4 ms·
I'm a former Big-4 sysadmin. I wrote a comment sometime ago explaining things from 'our' side. I'll go see if I can dig it up. Edit: Found it. A thread called
by oz 14y ago
I'm a former Big-4 sysadmin. I wrote a comment sometime ago explaining things from 'our' side. I'll go see if I can dig it up.
Edit: Found it. A thread called "Why everyone hates the IT department." I'll copy and paste to save y'all the trouble.
-----------------------------------------
I was a sysadmin for a financial services firm, and then for a Big-4 accounting firm, so I may have some perspective:
1. "For starters, I was not allowed to use my own equipment. They rattled off some gibberish about security and support even though my mail client supports SMTP and I can read Office files just fine. Also, for an agency focused on security their insistence on using Windows XP was baffling."
The first rule of System Administration [0] is to start every host in a known state. The reason for this is predictability - as the sysadmin, you know what to expect - certain software is installed, certain settings are configured, etc. You simply CANNOT manage systems at scale without this approach. Without it, testing, upgrades etc. are a shots in the dark.
Another issue is ownership. Let's say you get company email on your personal BlackBerry. You're mugged, and the device is stolen. A competent administrator will immediately issue a WIPE command from the BlackBerry Enterprise Server, so that all data is erased. But wait! Those picture of your daughter's recital were on the phone. They're gone, and you're gonna be pissed. With a company-owned device, the expectations are different.
A friend of mine once had to re-image the laptop of a senior executive. Turns out, the only pictures of her daughter's high-school graduation were on it. A year later, he's still having to feed her stories about ongoing efforts to retrieve the data...
Regarding Windows XP, OS upgrades are not to be done lightly. It requires very extensive regression testing for all Line-of-Business apps. Believe me, there isn't an IT guy there who doesn't want the upgrade to Win 7, but after a time in this business, you learn to tread carefully, as information systems can break in all sorts of subtle ways and management doesn't want to hear it.
2. "Secondly, I was told I could only use a certain browser because of another incoherent argument relying on "security." Interestingly, nothing was done to keep me from putting a pocket version of Firefox on a flash drive and connect to my own secure proxy. This is because the IT guys had no idea such wizardry was even possible."
Again, standards. When their enterprise web-based ERP system that's been tested in IE6 and works fine breaks when you're using Chrome 15.0.874.121 m, who's gonna get the call? Oh that's right. IT. Multiply that by a few hundred machines, and your network is unmanageable.
There exists technology to control USB drives, but in most organizations, it won't fly - they're simply too convenient. Besides, how do you expect the VP of Sales to load his iPod? Definitely shame on your IT guys for not blocking outbound connections to your own proxy at the firewall.
3. "Thirdly, for some reason print jobs were routed out of the office to a data center in San Angelo and then routed back to the printer down the hall. Printing a single page was non-deterministic and painful, never mind my final reports. This was a result of some state mandate about consolidating IT."
This sounds like the state's fault. They were probably sold a solution that promised centralized tracking / routing of print jobs, based on parameters such as job submitter, color vs monochrome, time of day, printer availability etc. Not IT's fault.
4. "And then there was the time I tried to install Notepad++ to do some minor dev work (they hired a CS undergrad to do financial work so I thought I'd do more than estimate results). 2 weeks later I was approved to use a similar text editor on the grounds that I already have a task bar to manage multiple documents - a tab bar is completely unnecessary and Notepad++ requires further scrutiny. 3 weeks later I had a Perl interpreter."
I was a sysadmin, and I had to get written and signed approval from my Manager, the Security Manager and the CIO to install any non-standard application. Pleasant? No. Necessary? Yes - everything needs to documented; otherwise these things spiral out of control quickly.
5. "At my current job they forced me to let them change the root password on my issued machine to something they knew and I didn't. I get why you do this: because you cannot fully trust people and I dealt with sensitive data; fine. Afterward I re-installed my OS and set my root password back. I don't understand why they don't think these things through."
