5 ms·
Which just proves that BigCo policies are written by bozos. All this means is that people take all the customer data before you submit your notice. Different
by avinium 7y ago
Which just proves that BigCo policies are written by bozos.
All this means is that people take all the customer data before you submit your notice.
Different story if someone's fired for cause, of course.
- dahdum 7y ago> Which just proves that BigCo policies are written by bozos. I know it feels good to say that, but isn't it more likely they are just rational human beings making decisions by weighing a wide array of facts - most of which we aren't even aware exist?
- manigandham 7y agoOr perhaps policies are written by smart people who have lots of experience and data that shows that it's a time of increased risk that's not worth it when your company has valuable trade-secrets, customer relationships, and other confidential data. Sometimes it's as simple as protecting team productivity and morale. I guess if it's a small startup with 5 people it doesn't matter, but please don't assume that everyone at all these major companies is a "bozo".
- asark 7y agoProbably it's mostly "we did something!" box-ticking. Having policies matters more than their being effective or sensible, generally.
- manigandham 7y agoWhat are you basing this on? Seems like the same assumptions as the other comment. I've explained several reasons why it makes a difference.
- asark 7y agoThe vast majority of business decisions I've seen around security have boiled down to "we need to be able to put something on this sheet/slide, and it needs to be something that will raise the fewest questions—so, exactly what everyone else does". Effectiveness or actual purpose isn't on the radar, and improving security through these processes does happen but is basically a side-effect or an accident. Some of these things probably are based in some real need (at whichever business started the ball rolling) and tend to be useful for that reason, but I guarantee a lot are just doing things for the sake of being able to say something was done after an incident, get that in place at a couple bigcos and pretty soon it's a standard industry practice, even if it's not sensible at many places implementing it. This smells very much like one of those.
- deleted 7y ago[deleted]
- manigandham 7y agoThis is not about security, it's HR. These policies are for mitigating potential risky behavior, not to stop otherwise malicious actors. It's about managing normal workers during a time period that will have decreased or even negative productivity and can cause team cohesion issues. For example: a salesperson wont work on new deals and may even sabotage existing deals that they know they can pick up at a new company. Sometimes it's as innocuous as copying their contacts or browsing through new deal flow which they don't need to know about if they're going to a competitor. A manager might stop getting reports from their team or put off other tasks. Sure it may all go well but there are still hundreds of reasons to avoid all this potential risk. HR departments aren't stupid or useless. They exist to manage the most complicated part of any business: the people. If you haven't ever worked in these sectors or departments, I'd recommend against assuming they have no value.
- asark 7y agoI don't assume they have no value. And this general sort of decision-making happens all over in companies (and the public sector) all the time. It's not limited to any particular department, it's just a little more checklisty and cargo-culty in the security world (and I would expect in HR where it concerns procedures like this). [EDIT] to provide some context, I've come to see a huge portion of decisions about policies, procedures, tools, and more as basically personal and departmental risk mitigation and blame-deflection rather than anything aimed at helping a business function. At a high level that's the goal, but in the details it becomes about making sure there's always something or someone to point a finger at. Conveniently these things don't always need to be directly relevant or useful, so long as something's being done and can be put on a powerpoint slide when the C-suite or someone at some company yours is courting asks a question. As long as "what are we doing about X?" can be answered with "Y and Z, both of which are standard industry practices, see this HBR article about how IBM does it" you're good.
- reallydude 7y ago> Or perhaps policies are written by smart people Where has that been true? JPMorgan has policies on notice depending on your position (engineer II has a different notice window than a IV). During the ISO9000 heyday, it was SHOCKING to see how random HR exit policies were between hundreds of companies, with a bias toward traditional 2 week notice. The norm is that smart people aren't in HR, because smaller companies outnumber smaller ones.