3 ms·
Good IT security isn't invisible; it's there to prevent people from deploying poorly designed applications that require unfettered open outbound access to the i
by clwg 2y ago
Good IT security isn't invisible; it's there to prevent people from deploying poorly designed applications that require unfettered open outbound access to the internet. It's there to champion MFA and work with stakeholders from the start of the process to ensure security from the outset.
Mostly, it's there to identify and mitigate risks for the business. Have you considered that all your applications are considered a liability and new ones that deviate from the norm need to be dealt with on a case by case basis?
- darby_nine 2y agoI think the idea is that if you don't work with engineering or product, people will perceive you as friction rather than protection. Agreeing on processes to deploy new applications should satisfy both parties without restrictions being perceived as an unexpected problem.
- RHSeeger 2y agoBut it needs to be a balance. IT policy that costs tremendous amounts of time and resources just isn't viable. Decisions need to be made such that it's possible for people to do their work AND safety concerns are address; and _both_ of them need to compromise some. As a simplified example - You have a client database that has confidential information - You have some employees that _must_ be able to interact with the data in that database - You don't want random programs installed on a computer <that has access to that database> to leak the information You could lock down every computer in the company to not allow application installation. This would likely cause all kinds of problems getting work done. You could lock down access to the database so nobody has access to it. This also causes all kinds of problems. You could lock down access to the database to a very specific set of computers and lock down _those_ computers so additional applications cannot be installed on them. This provides something close to a complete lockdown, but with far less impact on the rest of the work. Sure it's stupidly simple example, but it just demonstrates the idea that compromises are necessary (for all participants)