More Content - Including Podcasts

Showing posts with label information technology. Show all posts
Showing posts with label information technology. Show all posts

Wednesday, December 14, 2011

Medical Education Networks Must Be Good Neighbours

This story makes an understated point for us managing medical education and research networks.

While we may not operate or support the systems on the clinical networks, we operate immediately adjacent to them.

As our educators and researchers bring devices closer between these networks, we need to illustrate leadership, good faith, and act as responsible neighbours and ensure systems under our management are as protected as possible, and users as educated as possible. This in turn lightens the load for our colleagues managing the clinical networks immediately responsible for patient care.

Malware shuts down hospital near Atlanta, Georgia
http://nakedsecurity.sophos.com/2011/12/13/malware-shuts-down-hospital-near-atlanta-georgia/

Wednesday, November 23, 2011

Original Podcast Back Online!

The original itManageCast podcast is back online!

This interview was recorded a few years ago when one of Vivit's "best & brightest" members, Mike Peckar, was deploying HP network management software at Camp Victory in Iraq.  If you use (or used) HP Software Network Node Manager (OK, I'm dating myself here, but you know the application family I'm talking about) you should know (or know about) Mike.  He literally wrote the book on the use of that software. Seriously. Literally.

Interestingly enough, while this interview took place a few years ago, the root issues around NMS really haven't changed and most players in the market space haven't shifted significantly.

I'm about to get back in the game of analysing enterprise NMS solutions (which takes me back to my early career in some ways) so I found this "classic" itManageCast interview helpful, and thought many of you might as well.

Stay tuned for updates on my explorations into the current world of NMS.  in the meantime, listen to the interview with Mike Peckar about his book "the Fognet Fieldguide to Network Node Manager."

http://itmanagecast.podbean.com/


       

                               
   
Podcast Powered By Podbean
   
   

Wednesday, April 14, 2010

To iPad or Not To iPad?

While technically the iPad isn't even available in my neck of the woods yet, that hasn't stopped enterprising Canucks who live near the border from ducking down across the line and bringing one home. Yesterday I got my first in-person glance at one during a meeting downtown, and was suitably impressed at the usability and form. But with the product soon to be more widely available, I have to consider whether I'll indulge in this product and give it the itManageCast "Seal of Approval" or pass it off as another techno-fad?

For the past while I've been coming closer and closer to jumping in and buying myself an e-book reader, but the problem I've had with the products breaks into one of two chief complaints:
a) too small
b) too limited in function

To me, the purpose of getting such a device is to lighten my briefcase, and have some side benefits of an administrative/remote access tool and ideally also include recreation/leisure capabilities.

Screen Size
Maybe it's just the age I'm getting to, but if I'm going to be spending any serious amount of time reading off an electronic platform, it needs to be bigger than a paperback. Especially since a lot of the material I plan to read is technical in nature, and will include diagrams, images, and colour. I want the ability to upload any PDF file or other document format I happen to get technical docs and white papers in, plus various e-book formats. This starts to really limit the field of currently available products. The 5-6" Sony readers are just too small for my uses. The format size on the Kindle DX would work (9.7" reading surface) and the current version supports PDFs natively.

The e-ink technology is amazing in various light conditions; I tried one of these last year at a trade show and was impressed by the ambient direct-light readability of the screen. But it's still only grey-scale, no colour.

Form Versus Function
Tablet PCs can do all of this, but they are WAY heavy; that footprint takes us out of the zone I'm comfortable holding & reading. What they do offer is the multiplicity of functions that I'm after.

So what am I looking for? I need a device that can be my reader and my notebook. If I'm going to move away from carrying paper I want to truly do that. I want a device that will replace my journal/notes and accommodate the copious notes I take in day, random and frequent updates to my calendar, various tech docs I want in my "hip pocket," Internet access, e-mail access, and the ability to create/read/edit simple documents on the go.

I don't think I'm alone in this, am I?

Additionally, if this same device can be used on occasion as a network console connection, all the better.

What's Left to Consider?

So I figure I'm looking at the iPad, but its got me a little jittery - it seems that it does nearly everything I want in the form-factor I want, but it's that "Apple lock-down" I'm not too certain about. Can I connect it to an external USB drive or an external monitor? How reliable and functional is the 802.11b/g/n connection? I've read reports that have noted issues. Not only that, but now the stories break that the 3G signal strength exceeds national standards in Israel. And how many other countries I wonder?

