The most comprehensive approach is to have an InfoSec policy portfolio which permeates into every corner of your organisation and dictates secure operating behaviours and mandates logical and physical security practices. This will include regular vulnerability scans on your code, your application stack and your infrastructure but it will also include instructions on how to classify data and how to handle data according to that classification.
Compliance is a achieved by marking a checklist which is why is fairly easy to botch it up. Sure you can do a subset of the checklist and have compensating controls for everything you've missed but the risk of non-compliance is not being able to do business (at best) and jail time (at worst) so you tell me what is your motivation to fail to meet the bare minimums of security best practices in card payment industry, aka, PCI-DSS.
Think of a castle; It will have several walls, towers, heavy doors, guards etc. It will also be placed in a hill, a mount or otherwise hard to access area (never in a vale for instance). It will also have the largest possible distance between the treasure hall and the front door. The threats your castle faces will continuously evolve, and the walls that stood up against bows and arrows are useless against turrets or cannons, so if you want to keep your treasure you do your best to be one step ahead and you don't get that by making sure your original walls are still in place or any other base requirements are still met.
Well, I guess it won't hurt if I offer my services for PCI guidance for startups here :-)
One thing to keep in mind is that PCI is a bare-minimum of security "best practices" that aims at validating that a company transacting with payment cards has an understanding of data classification and protection.
It's hard to correlate the two because there have been several policies put in place to reduce crime over the years, don't forget that our main industry is tourism and happy people spend more :-).
I can tell you that in the late 90s some areas of Lisbon were pretty dismal if not outright dangerous, and now the city seems much safer. I believe there are some studies on the effects on crime rates mentioned in one of the links above (my original comment).
Likewise, and also quite likely we are some of many thousands. Unfortunately I think in this case there are some people re-inventing the meaning of "digital" to signify young.
Enough grumpiness for one day, I'll go organize my Casio collection now.
Out of curiosity, if you had received an application from a 40 something who has been "digital" since before the internet was deemed a human right, would you have felt comfortable hiring him?
The big "eureka" moment was to start treating drug usage as a health issue instead of a criminal issue. It's not legal to buy or sell drugs in Portugal and if you are found carrying drugs they will be taken away from you (in most circumstances) but it's not a crime to consume them so you won't go to jail or face any prosecution.
From what I can remember, the original plan had some provisions for "assisted usage rooms" where trained personal would help guarantee that needles were clean and offer assistance to reduce ODs, but this never made it into the law because.
I can't be sue if US political influence had any weight on the final legislation, I mean, it would not be unheard of but on the other hand it would not be a matter of public record either.
It's not often that I have the opportunity to feel proud of the legislators in my home country, but Portugal has been on the leading edge of drug prevention and rehabilitation since we moved from a "war on drugs" to a program of health risk prevention and removed the weight of criminal charges and proceedings from the equation.
But theft, burglary and robbery are all crimes against property while drug consumption is about personal health, be it alcohol or tobacco or un-taxed drugs.
I think it's normal for startups to try to get things for free, be it software or work hours, and that's OK up to a point, but once a company reaches a plateau of business activity and operational maturity then it becomes a sign of poor management that they can't balance workload and workforce.
Out of curiosity, are you German? My experience with German companies was centred in the financial services sector out of Frankfurt and some tech companies out of Munich and overtime was never even suggested so I'm thinking there might also be some differences between the regions.
I agree with you completely. Even our work schedules are still based on the mandated daylight times which were created so that factories wouldn't have to keep their lights on for too long.
I'm an expat myself so I'm curious about this.. Were their visas tied to their work contract? Did they have their families living with them?
As an anecdote, when I first moved abroad I was single and didn't speak the local language (Dutch) so I didn't really have any incentive to interact socially outside of work and I ended up spending way too many hours in the office but just about managing to do my job competently because I was pretty sad and demotivated all the time and often doubted my decision to move abroad.
>One problem with organizations that bill by the manhour--law and consulting--is that even if the employee output diminishes, the firm still bills the same rate. There isn't a lot of incentive to keep your employees heads fresh.
I think you've hit a pretty good point straight in the head here. The article also seems to focus on a consulting company which very likely sells man-hour packages so it is on their best interest to have "heroes".
Well, I would classify it as work because it was a social interaction with a comercial intent.
If you were a contractor you could probably justify those expenses as part of your activity because it's culturally acceptable to engage in alcohol consumption with work relationships and you were representing your company while doing so.
That sounds like a horrible place to work and the arguments are complete nonsense.
To me, and maybe I'm just too cynical, but it sounds like the manager was telling you that the company needed 50% of your work to be off the books in order for them to meet expectations which is a sign of a poorly managed company. But then again it makes sense since, according to him, only people who show no capacity to self-manage, prioritise or delegate get promoted.
I think you did well in leaving that job, good on you!
The contrary belief is what is described in the article, where people are expected to stay in the office, or on-call for long hours to be valued as employees.
The sad thing is how many people actually live like this, defining themselves through what they do instead of who they are.