3 ms·
The first point would be gamechanging. Also used to do govt work. I'm sure everyone has stories. My takeaways. 1) Understand what people need -> AND LET THEM
by random5634 6y ago
The first point would be gamechanging.
Also used to do govt work. I'm sure everyone has stories.
My takeaways.
1) Understand what people need -> AND LET THEM DO IT.
2) DO NOT ADD A SINGLE NEW THING with the IT / automation. If the old system doesn't have it DO NOT ADD IT. No 20 extra fields for demographics if you didn't track that before. That can be added later IF it's a MUST.
If they would take away all various fifedoms and hassle - people actually would bring a lot more tech into gov. Let the local business / division people make a decision. The only requirement be that they go through a 1 hr training and be exposed to 3 packages in their space (ie, do demos no powerpoint).
Take away all other requirements. Be OK with smaller failures. Govt is so scared of just letting folks try stuff out that everything turns into a 100M project that goes totally of the rails in terms of scope etc (ie, what people need / want is long forgotten, it's what MANAGERS want that gets emphasized).
Result - even if successful (rarely) for downline workers the software brings TONS of extra (not less) work.
----
My own examples. The IT folks say that passwords have to change every 90 days. Google for example does not default to this (stupid) rule - they push two factor without SMS (which is better). Bam - you are out or have to pay for a "security" solution on top of whatever standard platform you are using with admin rights that can force rotate passwords (and is a MASSIVE backdoor itself vs self-serve password mgmt).
Then purchasing. We need an ipad to edit some videos. OH, Apple is not supported. This is 10K employees but you can't get an apple product to use unless the city atty will sign off on a variance (no chance).
- wslack 6y ago> The IT folks say that passwords have to change every 90 days This is explicitly not the NIST recommendation (the group in gov that sets some security standards), but the word is not getting out quickly.
- random5634 6y agoFor a long time this must have been on the recommendation list - because password forms with insane complexity (12 charachters, upper, lower etc), but then non copy pastable forms and 60 day change requirements remained very common. The current IRS requirements are 90 day password changes. Ergo - many people write their passwords down in a text document next to the software launch icon. What I don't get - if your computer is hacked, and you force people to write down their passwords on the computer being hacked, they will even more easily be able to access the systems you have access to. Google seems to get this right. I have had same password for 20 years, if I login with a new device I use my MFA (no SMS). If I do a security sensitive op I need to login and do an MFA again (password reset etc). I imagine they actually monitor and rate limit bad login attempts etc. A 10 character password is really fine then in my view as an example.