Sometimes the "no" exists for a reason. Users don't understand this, and want the path of least resistance. Which is why policies exist for terminating such users from organizations.
But heh, infosec shouldn't exist and everyone should be able to BYOD, amirite? "Frictionless" or something like that?
> Sometimes the "no" exists for a reason. Users don't understand this, and want the path of least resistance. Which is why policies exist for terminating such users from organizations.
I will say that, in my experience dealing with government and DOD contractor security, is that they often fail to articulate the reasons. Users should understand, at some level, the threats you are trying to face. If someone comes to you for permission to do something and your "No" is backed up with nothing more than "That's the policy" or "Because I said so" you can expect them to be much more hostile to it and more likely to go around it.
But heh, infosec shouldn't exist and everyone should be able to BYOD, amirite? "Frictionless" or something like that?