One admin proactively put a Baywatch photo as wallpaper : - )
We also "got Hoffed".
At another place I worked, the devs took a screenshot of their desktop and made it the lock screen image, so it looked like it was unlocked, just to annoy security (i.e. me!).
Overall the "buy treats for the office" rule helped to establish the habit even though I think we never followed through with it. We mostly just told newcomers that this is the rule and they locked their screen as expected. And ofc it turned "Hey, lock your screen!" into "Oh, you want to treat us?" which makes for a more cheerful way to remind people.
If you can't trust your coworkers in the same office, you should absolutely have private rooms that get locked, and shut down your machine completely every time you leave it.
And it gives some incentive to everyone to watch each others backs and keep each other honest. Which is how actual trust gets built IMO.
Knowing someone will catch and make sure you know you screwed up on something important before it became a bigger problem, rather than ignoring it and letting it fester.
Higher stakes areas, but most military combat MOS, LEO, skydiving, and climbing groups do similar things - always check that everyone around you has their act together (and give them shit if they miss something) so that there isn’t something serious that gets missed and gets someone or the group killed.
Or in this case, something serious gets missed and the company gets ‘killed’.
Think of it as tough love. And if they can dish it out, they’d better be able to take it or that is a whole nother level of ribbing that’s coming.
Precisely. So if you want to be safe, shut down completely the machine. Then all of the people you listed can't access it.
Suspend adds major security issues above and beyond either of these scenarios.
The majority of scenarios, none of those folks are able to do much to a locked machine without powering it off, which resets it to the state you were referencing.
They could install a hardware keylogger of course, and none of these protections would help.
It’s all tradeoffs. SCIF’s are better still after all, and a nightmare productivity wise.
The price of security is always wasted time.
> The majority of scenarios, none of those folks are able to do much to a locked machine without powering it off
But they are able to unlock it if they saw you unlock it yesterday.
If you have an encrypted hard drive and the key is in a usb you carry with you, they can't do anything.
Ah yes, the excellent security practice that if you see someone messing with someone else's equipment that's completely normal - praiseworthy, even - and if you don't challenge them on it, you get donuts.
You are legally liable for the messages you send; the access rights you have etc;
This is why shared accounts are one of the first thing a CISO/CIO will try to kill. It makes liability lie with the company and not the individual.
You will not be able to hide behind the fact you refuse or fail to secure your devices if someone sends a threatening message from your email account or if someone deletes the prod database.
Where shared credentials are required there is usually an access log associated: which ties individual named accounts to shared access rights in the event of eDiscovery or forensics.
Some trust is good, but if we really believed in trust then we wouldn't even both having access accounts with our names on them.
I recommend Deviant Ollam’s YouTube channel for an entertaining way to expand your assumptions
The real reason for the policy is so when some dumbass sends a dick pic from their work computer and gets fired for it, they can't claim "it wasn't me" and expect to keep their job.