Live data from Hacker News

Most “mandatory requirements” in corporations are imaginary

nibblestew.blogspot.com

171–180 of 405 posts

Re: Most “mandatory requirements” in corporations are imaginary

#171
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

The other principle is separation of duties. Policy is made by people who aren't the practitioners so that the interests of the organization are ahead of the whim or convenience of the practitioner. People who served in the military usually get this concept, as it's more obvious that there is a long line of stupid actions on random soldiers' part that leads to a longer line of preventative rules.

I'd also say that when I worked on a program for a big company that interfaced with alot of small companies and startups a few years, the startups in particular had really awful practices. The "bullshit" compliance checklists for security revealed awful practices that present real risks. The big company was more vulnerable to systemic risk due to inflexibility, the small companies are more vulnerable to individual risks due to employee action or lack of controls.

Re: Most “mandatory requirements” in corporations are imaginary

#172
post #33

Earlier quoted context omitted.

I think the problem with this logic is it hinders a hundred people on a daily basis to prevent one person from doing something stupid once a year. That’s just not great ROI.

Anyone who has spent a bit of time trying to calculate the lost productivity caused just the meetings needed to discuss breaches (internal, accidental), knows it's great ROI.

This just tells us that we shouldn’t discuss breaches so much? My one experience with a breach has been that the whole process around it was a collosal waste of everyone’s time.

Re: Most “mandatory requirements” in corporations are imaginary

#173
post #91

It's interesting that in tech there is this expectation that every available thing should be done to make the employee as happy and relaxed as possible. If an employer refuses to do these things it's met with "does not compute", as in this example. Granted, it does seem to make sense that your employees are as happy and relaxed as possible, but this attitude doesn't seem to exist in other industries to the same degre…

I think it's the hacker mindset of not being afraid to change things. Every job I ever had I always questioned the rules and pushed for change to make things less redundant and more efficient. This was even in retail as a teenager, and being a waiter for church bingo when I was 10.

Some of us just have that inherent urge to say "wait, wouldn't it be better if we did it this way" instead of quietly following the rules. My guess is that people with this mentality are more likely to want to be a programmer in the first place.

Re: Most “mandatory requirements” in corporations are imaginary

#174
post #144
post #55

Earlier quoted context omitted.

Everyone greatly overestimates ROI in their own area of expertise and greatly underestimates costs in the rest. You might be right in some special instance, but generally you are not. One example: Sending files via Email is a security problem. So you prohibit this via settings, virus scanners, appliances, etc. Now you've solved the emailed worm problem. However, you've just created a "how do we move files/data/screen…

Doesn't SharePoint trivially solve all this?

I don’t think I’ve ever heard Sharepoint and ‘trivially solved’ in the same sentence before.

The problem with using sharepoint is that now you have sharepoint, and people will start using it, with all attendant horrors.

Re: Most “mandatory requirements” in corporations are imaginary

#175
post #36
post #33

Earlier quoted context omitted.

I think the problem with this logic is it hinders a hundred people on a daily basis to prevent one person from doing something stupid once a year. That’s just not great ROI.

It's a great ROI if that one stupid thing a year is someone pushing your company's codebase and all your trade secrets to a public repo.

By the same logic it’s good to have your company located in an armored bunker underground on the off chance that someone nukes the city you are in.

I realize the chances are a bit different, but it illustrates the point.

Re: Most “mandatory requirements” in corporations are imaginary

#176
The whole problem seems to pivot around blame.

Having only ever worked at a small company, I've enjoyed the absence of fear of blame. When the hierarchy is so minimal risk-vs-benefit seems to be easy to communicate and digest between both ends of the spectrum and accept with shared responsibility. I understand this doesn't automatically scale, but it feels unsatisfying to assume blame is as inevitable part of growth.

Can anyone think of a way to avoid it? Is it a necessary side effect of larger layered hierarchy or is it something else?

Re: Most “mandatory requirements” in corporations are imaginary

#177

This is all too common. A friend told me about his company where the IT decision makers were largely centralised, physically near their cloud servers and they frequently discounted the measurable and serious difficulties of internal tech consumers suffered in other locations for years, even though their architecture would have made it comparatively easy to rebalance things for a more global approach. Early in my care…

A fun one I experienced was awful VOIP call quality due to a policy requirement that all company network traffic route through the headquarters office, and all the latency that introduced for anyone who worked from one of the (many) other offices.

Then one day the director of sales had a rather important call with a major prospective client while they happened to be visiting one of the regional offices. We were enjoying absolutely stellar-sounding phone calls within 48 hours.

Re: Most “mandatory requirements” in corporations are imaginary

#178
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

Side issue, but I have cause to mention Chesterton's Fence so often that it's become a real frustration that there is no Wikipedia article about it — only this essay about why Wikipedia contributors should honour it. I wish there was an actual article I could point to when I want people to know about it.

(Why don't I just make one? I have basically given up on making substantial contributons to Wikipedia since the Deletion Police took over the asylum. There's a 90% probability that if I did spend a couple of hours writing a good article, someone would come along within a week and spend a couple seconds deleting it. It's out of control.)

Re: Most “mandatory requirements” in corporations are imaginary

#179
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

Side issue, but I have cause to mention Chesterton's Fence so often that it's become a real frustration that there is no Wikipedia article about it — only this essay about why Wikipedia contributors should honour it. I wish there was an actual article I could point to when I want people to know about it. (Why don't I just make one? I have basically given up on making substantial contributons to Wikipedia since the De…

What is this Wikipedia "Deletion Police"? I haven't heard of quality content being consistently deleted.

Re: Most “mandatory requirements” in corporations are imaginary

#180
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

Side issue, but I have cause to mention Chesterton's Fence so often that it's become a real frustration that there is no Wikipedia article about it — only this essay about why Wikipedia contributors should honour it. I wish there was an actual article I could point to when I want people to know about it. (Why don't I just make one? I have basically given up on making substantial contributons to Wikipedia since the De…

You could use this redirect as a link: https://en.wikipedia.org/wiki/Chesterton%27s_fence
Post reply on HN