| Perfil de YuenYHYeong Huey's spaceBlogListas | Ayuda |
|
27 julio A Humble Muggle CommentEvery beginning has its ending.............Harry Potter 7 marked the last ending of Harry Potter series. Finished reading it and sense some characters and story lines reflected upon reality of life.
Feeling sad on professor Severus Snape "tragic" death. He was a good man but being misunderstood for his whole life because he acted "weird" during his teenage life and shown the tendency towards Dark Magic. Professor Dumbledore was selfish person during his teenager life. How James humiliated Snape during their Hogwart school life and James possesion of Invisibility Cloak explained much of his undetected wrongdoing at school.
Maybe what Snape had said is correct ............"They're not as wonderful as everyone seems to think they are." However, society favour upon Good Force rather than Dark Force and hence made James & Dumbledore great men in Hogwart.
So.........What is the definition of good person and bad person? 15 julio Another Check Point MeetingLast Thursday,my project partner informed me to attend a checkpoint meeting on Friday morning 10am at client office. As usual, I had a cup of Nescafe at the front stall opposite the client office. My project partner reached at 9.30am, and we had breakfast at the food court. (Luckily we did that). At 10am sharp, both of us, grabbed the chairs and sat on the second row of the meeting room table, because the front row occupied by the chairman, the speakers, and the vendors who are going to do presentation.
Meeting started around 10.30am after everything setup to begin our Friday. There were 5 vendors in the meeting room waiting for their turn to present their security implementation on their respective system to the "Mighty Judge of Data Security Unit". Vendor A, which developed the biggest part of the system started their presentation, and this is where his nightmare begun. As he went through his system against the Central Bank guideline checklist, which I saw was filled up with details and complied to all the applicable items in the listing with the word "Yes".
The show began here....
Judge : Where is my Central Bank guideline checklist? Why no one prepare the checklist and we just go through the list?
After 10 minutes of photostating process...........
Checklist : All login IDs must have an expiry day and set to inactive after a period of inacivity set in the policy.
Judge : Do your system have that?
Vendor A : Yes.
Judge : However, my department may not need to login into the system if no user complaining for a very long time. So, my department's IDs shouldn't have expiry date.
Vendor A : Err.....(he is starting to scratch his head -- exceptional case?).
Checklist : All system should have system log files.
Judge : Do your system have that?
Vendor A : Yes. For process A, log file store in location A. Process B which is in another system, log file stores in location B.....etc.
Judge : Is your system log file easy to understand? Can you make it understandable by non-IT savvy?
Vendor A : Hmm.....(he is lost in the space of confusion. System log file to be read by non-IT savvy? After the system finished development?)
Judge : (Turned her head to the chairman) In our organization, who is responsible to read the system log file?
Chairman : Currently, there is no such person exist.
Judge : I think your department should assign someone to read the log file.
Chairman : You must be joking, your department is an IT department, why not your department just take over the job?
Judge : Nope. That shouldn't be. Auditor, isn't your department to review the log file to scrutinize if there is any abuse to the system?
Auditor : Ha?
(And this finger pointing continue for 10 minutes without any conclusion except Vendor A still confuse in his world)
This "integerrogation" process continue for more than 2 hours just for Vendor A system because of Judge's new requirements and questions branches out from the Central Bank checklist. Vendor A did complied to all the checklist items but what he not aware of are those "exceptional cases" and he needs to make additional changes. This happened to us last time, we encountered the same problems and we were having the thoughest time to make last minutes changes without any extension of dateline. When we requested for the "exceptional cases" checklist from the Bank, the Bank answered "NON existing item found". Today, we see our fellow vendors encounter the same problems, we saw our "past".
Human never learn from their mistakes and past experiences. All new vendors faced the "exceptional cases" incident with the "Judge", not that we never comply to Central Bank ruling, but we are not inform of such "exceptional cases" and we are forced to make changes within shortest time. "Judge" always attend the project meeting just before the UAT begins and vendors will struggle before UAT begin.
If "exceptional cases" is such crucial to our system development, why no one in the Bank have the initiative to create a checklist and give to all vendors to develop accordingly? If this exceptional cases checklist exist, we can save a lot of time, human effort, transportaion, parking fees, electricity, saliva, brain cells....etc on this unnecessary process. (A watse of tax payers money)
If the Bank willing to pay me few thousand RM to prepare the checklist, I would accept with great pleasure for the benefits of we, ie: vendors' mental health.
01 julio 安静的位置 |
|
|