So what are the alternatives?
I recently came across a product about to be released by German manufacturers using a combo of Linux & Andriod for an O/S, and an Intel Atom processor. The product is dubbed the WePad, and it boasts a larger multi-touch display, although shorter battery life (6 hrs vs. the touted 10 of the iPad). WePad is worth looking at in my view, being a bit of an OpenSource bigot... WePad is due out in the market August 2010 in Europe, so I'll tell you what folks at Neophonie; send me a unit to work with for a week or so and I'll get my review out on what I think sounds like a viable alternative to the iPad.

Now I will commence holding my breath.

Monday, April 12, 2010

Security Perspective on Social Networking

Facebook, Twitter, LinkedIn... all words that can make the IT manager's skin crawl. The simple solution is to block the URLs at the firewall; once people are plugged in at the office, too bad, no social networking on work time. I think that's the way most IT manager's would prefer it. We're a bit of a draconian bunch, largely because this is the kind of stuff that just ends up making problems for us.

But is this the best approach? Other managers in the organisation may be concerned about morale, and want these sites available to their staff - well we certainly don't want to start creating exception rules in the firewalls or network compliance tools to manage which users get access and which don't. More business centric reasons exist as well; some business units may want to use these sites for market research, sales/marketing, recruiting, and other functions.

I've recently seen some interesting and creative use of combining the three main social media sites for marketing and recruitment processes. An organisation I was meeting with last week was telling me about how they use Facebook & Twitter accounts to monitor customer satisfaction with their products and services, and respond quickly to concerns from their customers or deal with urban myths about them that get propagated through these media. From a business perspective, that approach makes a lot of sense. This same organisation also uses individual LinkedIn accounts from their recruitment professionals as a mechanism to reach out to prospective new employees and contractors, and ties it all together with Facebook & Twitter promotion of new positions and recruitment drives.

So in this scenario, the IT team has to work with the other business units (sales, marketing, and HR) to make sure they can get timely access to the tools, ensure that they maintain corporate image and privacy, and verify the content of those sites - both what is "going out" and what is "coming in."

Where do you start?
Ensure first that the leaders of the organisation understand the challenges for the IT team, possible budget implications, and risks.

For certain, a review of existing organisational IT usuage policies. First off, so you have them in place? Secondly, have they been distributed (recently) and signed off? And lastly, does the language (hopefully not too "lawyered up" so that people understand what they are committing to) apply to this kind of scenario?

What questions should you ask?
Once you've established who's allowed to do what, it becomes a question next of enforcing the rules while allowing the business functionality that's been agreed to. Now we get into the business analysis side of the equation. Understand clearly what the business needs are so that your team can work with the rest of the business to deliver the solution that makes the most sense.

You'll need to look at technical considerations, some of which might be:
Will Twitter use be via the web interface, or 3rd party apps like TweetDeck?
Will you allow all Facebook apps, or try and block some (like games, etc.)?
Will this be allowed corporate wide, or group by group?


Who's already looking down this path?
There are developers such as Teneros and SocialWare who are developing middleware-like apps that monitor content for these sites, to ensure that the organisation knows what is going out or coming in. These tools have some limitations, so it's best to research the options closely, but it's good to know you HAVE options! SocialWare is particularly interesting to me and likely may be the subject of a future blog posting.

Check through your personal network (errr, via LinkedIn?) to see who else is in your shoes and dealing with this kind of challenge today. I was surprised to learn recently how many organisations haven't even started to deal with this from an IT perspective yet. I know we're busy, but...

As always, your feedback and input on this article is greatly appreciated; reply with your thoughts and I'll post them for continued conversation.

Wednesday, March 31, 2010

Patch Released to Remediate More Day Zero Exploits for Internet Explorer

A critical cumulative security update for MS Internet Explorer was released yesterday (March 30) as noted in security bulletin MS10-018. This patch deals with 10 (count 'em, TEN) additional vulnerabilities within the browser, 9 previously undisclosed and one that was made public. The one known vulnerability is specifically for IE 6 & 7, although the patch in general is advised for IE 5.01 through 8, and while MS rates this security patch as "moderate" for IE 8 on servers, why would you take a chance these days?

What are the Risks?
The known vulnerability for older versions of IE, referred to by the Common Vulnerabilities and Exposures group as CV-2010-0806, was first described in an older Microsoft Security Advisory and is a vulnerability that could allow remote code execution; as for the impact of the rest of the undisclosed vulnerabilities, Microsoft states the following:

"The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights."

