Posts by Russell Clarke
Last ←Newer Page 1 2 3 4 5 Older→ First
-
OnPoint: MSD's Leaky Servers, in reply to
Consultants can only be effective if the public servants they work for are any good.
-
OnPoint: MSD's Leaky Servers, in reply to
I'll give my favourite consulting answer: It depends.
-
If you'd started with an OSI Layer Number it could have saved a lot of typing :)
-
OnPoint: MSD's Leaky Servers, in reply to
Has that been confirmed? Looks like this could have happened as part of an IT ops balls-up, not helped by poor change management.
-
OnPoint: MSD's Leaky Servers, in reply to
... and where do those requirements come from? The business whose problem you are solving. Someone would have accessed and 'solved' the security considerations; maybe these items were given lower priority or put out of scope due to time or money ... again this would have been a business call.
I cringe when I hear of people blaming the business for the requirements. As a technology consultant who does a lot of requirements work, I'm working with the business to add value, not just to scribe ill-thought out blue sky wish lists.
Good business analysis consulting is about helping the business realise what they don't understand about technology, uncovering things they haven't considered, challenging their assumptions and highlight risks and issues, and persuading them to do things the right way.
Such risks include security, or lack thereof.
Perhaps the business did indeed treat this as a low priority, but I would expect any savvy technology partner to be raising their hands and shouting about this to the governance stakeholders, and saying it's not acceptable.
Saying 'we were just following orders' is a cop-out.
-
As Ira's and MSD's version of events is somewhat different, it's lucky they record all phone calls. All they need to do is release the recording in question.
Keith can probably tell them what folder it's in.
-
OnPoint: The Source, in reply to
your intellect is sort of on the level of a paua
Hey don't hate on the poor pauas!
-
OnPoint: MSD's Leaky Servers, in reply to
I feel your pain.
-
OnPoint: MSD's Leaky Servers, in reply to
Indeed. Having been around numerous government IT departments, linked infrastructure is wishful thinking.
-
OnPoint: MSD's Leaky Servers, in reply to
Correct.
Unless they have logged every system access from every entry point (which is deemed unnecessary in most IT environments, so I highly doubt they do it), they can't categorically know.
So they are saying this because they are:
a) Bullshitting us
b) Misinformed
c) All of the above