Live data from Hacker News

Most “mandatory requirements” in corporations are imaginary

nibblestew.blogspot.com

181–190 of 405 posts

Re: Most “mandatory requirements” in corporations are imaginary

#181
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

Side issue, but I have cause to mention Chesterton's Fence so often that it's become a real frustration that there is no Wikipedia article about it — only this essay about why Wikipedia contributors should honour it. I wish there was an actual article I could point to when I want people to know about it. (Why don't I just make one? I have basically given up on making substantial contributons to Wikipedia since the De…

> Why don't I just make one? I have basically given up on making substantial contributons to Wikipedia

You don't have to put it up on Wikipedia. You could put it on Neocities or Medium or wherever.

Re: Most “mandatory requirements” in corporations are imaginary

#182

Earlier quoted context omitted.

In Europe (did a lot of flying lately) the 100ml still stands for sanitizers. You can go over the 100ml only if you got a baby with you and they allow the water/milk for the baby.

Funny thing is: once you travel with a baby, basically anything goes. 1L water bottle? no questions asked. Even though the baby won't drink 1L of water on a 2-hours flight. The whole restriction on liquids is fairly ridiculous, and even more of a security theater than most of the other checks. And I think the security guards know it, and use any excuse to look the other way.

To be fair, traveling with a baby makes you much less likely to attack a plane.

This exception makes the TSA's policy more pragmatic and reasonable.

The harm of denying a baby milk or formula is worse than the risk of terrorism in this case. Not to mention is that it lowers the incidence of crying babies on flight.

The same logic could be applied to hand sanitizer restrictions in a global pandemic. Allowing people to carry a larger size could save more lives than the risk it poses. This is especially true when shortages can make it difficult to buy a travel size.

Re: Most “mandatory requirements” in corporations are imaginary

#183
post #75

In 1605 there was an attempt to blow up the British Parliament during the state opening by placing explosives in the cellars. 415 years later they still search the cellars for barrels of explosives, using oil lanterns and armed with swords. I feel that so many organisations are doing the same thing, maintaining an old solution for a problem that no longer exists. So I think it's just as, or more, important to apply t…

I think this is more typical in public administration. Employees just follow the existing rules/laws because it’s not their job challenging them, and decision makers are mostly concerned on shifting away blame from them. Nobody wants to be that guy that ordered to stop searching for a bomb, the day that a new bomb will be placed. The only reason why one should stop doing it is to gain efficiency (= be more productive…

> Employees just follow the existing rules/laws because it’s not their job challenging them, and decision makers are mostly concerned on shifting away blame from them

>but the efficiency metric is non existent in public administrations.

And both of these have very insidious downstream consequences.

The nature of government employment selects over time for people who are dedicated to process for process sake so of course there's nobody around who asks "why?" and nobody around to say "the tradeoff is worth it let's do X instead".

Politicians and high level bureaucrats control the resource streams. The less efficient the larger the resource streams and the more power they have. Not only is there no incentive for efficacy at a high level because "screw it's other people's money" but there is an incentive for inefficiency because it lets the people calling the shots preserve/grow their power.

The only time you get a push for efficiency is deep in the bowels of a silo/fiefdom where the teams are small and the organizational unit's resource inputs are static but their performance metrics are pegged to outputs. Of course this sentiment dies on the way up the org chart because resources are mostly a "use it or lose it" type thing.

One effect is that this drives away exactly the kind of results driven people who should be working as public service.

Another effect is that it cements the status quo such that it is basically impossible for a government or government unit to pivot from "being inefficient and generally sucking" to "decent use of taxpayer's money" without an existential crisis for the organization. Basically nobody says "hey, WTF are we doing" while the organization is becoming an ineffective graft ridden mess. Everyone just keeps their head down until a shock forces them to actually solve the problems.

This is why you never see government organizations in rich places like NYC, Boston or DC clean themselves up but you occasionally see government organizations in poorer places like Buffalo or Newark clean house because as painful as making do with less and cleaning your own house is to those kinds of organizations the alternative of having politicians do it for you to win brownie points is worse. The rich places can just paper over their organizational problems with money. The poorer places have to stay on task or clean house much more frequently if they don't because there's less money to float along on.

BigCos have some similarly bad feedback loops but it's much more common to see them lop off an org that's dead weight because when the metric the people at the top use is profit you get much more incentives value driven behavior.

