they don't want to second-guess it?