People · 3.2

How a control looks from the machine

How a control looks from the machine. What it costs, who decides, and what usually goes wrong.

For an independent reference point, see NCSC guidance on managing people risk.

The day

Throughput, handover, and a job that has to ship

An operator's day is measured in parts produced. A shift starts, a handover happens in a few minutes, a job runs, something goes wrong with a tool, and the schedule is already tight.

Every control introduced into that day costs seconds at a moment when seconds are contested. Controls that cost seconds at the wrong moment do not get followed; they get worked around, and the workaround is invisible to everybody who designed the control.

What a control looks like from there

Three examples

A password at a terminal. Forty seconds with gloves on, several times a shift, on a keyboard with a film over it. The predictable outcome is a shared login written on a card, and it is not a discipline problem.

An authorised transfer route. If it takes ten minutes and involves finding somebody in an office, the memory stick wins whenever the office is empty, which is most of the second and third shifts.

A locked USB port. Solves the transfer route and does not replace it. If nothing replaces it, the job stops or somebody finds another way, and one of those two is what will actually happen.

The principle

The compliant route has to be the fast route

Where following the control is quicker than avoiding it, the control holds without enforcement. Where it is slower, enforcement is required permanently and will fail during the busy week.

This is the single most useful sentence in this part of the blog and it costs money to honour, which is why it is frequently skipped in favour of a policy.

Designing with them

Ask three operators before deploying anything

What would make this unworkable? When in the shift would this hurt most? What would you do if it did not work and the job had to run?

The answers take twenty minutes, they are specific, and they are almost always things nobody in the office had considered. The third question in particular predicts the workaround before it exists.

Who the threat model is

Operators are not the enemy

A programme that arrives on the floor as suspicion produces resentment and concealment. Almost all of what governance on the floor catches is error, convenience and drift rather than malice, and saying so plainly changes how it is received.

The entry on what staff are told is about doing that properly.

Shift patterns

Design for the third shift

Anything that depends on somebody in an office being available is a control that works on days and fails at night. Nights are when the unusual transfers happen, for entirely ordinary reasons.

Either the route works unattended or it does not work.

Feedback after deployment

Go back in a fortnight

Not to check compliance: to ask what is annoying. The answers arrive freely if nothing is at stake and they identify the workaround while it is still one person's shortcut rather than the way things are done.

The pilot machine

Deploy to one first and listen

One machine, one shift, a fortnight. Whatever is wrong will be apparent and will cost one machine's disruption rather than the whole floor's. Suppliers who skip this step generally do it anyway, later, as a rollback.

Gloves, noise and light

Physical conditions defeat controls designed indoors

Touchscreens with gloves. Passwords under machine noise. Screens in sunlight or in a dark corner. Badge readers mounted where a person carrying something cannot reach.

Every one of these has produced a shared credential somewhere, and every one is visible in ten minutes of watching.

Also

Elsewhere in people