Re: Most “mandatory requirements” in corporations are imaginary

#184
post #126

Earlier quoted context omitted.

several levels of auditors were effectively asking us to downgrade to comply with their policy without even understanding the difference The auditors' policy? Are you sure? An auditor's job is to check if you're doing what you say you should be doing. If you're arguing with an auditor then you're essentially arguing with your own organisation without any hope winning the argument.

Not really a fair assessment. An auditor's job is often to check if you're doing what an external standard says you should be doing (SOC 2 => AICPA trust principles; FedRAMP => NIST 800-53, etc.). Unfortunately, these external standards may be written vaguely and while you may have policies that define X as Y, the auditor doesn't have to accept your answers. For example, when PCI requirement 5 says "Deploy anti-virus…

No, they check if you're doing what an external standard that you purport to follow is being followed.

You dont have to claim that you follow some standard that actually makes you less secure, you are just not going to be able to sell to clients who are also sheep in this manner (read: everyone.)

Re: Most “mandatory requirements” in corporations are imaginary

#185
post #63

I had this experience with some companies I was interviewing with. They would force me to submit my most recent payslip from my previous employer. I gave up after some protest, coz they could not have proceeded with my interviews without it.

Illegal in many other parts of the world (e.g. in Europe).

OP is probably from India, this is the norm here. Most companies will ask you for your last months of payslips, reason? Nobody knows.

In general, companies treat you are like a criminal trying to con them. Submit previous payslips, last company's relieving letter, contacting the previous company, stupid non-compete clauses, bond clauses and list goes on.

This is unlikely to change as most employees don't really have the bargaining power to question the rules, the workforce is abundant, they can just tell you to fuck off and hire someone else.

Re: Most “mandatory requirements” in corporations are imaginary

#186
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

Side issue, but I have cause to mention Chesterton's Fence so often that it's become a real frustration that there is no Wikipedia article about it — only this essay about why Wikipedia contributors should honour it. I wish there was an actual article I could point to when I want people to know about it. (Why don't I just make one? I have basically given up on making substantial contributons to Wikipedia since the De…

Just use this: https://en.wikipedia.org/wiki/G._K._Chesterton#Chesterton's_...

Re: Most “mandatory requirements” in corporations are imaginary

#187
I work in medical devices and we have a lot of that. We have tons of tedious processes that take a lot of time and don’t improve the product at all. Often they prevent fixing of problems. When you ask why things are that way the answer usually is “the FDA requires it”. But often when you read the latest regulations things it’s easy to see ways to improve our processes and still be compliant.

I think the problem is that the company has found something that works in an acceptable manner and there is a big risk that any change will have unforeseen consequences so people stick to what works, no matter how badly.

There is another set of internal rules that clearly make life of one function easier at the expense of others. Again, these are very hard to challenge.

Re: Most “mandatory requirements” in corporations are imaginary

#188
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

> In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place

I disagree. I've worked in a BigCorp and many requirements were in place not due to reason but due to feelings and inertia. The "butts in seats" requirement was one of the main ones. Even after showing my boss that I could at the very least work equally as effectively from home, he still felt it wasn't OK for me to work at home more than once a week. And never underestimate the power of inertia. Things are this way, they've always been this way.

Re: Most “mandatory requirements” in corporations are imaginary

#189

Earlier quoted context omitted.

Side issue, but I have cause to mention Chesterton's Fence so often that it's become a real frustration that there is no Wikipedia article about it — only this essay about why Wikipedia contributors should honour it. I wish there was an actual article I could point to when I want people to know about it. (Why don't I just make one? I have basically given up on making substantial contributons to Wikipedia since the De…

What is this Wikipedia "Deletion Police"? I haven't heard of quality content being consistently deleted.

I often hear it called Deletionism, and there is a Wikipedia article about it:

https://en.wikipedia.org/wiki/Deletionism_and_inclusionism_i...

It cites a quote from Paul Graham (cofounder of Y Combinator) that begins "Deletionists rule Wikipedia."

Re: Most “mandatory requirements” in corporations are imaginary

#190
post #138
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

An example, I'm unable to resolve so far: ISO 26262 includes the requirement to prevent “implausible values, execution errors, division by zero, and errors in data flow and control flow” (8.4.4). I'm confident the division by zero aims at integer division because the result is undefined. For floating point, division-by-zero is perfectly fine and well defined by IEEE 754. Nevertheless, our safety folks require us to e…

Just because division by zero produces a value doesn't mean the value means anything or should ever have been obtained. Division by a very small number and division by zero should NOT have the same effect. That is the error which you're supposed to catch by not dividing by zero in the first place.
Post reply on HN