Story colleagues told me once: requirements for a car's rear wind shield was that is had to withstand air pressures of 120km/h. But the car could not go in reverse that fast, so the requirement did not make sense and was loosened. On delivery of the produced cars, many rear wind shields were broken. Turns out they were transported from the factory on a train, faced backwards so they could fit more cars on the train.…
Most “mandatory requirements” in corporations are imaginary
141–150 of 405 posts
Re: Most “mandatory requirements” in corporations are imaginary
#142Earlier quoted context omitted.
several levels of auditors were effectively asking us to downgrade to comply with their policy without even understanding the difference The auditors' policy? Are you sure? An auditor's job is to check if you're doing what you say you should be doing. If you're arguing with an auditor then you're essentially arguing with your own organisation without any hope winning the argument.
Not really a fair assessment. An auditor's job is often to check if you're doing what an external standard says you should be doing (SOC 2 => AICPA trust principles; FedRAMP => NIST 800-53, etc.). Unfortunately, these external standards may be written vaguely and while you may have policies that define X as Y, the auditor doesn't have to accept your answers. For example, when PCI requirement 5 says "Deploy anti-virus…
Re: Most “mandatory requirements” in corporations are imaginary
#143It's interesting that in tech there is this expectation that every available thing should be done to make the employee as happy and relaxed as possible. If an employer refuses to do these things it's met with "does not compute", as in this example. Granted, it does seem to make sense that your employees are as happy and relaxed as possible, but this attitude doesn't seem to exist in other industries to the same degre…
> It seems that in tech people expect to be "looked after" White men who get a job right after college and haven’t developed life skills yet. Then once they get a taste of making $150k+ and having their every whim catered to think anything less is unacceptable.
Re: Most “mandatory requirements” in corporations are imaginary
#144Earlier quoted context omitted.
Anyone who has spent a bit of time trying to calculate the lost productivity caused just the meetings needed to discuss breaches (internal, accidental), knows it's great ROI.
Everyone greatly overestimates ROI in their own area of expertise and greatly underestimates costs in the rest. You might be right in some special instance, but generally you are not. One example: Sending files via Email is a security problem. So you prohibit this via settings, virus scanners, appliances, etc. Now you've solved the emailed worm problem. However, you've just created a "how do we move files/data/screen…
Re: Most “mandatory requirements” in corporations are imaginary
#145Earlier quoted context omitted.
several levels of auditors were effectively asking us to downgrade to comply with their policy without even understanding the difference The auditors' policy? Are you sure? An auditor's job is to check if you're doing what you say you should be doing. If you're arguing with an auditor then you're essentially arguing with your own organisation without any hope winning the argument.
Not really a fair assessment. An auditor's job is often to check if you're doing what an external standard says you should be doing (SOC 2 => AICPA trust principles; FedRAMP => NIST 800-53, etc.). Unfortunately, these external standards may be written vaguely and while you may have policies that define X as Y, the auditor doesn't have to accept your answers. For example, when PCI requirement 5 says "Deploy anti-virus…
Re: Most “mandatory requirements” in corporations are imaginary
#146Earlier quoted context omitted.
several levels of auditors were effectively asking us to downgrade to comply with their policy without even understanding the difference The auditors' policy? Are you sure? An auditor's job is to check if you're doing what you say you should be doing. If you're arguing with an auditor then you're essentially arguing with your own organisation without any hope winning the argument.
Not really a fair assessment. An auditor's job is often to check if you're doing what an external standard says you should be doing (SOC 2 => AICPA trust principles; FedRAMP => NIST 800-53, etc.). Unfortunately, these external standards may be written vaguely and while you may have policies that define X as Y, the auditor doesn't have to accept your answers. For example, when PCI requirement 5 says "Deploy anti-virus…
I don't mean to just single out CIS as bad, but recently I learned that Ubuntu CIS docker images contain Aida, cron, and sysctl configuration. Yes, you pay for that. I'll be making fun of that for a long time.
Re: Most “mandatory requirements” in corporations are imaginary
#147In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…
Yes, but that doesn't mean it was ever a good reason, or that the reason still applies.
In a very large number of cases—like the one mentioned in the article—the primary reason is to let the company's management feel more "in control" of their low-level employees.
In a lot of (closely related) cases, it's straight-up racism, sexism, or classism. (Frankly, one can easily make a case that the working-from-home prohibitions fall into that category—they derive from an assumption that low-level employees are lazy and want to avoid work as much as possible, because they're analogous to the assembly-line employees of yesteryear, and thus assumed to be lower-class...which means lesser beings.)
Re: Most “mandatory requirements” in corporations are imaginary
#148It's interesting that in tech there is this expectation that every available thing should be done to make the employee as happy and relaxed as possible. If an employer refuses to do these things it's met with "does not compute", as in this example. Granted, it does seem to make sense that your employees are as happy and relaxed as possible, but this attitude doesn't seem to exist in other industries to the same degre…
Re: Most “mandatory requirements” in corporations are imaginary
#149Re: Most “mandatory requirements” in corporations are imaginary
#150Our time on this Earth is limited and we can't do everything. We have to make decisions. "X is required" is shorthand for "we do not want to deal with the consequences of the lack of X". It's a decision. Sure, they could, but they wouldn't have resources to deal with other things. That's basically all there is to understand here. All the rest are corollaries: - Sometimes changed circumstances require revisiting some…