3 ms·
At some point, you need to trust your staff. If you do not trust them to keep confidential information private, then why are you giving them the information in
by codingdave 1y ago
At some point, you need to trust your staff. If you do not trust them to keep confidential information private, then why are you giving them the information in the first place?
- mingus88 1y agoYou can’t really sniff out disgruntled employees until they act on it.
- rf15 1y agomaybe if your employees are disgruntled and feel like they can't talk to you about it you are shit at your job
- Traubenfuchs 1y agoI had aggressively disgruntled colleagues that couldn‘t deal with being fired, having 3 month notice period and 2 extra salaries and called the CEO names via anonymous all hands meeting. Many people are babies.
- MattPalmer1086 1y agoPeople make mistakes. Why not put a simple control in that doesn't get in the way of any legitimate use?
- Aachen 1y agoThe mistake being, what, accidentally sneezing onto the printscreen button so hard it depresses? This isn't the same as leaving a tool in someone; making and misplacing a screencap take active doing. If your meeting participants actively want to put data where it doesn't belong, the solution isn't accident prevention
- MattPalmer1086 1y agoThe mistake being to intentionally take a copy of something confidential, because you forgot it was supposed to be confidential. People do things like this all the time. It's essentially a guardrail. It can be easily circumvented if someone was being actively malicious.
- Aurornis 1y agoI have some friends who work in a medical facility. They get an extreme amount of training on patient privacy laws and constant reminders not to get sensitive patient information on to their personal devices. Despite the intense training and constant warnings, it happens constantly. And that’s just the cases they know about and address. You have to be able to trust your staff, but you also have to be realistic that any organization at scale will have people who either don’t care or don’t think and it happens frequently.
- hedora 1y agoIn the US, medical privacy laws serve exactly two purposes: 1) Prevent the patients from suing after a data breach or intentional sale of their medical records, regardless of negligence. 2) Transfer as much money as possible from health care to privately owned businesses in the compliance industry. Very few computer security lessons from that industry generalize to other parts of the economy.
- leovander 1y agoExtreme amount of training? More like once a year online HIPAA test that everyone blows through with the occasional CISO phishing campaigns that at least one person fails.
- 7bit 1y agoThis is a very weak argument.