One chestnut from my history in lottery game development:

While our security staff was incredibly tight and did a generally good job, oftentimes levels of paranoia were off the charts.

Once they went around hot gluing shut all of the “unnecessary” USB ports in our PCs under the premise of mitigating data theft via thumb drive, while ignoring that we were all Internet-connected and VPNs are a thing, also that every machine had a RW optical drive.

  • Hogger85b
    link
    fedilink
    682 years ago

    Set the automatic timeout for admin accounts to 15 minutes…meaning that process that may take an hour or so you have to wiggle the mouse or it logs out …not locks… logs out

    From installs to copying log files, to moving data to reassigning owner of data to the service account.

      • @fat_stig@lemmy.world
        link
        fedilink
        English
        02 years ago

        Mine was removed by Corporate IT, along with a bunch of other open source stuff that made my life bearable.

        Also I spent 5 months with our cyber security guys to try and provide a simple file replication server for my team working in a remote office with shit internet connectivity. I gave up, the spooks put up a solid defense, push all the onerous IT security compliance checking onto my desk instead of taking control.

        Not as bad as my previous company though, outsourced IT support to ATOS was a nightmare.