4 ms·
I was a sysadmin for a financial services firm, and then for a Big-4 accounting firm, so I may have some perspective: 1. "For starters, I was not allowed to us
by oz 15y ago
I was a sysadmin for a financial services firm, and then for a Big-4 accounting firm, so I may have some perspective:
1. "For starters, I was not allowed to use my own equipment. They rattled off some gibberish about security and support even though my mail client supports SMTP and I can read Office files just fine. Also, for an agency focused on security their insistence on using Windows XP was baffling."
The first rule of System Administration [0] is to start every host in a known state. The reason for this is predictability - as the sysadmin, you know what to expect - certain software is installed, certain settings are configured, etc. You simply CANNOT manage systems at scale without this approach. Without it, testing, upgrades etc. are a shots in the dark.
Another issue is ownership. Let's say you get company email on your personal BlackBerry. You're mugged, and the device is stolen. A competent administrator will immediately issue a WIPE command from the BlackBerry Enterprise Server, so that all data is erased. But wait! Those picture of your daughter's recital were on the phone. They're gone, and you're gonna be pissed. With a company-owned device, the expectations are different.
A friend of mine once had to re-image the laptop of a senior executive. Turns out, the only pictures of her daughter's high-school graduation were on it. A year later, he's still having to feed her stories about ongoing efforts to retrieve the data...
Regarding Windows XP, OS upgrades are not to be done lightly. It requires very extensive regression testing for all Line-of-Business apps. Believe me, there isn't an IT guy there who doesn't want the upgrade to Win 7, but after a time in this business, you learn to tread carefully, as information systems can break in all sorts of subtle ways and management doesn't want to hear it.
2. "Secondly, I was told I could only use a certain browser because of another incoherent argument relying on "security." Interestingly, nothing was done to keep me from putting a pocket version of Firefox on a flash drive and connect to my own secure proxy. This is because the IT guys had no idea such wizardry was even possible."
Again, standards. When their enterprise web-based ERP system that's been tested in IE6 and works fine breaks when you're using Chrome 15.0.874.121 m, who's gonna get the call? Oh that's right. IT. Multiply that by a few hundred machines, and your network is unmanageable.
There exists technology to control USB drives, but in most organizations, it won't fly - they're simply too convenient. Besides, how do you expect the VP of Sales to load his iPod? Definitely shame on your IT guys for not blocking outbound connections to your own proxy at the firewall.
3. "Thirdly, for some reason print jobs were routed out of the office to a data center in San Angelo and then routed back to the printer down the hall. Printing a single page was non-deterministic and painful, never mind my final reports. This was a result of some state mandate about consolidating IT."
This sounds like the state's fault. They were probably sold a solution that promised centralized tracking / routing of print jobs, based on parameters such as job submitter, color vs monochrome, time of day, printer availability etc. Not IT's fault.
4. "And then there was the time I tried to install Notepad++ to do some minor dev work (they hired a CS undergrad to do financial work so I thought I'd do more than estimate results). 2 weeks later I was approved to use a similar text editor on the grounds that I already have a task bar to manage multiple documents - a tab bar is completely unnecessary and Notepad++ requires further scrutiny. 3 weeks later I had a Perl interpreter."
I was a sysadmin, and I had to get written and signed approval from my Manager, the Security Manager and the CIO to install any non-standard application. Pleasant? No. Necessary? Yes - everything needs to documented; otherwise these things spiral out of control quickly.
5. "At my current job they forced me to let them change the root password on my issued machine to something they knew and I didn't. I get why you do this: because you cannot fully trust people and I dealt with sensitive data; fine. Afterward I re-installed my OS and set my root password back. I don't understand why they don't think these things through."
Don't take this personally, but sysadmins hate people like you - you make unauthorized changes and make our lives difficult. Your IT guys sound incompetent though - why weren't BIOS passwords in place to prevent booting from CD? And since you say root password, sounds like you were in a UNIX / Linux shop. If you were in an AD environment, after reinstalling, you wouldn't have been able to join your computer to the domain without domain administrator credentials.
I understand that the situation sucks, but there are good (at least for a particular meaning of good) reasons why it is so. There is room for improvement on both sides.
Whew. Felt good to get all that off my chest. No hard feelings?
[0] Tom Limoncelli - The Practice of System & Network Administration.
- MatthewPhillips 15y agoEven large corps give their programmers admin on their own computers. No average or above programmer would work for a company where they had to request permission to install a text editor. That's simply unacceptable.
- gatlin 15y agoI resent that! :) But since I do have admin and I'm leaving soon, maybe not ...
- samirageb 15y agoI think you would find that to be simply not true depending on the nature of the organization. Work for the government, or any security conscious organization, and you'll see how little control you have (for good reason).
- ShardPhoenix 15y agoThis attitude might be ok for managing the average office worker's machine but when it comes to jobs like programming that are not highly regimented, it's just not good enough. Get out of my way and let me do my job. I'm glad I'm at a company that lets us do whatever we want to our machines (we use a VM for the few things that require IE).
- oz 15y agoI'm also a programmer, and agree completely - I think devs should have admin rights on their boxes, and at the very least access to VMs for testing Ultimately, it's an issue of trade-offs: I guarantee that since you're allowed to go wild on your machine, the IT cost to support devs is higher. It's not right or wrong, simply a matter of trade-offs. It's up to an individual organization to determine an acceptable trade-off. Edit: Grammar
- mkopinsky 15y agoOTOH, the IT cost to support competent users is lower, since they don't come crying to you every time the printer needs paper. In the scheme of things, I wonder which effect predominates.