|
|
|
|
|
by twojobsoneboss
648 days ago
|
|
TBF there are orgs at companies whose sole role is to play DEFENSE - lawyers, CSO etc… if they deem something too risky it IS their job to block it, and then it’s up to upper management to override them if the situation calls for it. Now that said they should still try to advance the mission within that framework, and not be lazy. |
|
Yes, their role is defense, but not insofar as to remove the profitability of the organization. In several orgs now I've seen the legal team blow contracts and the security team break the product and the IT team break development in the name of performing their role "correctly".
Brainless box checking is not part of defense, you must be willing to critically think about how to fit your role to your product or organization's profit motive.