Live data from Hacker News

Most “mandatory requirements” in corporations are imaginary

nibblestew.blogspot.com

351–360 of 405 posts

Re: Most “mandatory requirements” in corporations are imaginary

#351

Earlier quoted context omitted.

Funny thing is: once you travel with a baby, basically anything goes. 1L water bottle? no questions asked. Even though the baby won't drink 1L of water on a 2-hours flight. The whole restriction on liquids is fairly ridiculous, and even more of a security theater than most of the other checks. And I think the security guards know it, and use any excuse to look the other way.

To be fair, traveling with a baby makes you much less likely to attack a plane. This exception makes the TSA's policy more pragmatic and reasonable. The harm of denying a baby milk or formula is worse than the risk of terrorism in this case. Not to mention is that it lowers the incidence of crying babies on flight. The same logic could be applied to hand sanitizer restrictions in a global pandemic. Allowing people to…

"traveling with a baby makes you much less likely to attack a plane"

Why would that be the case?

Re: Most “mandatory requirements” in corporations are imaginary

#352
post #211

Earlier quoted context omitted.

About five years ago, a place I was working at was selecting a new laptop for all employees. Mine was up for replacement, so I was interested in what they were picking. They'd arrived at some god-awful Lenovo gamer model. It fit the performance and price point they'd decided they needed. I said I'd prefer to have something smaller with less Christmas lights. "Policy is everyone has to have the same laptop, and some p…

This is literally my job. Amazon calls it Dive Deep/Earn Trust. I get called in constantly to "Remove Blockers". Part of it is just understanding why the policy exists and then getting a policy modification. While it's definitely an art, it's not as hard as a lot of people think, but you can't be afraid to escalate.

I'm envious. So if people end up being the blocker, do you remove them too?

Re: Most “mandatory requirements” in corporations are imaginary

#354

Earlier quoted context omitted.

> It's probably by design, because as soon as you put a reason that becomes a target and people start to get ideas about why it doesn't apply to them. There's more to it than that. There are two separate groups of reasons: 1. The reasons a policy was put in place. ("Why did we do this?") 2. The reasons a policy succeeds. ("Why is this a good idea?") You can know the reasons in group 1. But nobody cares about those. W…

I was working in a throughout computing problem domain. About the time I got there, some asshole in HR had everyone’s (current and former employees) tax information on their work laptop and lost it. Tens of thousands of people, because there was no policy against putting such information on portable equipment. And as far as I’m aware there still isn’t. No, within the year (might have been a lawsuit, I can’t recall) n…

I don't know if encryption was the right policy response here (it seems to be a very good idea regardless due to theft/hacking possibilities), but I'm OK with this sort of policy sometimes.

Full disk encryption is a fair response because it won't be feasible to enumerate every type of situation that results in sensitive data being put on the laptop (such as temporary files or source code). If someone was going to just add tax numbers to a list it leaves a lot out; if they say "sensitive data" it leaves a lot open to interpretation; if they list everything they can think of it'll be impossible to properly comply while still getting work done.

So perhaps it was a heavy handed approach handed down mindlessly, but it could also have been someone looking at the bigger picture. Knowing the intent as others said would help.

Re: Most “mandatory requirements” in corporations are imaginary

#355
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

> but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. The issue is that all the policy documents often only contain the One True Way to achieve their goals, while the goals remain unstated. The documents should always come with a rationale. And appending "exceptions may be granted for equivalent or better processes"…

I wonder if there's a value in simplicity of policy. Just like with coding. Sometimes you decide not to add more features or make something more efficient because it would make the code harder to maintain. If you have one blanket policy at your company, it cuts down on conversations. Case in point: you said that auditors don't understand the benefit of better hashing functions. If the policy allowed for "equivalent or better" maybe it would cause the confusion in different departments with different auditors many times over. If this is the case, though, I agree that this should be listed as the rationale, because I can imagine it's demotivating when people are required to do a worse thing for no apparent reason.

Re: Most “mandatory requirements” in corporations are imaginary

#356
post #75

In 1605 there was an attempt to blow up the British Parliament during the state opening by placing explosives in the cellars. 415 years later they still search the cellars for barrels of explosives, using oil lanterns and armed with swords. I feel that so many organisations are doing the same thing, maintaining an old solution for a problem that no longer exists. So I think it's just as, or more, important to apply t…

I think this is more typical in public administration. Employees just follow the existing rules/laws because it’s not their job challenging them, and decision makers are mostly concerned on shifting away blame from them. Nobody wants to be that guy that ordered to stop searching for a bomb, the day that a new bomb will be placed. The only reason why one should stop doing it is to gain efficiency (= be more productive…

Did you read the article?

Re: Most “mandatory requirements” in corporations are imaginary

#357
post #211
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

About five years ago, a place I was working at was selecting a new laptop for all employees. Mine was up for replacement, so I was interested in what they were picking. They'd arrived at some god-awful Lenovo gamer model. It fit the performance and price point they'd decided they needed. I said I'd prefer to have something smaller with less Christmas lights. "Policy is everyone has to have the same laptop, and some p…

[deleted]

Re: Most “mandatory requirements” in corporations are imaginary

#358
Working Nuclear at a shipyard, if you exceed exposure limits you are going to get fired. As soon as they don't have enough people for a hot job exposure limits are immediately raised. Wait it's so dangerous I would get fired but not so dangerous that it doesn't matter if you need it done ?

Re: Most “mandatory requirements” in corporations are imaginary

#359

Earlier quoted context omitted.

> It's probably by design, because as soon as you put a reason that becomes a target and people start to get ideas about why it doesn't apply to them. There's more to it than that. There are two separate groups of reasons: 1. The reasons a policy was put in place. ("Why did we do this?") 2. The reasons a policy succeeds. ("Why is this a good idea?") You can know the reasons in group 1. But nobody cares about those. W…

I was working in a throughout computing problem domain. About the time I got there, some asshole in HR had everyone’s (current and former employees) tax information on their work laptop and lost it. Tens of thousands of people, because there was no policy against putting such information on portable equipment. And as far as I’m aware there still isn’t. No, within the year (might have been a lawsuit, I can’t recall) n…

You act like this policy was intended as punishment instead of as risk mitigation.

Mandating full disk encryption is easy for IT to enforce. A policy of not putting sensitive information on laptops is valuable, but difficult to enforce. Encryption is a sound way to reduce the risk of harm when that policy is inevitably broken.

Full disk encryption also been the company-wide policy of everywhere I've worked in recent memory, fwiw.

Re: Most “mandatory requirements” in corporations are imaginary

#360
post #196

Earlier quoted context omitted.

> The issue is that all the policy documents often only contain the One True Way to achieve their goals, while the goals remain unstated. The documents should always come with a rationale. A reason can be argued against while a policy must just be followed. It's probably by design, because as soon as you put a reason that becomes a target and people start to get ideas about why it doesn't apply to them. Much like whe…

On the other hand, a reason can convince people, while a policy can be avoided, worked around or ignored while creating zero feelings of guilt.

I think it depends on the person. For myself (and probably many people with the hacker mindset), I don't like useless rules and want a justification or I tend to think I "know better" which is of course sometimes true and sometimes not.

I used to think this was a rebellious streak but perhaps it's just from that desire to know how things work. Absent a reason, I'll find my own.

A lot of people don't care either way, rules make life simple so there's no need to complicate it further.

Post reply on HN