Don't take this personally, but sysadmins hate people like you - you make unauthorized changes and make our lives difficult. Your IT guys sound incompetent though - why weren't BIOS passwords in place to prevent booting from CD? And since you say root password, sounds like you were in a UNIX / Linux shop. If you were in an AD environment, after reinstalling, you wouldn't have been able to join your computer to the domain without domain administrator credentials.
I understand that the situation sucks, but there are good (at least for a particular meaning of good) reasons why it is so. There is room for improvement on both sides.
Whew. Felt good to get all that off my chest. No hard feelings?
[0] Tom Limoncelli - The Practice of System & Network Administration.
--------------------------------------------
To a comment he made further downthread:
"I can't imagine it would take more than a cursory look at Notepad++ to vet it."
This, right here, is the issue. You simply don't know what is involved. "I can't imagine why you need to draw blood to see if I have AIDS, Doctor."
The specific program is not the issue. IT in the enterprise is all about centralized/standardized management and configuration. Every deviation from the standard is gonna increase the burden of maintenance.
How it normally works is that there is a single base OS / apps specification, and defined optional applications. EVERYTHING is tested against these, and guaranteed to work. This allows deployment against a global fleet to go smoothly. It's all about known quantities, which allows them to quantify everything.
Please remember that no IT guy wakes up in the morning and says "Yay! How can I make gatlin's life suck today???" It's more like, "Oh shit, last months patches are not being installed on those PCs in accounting. I wonder if it's the SCCM [0] client?" You find out 8 hours later that there's a conflict between $NON-STANDARD APPLICATION and the SCCM client. Have fun scouring Technet and forums to find a solution. These are the things that fill us with dread.
I'm not saying it's right. Just want you to see the other side.
[0]- Microsoft System Center Configuration Manager
- parasubvert 14y agoWhat you say has strong kernels of truth. The problem I have is the unstated conclusion, "therefore users must suffer". There are many mitigating approaches that DON'T require making the users' life hell. Before I begin, please understand I am not directing my criticism at you personally but rather the policies that you are defending. To your points: 1. Large scale environments with heterogeneity have approaches available like desktop virtualization or app containerization that ensure apps can be packaged in a self-contained way so that there's less need for full-OS control. Secondly, your remote wipe scenario makes no sense. If the device is stolen, you WANT your personal stuff wiped too! The root issue is highlighted by your re-imaging scenario: lack of regular, automated network backups. But that has very little to do with ownership amd control, and everything to do with the backup service quality and user training. 2. You're absolutely right about compatibility, but you'll notice the dodge to the original point. "Security" was defined as the reason for the use of a certain browser, not "Stadardization". Which we both know is horseshit - IE 6 has been long deprecated , unsupported, and a massive security hole, for example, to the point that its just budgetary negligence to keep insisting on that version. But again we get to "why hate IT" - its not standardization in reason, it's lying to your customers to cover up poor service. 4. I've run ops for multi tens-of-thousands of desktop environments and I have rarely seen that level of sign off required for non-standard applications except in highly secured (classified) contexts. It's draconian and unnecessary. Also note the misdirection: draconian approvals have little to do with "this requires documentation", it has to do with "preventing change". Of course exceptions require documentation, and at least line managerial approval, but requiring senior approval is a big red neon sign that the stated policy of the organization is "fuck change", rather than "embrace change and manage risk". Finally, to your point: "The specific program is not the issue. IT in the enterprise is all about centralized/standardized management and configuration. Every deviation from the standard is gonna increase the burden of maintenance." I agree with the first part. The latter part is where I say "that's the cost of doing business". The problem we have with much of old IT today is an operations-penny-pinching "change is bad and our processes are designed to prevent it" mentality rather than a balance between delivering new value and keeping it running, where "change is the norm and our processes are designed to manage it". Look man, I get where you're coming from, but after dealing with senior business execs for a long while, I feel IT-as-is is untenable. without a rethink, the abject hatred that many business people have towards IT will grow and rogue systems will flourish. Its like the PC days of 1983 agajn. The price to be paid by technology professionals for this acrimony will be large, similar to what mainframe professionals went through.