{"id":13626,"date":"2018-10-19T02:30:05","date_gmt":"2018-10-19T10:30:05","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2018\/10\/19\/news-7393\/"},"modified":"2018-10-19T02:30:05","modified_gmt":"2018-10-19T10:30:05","slug":"news-7393","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/10\/19\/news-7393\/","title":{"rendered":"Policies and paper trails &#8212; our new best friends"},"content":{"rendered":"<p><strong>Credit to Author: Sharky| Date: Fri, 19 Oct 2018 03:00:00 -0700<\/strong><\/p>\n<p>This IT pilot fish works with lots of sensitive data &#8212; and that means <i>really<\/i> sensitive, such as child abuse investigations.<\/p>\n<p>&#8220;Until a few years ago, I had access to all that data, so I could write ad-hoc reports against it,&#8221; says fish. &#8220;We &#8216;systems&#8217; people were given access to everything, so we could troubleshoot application problems for the users.<\/p>\n<p>&#8220;Then one day I was called into the CEO&#8217;s office. He told me that according to the logs, I did a search against the Child Welfare data for a particular family on a date and time six months earlier &#8212; and wanted to know why I did the search.&#8221;<\/p>\n<p>As best fish can recall, he was doing the search to troubleshoot a particular report that one caseworker was trying to run. To do that, he used his own workstation to duplicate the steps that the caseworker took to get to the error.<\/p>\n<p>Trouble is, fish has no documentation of that event. And though fish wasn&#8217;t violating any existing agency security or privacy policy when he accessed the data, the CEO decides to level charges against him for inappropriate use of confidential data &#8212; and suspend him for 30 days.<\/p>\n<p>Fish points out he didn&#8217;t release any confidential data into the wild, or use his access to the data for any personal benefit. All he was doing was his job &#8212; helping the users do <i>their<\/i> jobs.<\/p>\n<p>The CEO is unmoved.<\/p>\n<p>&#8220;If it weren&#8217;t for my union, I&#8217;d have lost my house due to this arbitrary, capricious and ill-advised decision on the part of the CEO,&#8221; fish says. &#8220;As it was, the union local president &#8216;plea bargained&#8217; me down to a one-day suspension, and that was that.<\/p>\n<p>&#8220;And while what I did wasn&#8217;t a violation of policy at the time, after the initial meeting with the CEO and before the charges letter, the VP and I created a new policy. Now we &#8216;systems&#8217; people don&#8217;t have access to any of the systems of record, and if we need it for troubleshooting, there&#8217;s a form to fill out.&#8221;<\/p>\n<p style=\"font-size: 0.875em;\"><strong>Sharky always files off the identifying marks from your true tales of IT life.<\/strong> <i>So send me your story at <a href=\"mailto:sharky@computerworld.com\" rel=\"nofollow\">sharky@computerworld.com<\/a>. You can also comment on today&#8217;s tale at <a href=\"https:\/\/plus.google.com\/u\/0\/communities\/113252326043973101081\" rel=\"nofollow\"><strong>Sharky&#8217;s Google+ community<\/strong><\/a>, and read thousands of great old tales in the <a href=\"http:\/\/www.computerworld.com\/search?query=+sharky&amp;s=d&amp;start=0\" title=\"Sharky's archives on easier-to-navigate pages\"><strong>Sharkives<\/strong><\/a>.<\/i><\/p>\n<p><em>Get Sharky&#8217;s outtakes from the IT Theater of the Absurd delivered directly to your Inbox. Subscribe now to the <a href=\"http:\/\/www.computerworld.com\/newsletters\/signup.html\" title=\"Daily Shark Newsletter subscription page\">Daily Shark Newsletter<\/a>.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3314937\/security\/policies-and-paper-trails-our-new-best-friends.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Sharky| Date: Fri, 19 Oct 2018 03:00:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>This IT pilot fish works with lots of sensitive data &#8212; and that means <i>really<\/i> sensitive, such as child abuse investigations.<\/p>\n<p>&#8220;Until a few years ago, I had access to all that data, so I could write ad-hoc reports against it,&#8221; says fish. &#8220;We &#8216;systems&#8217; people were given access to everything, so we could troubleshoot application problems for the users.<\/p>\n<p>&#8220;Then one day I was called into the CEO&#8217;s office. He told me that according to the logs, I did a search against the Child Welfare data for a particular family on a date and time six months earlier &#8212; and wanted to know why I did the search.&#8221;<\/p>\n<p>As best fish can recall, he was doing the search to troubleshoot a particular report that one caseworker was trying to run. To do that, he used his own workstation to duplicate the steps that the caseworker took to get to the error.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3314937\/security\/policies-and-paper-trails-our-new-best-friends.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[714],"class_list":["post-13626","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13626","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=13626"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13626\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=13626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=13626"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=13626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}