6 ms·
More like: your company (or government agency) is critical infrastructure or of a certain size, so there are obligations on how you maintain your records. It’s
by leipert 1y ago
More like: your company (or government agency) is critical infrastructure or of a certain size, so there are obligations on how you maintain your records. It’s not like the US or other countries don’t have similar requirements.
- egorfine 1y ago[flagged]
- leipert 1y agoNope: The other way around. If you are of a certain size, you are required to ensure certain criteria. NIS-2 is the EU directive and it more or less maps to ISO27001 which includes risk management against physical catastrophes. https://www.openkritis.de/eu/eu-nis-2-germany.html https://www.openkritis.de/eu/eu-nis-2-germany.html Of course you can do backups if you are smaller, or comply with such a standard if you so wish.
- egorfine 1y ago[flagged]
- mschuster91 1y agoWell, given that way too many companies in the critical infrastructure sector don't give a fuck about how to keep their systems up and we have been facing a hybrid war from Russia for the last few years that is expected to escalate in a full on NATO hot war in a few years, yes it absolutely does make sense for the government to force such companies to be resilient against Russians. Just because wherever country you are at doesn't have to prepare for a hot war with Russia doesn't mean we don't have to. When the Russians come in and attack, hell even if they "just" attack Poland with tanks and the rest of us with cyber warfare, the last thing we need is power plants, telco infra, traffic infrastructure or hospitals going out of service because their core systems got hit by ransomware.
- egorfine 1y ago> it absolutely does make sense for the government to force such companies Problem is, a) governments are infiltrated by russian assets and b) governments are known to enforce detrimental IT regulations. Germany especially so. > power plants, telco infra, traffic infrastructure or hospitals Their system _will_ get hit by ransomware or APTs. It is not possible to mandate common sense or proper IT practices, no matter how strict the law. See the recent incident in South Korea with burned down data center with no backups.
- deleted 1y ago[deleted]
- hiharryhere 1y agoGovernment isn’t perfect but I’d be interested to know what alternative you propose?
- egorfine 1y agoa) Incarceration time for IT execs and responsible engineers. b) Let companies go out of business once they fail to protect their own crucial data. None of that is possible.
- throwaway_fjmr 1y agoso you are not proposing anything real then? I can pull "magic indestructible backup solution" out of my arse, too :(
- egorfine 1y agoNo propositions at this point. I have no idea how to fix the problem.
- scns 1y agoThose are only punishments, which are shown to not work. Solutions are needed
- hiharryhere 1y agoIs it? It would be incredible if the government didn’t have specific requirements for critical infrastructure. Say you’re an energy company and an incident could mean that a big part of the country is without power, or you’re a large bank and you can’t process payroll for millions of workers. They’re ability to recover quickly and completely matters. Just recently in Australia an incident at Optus, a large phone company, prevented thousands of people from making emergency calls for several hours. Several people died including a child. The people should require these providers behave responsibly. And the way the people do that is with a government. Companies behave poorly all the time. Red tape isn’t always bad.
- egorfine 1y ago[flagged]
- myrion 1y agoConsidering that companies will do everything to avoid doing sensible things that cost money - yes, of course the government has to step in and mandate things like this. It's no different from safety standards for car manufacturers. Do you think it's ridiculous that the government tells them how to build cars? And similarly here: If the company is big enough / important enough, then the cost to society if their IT is all fucked up is big enough that the government is justified in ensuring minimum standards. Including for backups.
- egorfine 1y ago[flagged]
- StopDisinfo910 1y agoIt’s government telling you the minimum you have to do. There is nothing incredible there. It makes sense that as economic operators become bigger, as the impact of their potential failure grows on the rest of the economy, they have to become more resilient. That’s just the state forcing companies to take externalities into account which is the state playing its role.
- Fanmade 1y agoI'm usually first in line when talking shit about the German government, but here I am absolutely for this. I was really positively surprised when I had my apprenticeship at a publishing company and we had a routine to bring physical backups to the cellar of a post office every morning. The company wasn't that up-to-date with most things, but here they were forced to a proper procedure which totally makes sense. They even had proper desaster recovery strategies that included being back online within less than 2 hours hours even after a 100% loss of all hardware. They had internal jokes that you could have nuked their building and as long as one IT guy survived because he was in the home office, he could at least bring up the software within a day.
- egorfine 1y agoIt's incredible knowing the bureaucracy of Germany.
- zestyping 1y ago> This is incredible. Government telling me how to backup my data. Incredible. No more incredible than the government telling you that you need liability insurance in order to drive a car. Do you think that is justifiable?
- fauigerzigerk 1y agoThe difference is that you cannot choose who you're sharing a road with while you can usually choose your IT service providers. You could, for instance, choose a cheaper provider and make your own backups or simply accept that you could lose your data. Where people have little or no choice (e.g government agencies, telecoms, internet access providers, credit agencies, etc) or where the blast radius is exceptionally wide, I do find it justifiable to mandate safety and security standards.
- johannes1234321 1y agoLosing data is mostly(*) fine if you are a small business. If a major bank loses it's data it is a major problem as it may impact a huge number of customers and an existential way, when all money is "gone" (*) From state's perspective there is still a problem: tax audits, bad if everybody avoids them by "accidental" data loss
- fauigerzigerk 1y agoAs I said, a wide blast radius is a justification and banks are already regulated accordingly. A general obligation to keep financial records exists as well.
- Chris2048 1y ago> you cannot choose who you're sharing a road with while you can usually choose your IT service providers You can choose where to eat, but the gov still carrier out food heath and safety inspections. The reason is that it isn't easy for customers to observe these things otherwise. I think the same applies to corporate data handling & storage.
- flumpcakes 1y agoIt feels like you are being obtuse/arguing in bad faith. Of course there are standards on backups. Most countries have them. Let's think what regulations does the 'free market' bastion US have on computer systems and data storage... HIPAA, PCI DSS, CIS, SOC, FIPS, FINRA...