3 ms·
> Access control and integration with authentication platforms, logging / auditing, various layers of site-wide policies on all configurable features. Preferred
by jerrac 11y ago
> Access control and integration with authentication platforms, logging / auditing, various layers of site-wide policies on all configurable features. Preferred platforms (i.e.: Windows servers and MS SQL these days, Solaris and/or Oracle 10-15 years ago.) Lots of reporting features and professional service to support all of that.
From the sounds of it, you're running into how hard it is to balance security and usability. Personally, I prefer security, but I'm sure I'd say otherwise if someone was blocking me due to an old, outdated, policy.
As for antiquated web browsers, yeah, that's annoying. And it amazes me that there are companies out there who don't update their products, even when they're paid millions of dollars... Then there are the users who don't want to update....
> Another real annoyance is very slow deployment cycles. Getting client change control approval for even bug fix releases, let alone major upgrades is a real pain, doubly so if any hardware / resource requirements go up and now it's a capex line item that needs CFO approval. I envy the cloud folks.
That's not something I have had experience with. Sounds painful. Makes me glad to work in a smaller community college where I get to do mostly whatever I need to.
- acveilleux 11y ago> From the sounds of it, you're running into how hard it is to balance security and usability. Personally, I prefer security, but I'm sure I'd say otherwise if someone was blocking me due to an old, outdated, policy. What happens is the application will end up requiring dozens of roles juggling easily a hundred (discrete) privileges. The LDAP, AD, X.500 enterprise directory you have to integrate with will not have that granularity so a whole set of interfaces will be needed to map group(s) from the directory to role(s) and then you need an overlay to allow super users to customize the imported users. And you somehow need to handle the case where user disappear from the directory without breaking auditing. And you need to grow bulk modification interfaces and import interfaces for those user/roles/privileges. And then somehow make the UI human usable. And suddenly you'll need special "users" for anonymous session that are API launched, a whole API authentication layer and your load balancer now suddenly need to be session aware, and they want single-sign-on. And we've not actually implemented any core functionality, just satisfied the security dude that this will be SoX/HIPPA/ISO-27001 compliant.