Live data from Hacker News

Most “mandatory requirements” in corporations are imaginary

nibblestew.blogspot.com

141–150 of 405 posts

Re: Most “mandatory requirements” in corporations are imaginary

#141
post #89

Story colleagues told me once: requirements for a car's rear wind shield was that is had to withstand air pressures of 120km/h. But the car could not go in reverse that fast, so the requirement did not make sense and was loosened. On delivery of the produced cars, many rear wind shields were broken. Turns out they were transported from the factory on a train, faced backwards so they could fit more cars on the train.…

It certainly looks fabricated. Even if they were transported in open wagons only the front of the train feels all the power of the wind.

Re: Most “mandatory requirements” in corporations are imaginary

#142
post #126

Earlier quoted context omitted.

several levels of auditors were effectively asking us to downgrade to comply with their policy without even understanding the difference The auditors' policy? Are you sure? An auditor's job is to check if you're doing what you say you should be doing. If you're arguing with an auditor then you're essentially arguing with your own organisation without any hope winning the argument.

Not really a fair assessment. An auditor's job is often to check if you're doing what an external standard says you should be doing (SOC 2 => AICPA trust principles; FedRAMP => NIST 800-53, etc.). Unfortunately, these external standards may be written vaguely and while you may have policies that define X as Y, the auditor doesn't have to accept your answers. For example, when PCI requirement 5 says "Deploy anti-virus…

[deleted]

Re: Most “mandatory requirements” in corporations are imaginary

#143
post #91

It's interesting that in tech there is this expectation that every available thing should be done to make the employee as happy and relaxed as possible. If an employer refuses to do these things it's met with "does not compute", as in this example. Granted, it does seem to make sense that your employees are as happy and relaxed as possible, but this attitude doesn't seem to exist in other industries to the same degre…

> It seems that in tech people expect to be "looked after" White men who get a job right after college and haven’t developed life skills yet. Then once they get a taste of making $150k+ and having their every whim catered to think anything less is unacceptable.

Yeah, finance workers are rarely ever hired right after college. They are also way more oppressed demographics despite having significantly larger salaries.

Re: Most “mandatory requirements” in corporations are imaginary

#144
post #55

Earlier quoted context omitted.

Anyone who has spent a bit of time trying to calculate the lost productivity caused just the meetings needed to discuss breaches (internal, accidental), knows it's great ROI.

Everyone greatly overestimates ROI in their own area of expertise and greatly underestimates costs in the rest. You might be right in some special instance, but generally you are not. One example: Sending files via Email is a security problem. So you prohibit this via settings, virus scanners, appliances, etc. Now you've solved the emailed worm problem. However, you've just created a "how do we move files/data/screen…

Doesn't SharePoint trivially solve all this?

Re: Most “mandatory requirements” in corporations are imaginary

#145
post #126

Earlier quoted context omitted.

several levels of auditors were effectively asking us to downgrade to comply with their policy without even understanding the difference The auditors' policy? Are you sure? An auditor's job is to check if you're doing what you say you should be doing. If you're arguing with an auditor then you're essentially arguing with your own organisation without any hope winning the argument.

Not really a fair assessment. An auditor's job is often to check if you're doing what an external standard says you should be doing (SOC 2 => AICPA trust principles; FedRAMP => NIST 800-53, etc.). Unfortunately, these external standards may be written vaguely and while you may have policies that define X as Y, the auditor doesn't have to accept your answers. For example, when PCI requirement 5 says "Deploy anti-virus…

So every team gets to argue with the auditors? Seems like the people writing the policy should do that so there's one argument instead of n.

Re: Most “mandatory requirements” in corporations are imaginary

#146
post #126

Earlier quoted context omitted.

several levels of auditors were effectively asking us to downgrade to comply with their policy without even understanding the difference The auditors' policy? Are you sure? An auditor's job is to check if you're doing what you say you should be doing. If you're arguing with an auditor then you're essentially arguing with your own organisation without any hope winning the argument.

Not really a fair assessment. An auditor's job is often to check if you're doing what an external standard says you should be doing (SOC 2 => AICPA trust principles; FedRAMP => NIST 800-53, etc.). Unfortunately, these external standards may be written vaguely and while you may have policies that define X as Y, the auditor doesn't have to accept your answers. For example, when PCI requirement 5 says "Deploy anti-virus…

PCI also suggests a hardened system image, for example CIS and consistency checking like Aida. I'm getting tired of explaining that CIS (and other) "hardened" images just flip a few options and install lots of crap that can actually increase risk. E.g. You don't need cron? Haha, it's scored in the CIS benchmark, now you're running it.

I don't mean to just single out CIS as bad, but recently I learned that Ubuntu CIS docker images contain Aida, cron, and sysctl configuration. Yes, you pay for that. I'll be making fun of that for a long time.

Re: Most “mandatory requirements” in corporations are imaginary

#147
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

> In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place

Yes, but that doesn't mean it was ever a good reason, or that the reason still applies.

In a very large number of cases—like the one mentioned in the article—the primary reason is to let the company's management feel more "in control" of their low-level employees.

In a lot of (closely related) cases, it's straight-up racism, sexism, or classism. (Frankly, one can easily make a case that the working-from-home prohibitions fall into that category—they derive from an assumption that low-level employees are lazy and want to avoid work as much as possible, because they're analogous to the assembly-line employees of yesteryear, and thus assumed to be lower-class...which means lesser beings.)

Re: Most “mandatory requirements” in corporations are imaginary

#148
post #91

It's interesting that in tech there is this expectation that every available thing should be done to make the employee as happy and relaxed as possible. If an employer refuses to do these things it's met with "does not compute", as in this example. Granted, it does seem to make sense that your employees are as happy and relaxed as possible, but this attitude doesn't seem to exist in other industries to the same degre…

I guess it's a seller's vs a buyer's market, though maybe it's also cultural to some degree. It's generally hard to know which of the two came first, though in this instance I think it's clearer that the market influences the culture.

Re: Most “mandatory requirements” in corporations are imaginary

#150

Our time on this Earth is limited and we can't do everything. We have to make decisions. "X is required" is shorthand for "we do not want to deal with the consequences of the lack of X". It's a decision. Sure, they could, but they wouldn't have resources to deal with other things. That's basically all there is to understand here. All the rest are corollaries: - Sometimes changed circumstances require revisiting some…

[deleted]
Post reply on HN