3 ms·
> But putting that aside, employees installing “whatever software they want” is already a significant eyebrow-raiser. How do you ensure you are not a gatekeepe
by CSDude 4y ago
> But putting that aside, employees installing “whatever software they want” is already a significant eyebrow-raiser.
How do you ensure you are not a gatekeeper but also keeping company secure? Vetting software installations would be killer for any productivity at that scale I guess. Does it include npm install too which can run scripts or just desktop apps, chrome extensions?
- ryandrake 4y agoI agree with this. Allowing people to install software is not necessarily a security risk, but it can be if your company's overall security is vulnerable to hostile software on employee computers. In software development, you need to install software in order to do your job. I've worked at two "big tech" companies, and both of them had a policy of allowing employees (at least in engineering) to have root on their devices and install what they need to do their work. 1. We're intelligent adults and trusted to not fuck everything up, and 2. Internal systems are properly secured against fuck-ups, so a rogue compromised laptop on an internal network should not be able to screw anything up anyway. Then again, I've worked at smaller companies that thought their perimeter firewall and VPN for employees was adequate security. Once one got onto the internal network, there was no defense in depth. A compromised laptop (not to mention a disgruntled insider) that managed to get onto the internal network could literally wipe everything out.