Recommended Actions
Microsoft rates this patch from important to critical, depending on your desktop version of the browser. If you are leveraging automatic updating, this patch will get pushed to your end-users' desktop systems; if you manage your updates, be aware of this one and take the actions you judge as appropriate for your organisation to ensure servers & desktops using Internet Explorer are protected.

What Next?
This security flaw in the code for the browser seems to be oriented again around risks developing from phishing type attacks. IT managers & IT security professionals have to take this account in understanding the risk level and possible next steps. Applying the patch seems to be a given, looking at changing the default browser used in your organisation - well I'd be surprised if you weren't already considering that but there are usually many ramifications associated with that, including end-user training and most commonly used sites & applications.

Let's face it, for most of us there's just no getting away from IE completely.
This also brings forward the considerations around the social engineering side of the issue and how much of that we can control by managing where our users can go to on the Internet, and caching/pre-qualifying sites before users first access them.

In the meantime we contain what we can by educating our users, protecting the network as best we can without crippling the users, and staying as well informed as we are able. Hang on folks, this is going to continue to be a bumpy ride; hopefully I and other like-minded professionals can keep you educated on what is happening beneath the hype.

Friday, March 26, 2010

Five Top IT Security Trends for 2010

#1 Antiviral Products Move Away from Local Signatures
With the rate that variants of viri, trojans, and other attacks are coming out (approx 50,000 per day) signature based AV tools just can't keep up without bogging down the systems on your corporate network. So what are the AV companies doing to deal with this?

The leading AV companies are making a shift to where only a small subset of signatures are downloaded to your PC/network. The bulk of the testing happens "in the cloud" where the AV companies use cloud-based technologies to identify threats and note sites/exploits that need to be blocked and send that info to your AV clients.

The philosophy behind this is that there are basically two types of attacks; social engineering (downloads, phishing, etc) & computer attacks (exploit involved - identifies & exploits a vulnerability pre-existing in your computer).The theory is that they only need to worry about protecting against the vulnerabilities, if they are effectively dynamically blacklisting the social engineering risks via their cloud-based work.

#2 Increased Use of Application Whitelisting
The concept of whitelisting is that you block everything except a concise list of sites, addresses, or ports you wish to allow access to. This technology is being led by companies like Bit9 who have been working in this area for some time. Not a good technology for home users or large organisations to use for desktops because of the nightmare in keeping the list up-to-date, but this is a great tool for appliance-like technologies - ATMs, or any other purpose-driven technology. It is also worthy of consideration for use on servers.

#3 Enhancements in Firewall Rule Optimisation
More and more IT Managers are finding that they are struggling to keep pace with the rate of change they must apply to their firewall rules. This process also leads to omissions and redundancies in the firewall rules and ACLs. Firewall vendors and third parties have been releasing tools like Skybox's Firewall Compliance Auditor that bridge simply optimising your rules for increased efficiency and now start ensuring that they meet compliance rules .

#4 Increased Social Engineering via Social Media
Social Media sites like Facebook, LinkedIn, and others are continuing to become rampant hunting grounds for cyber-crooks, whether they are associated with organized crime or just script kiddies.

Creative cyber villains will continue finding new ways to exploit people that they'd consider high-value targets - this doesn't necessarily mean wealthy people; but instead it means a combination of the "low hanging fruit" - the people who seem to put a lot of information about themselves and their employers out on the Internet - and people who can be identified as working in organizations that are targeted for attack.


#5 Continual Evolution in Regulatory Compliance
Certainly not last but it rounds off this list as an important topic in computer security for 2010. Regulatory compliance continues to be a pressing topic for the leaders of our various organisations and therefore also for IT managers. As an IT manager, there are some key things that compliance should mean to us:
  • audits & audit trails in place & working
  • documentation showing current state of network & security (i.e.: configuration management)
  • change management processes in place & operating
  • clear understanding (& documentation) outlining key business risks how those risks are managed

For more in-depth analysis of these topics please contact itManageCast for a copy of the whitepaper titled "Top IT Security Trends for 2010."

Wednesday, June 24, 2009

Current Networking Trends that Affect Network Management

Trends in Network Management are understandably driven by the trends in network architecture. Network architecture tends to be viewed as monolithic and unchanging; this is far from the truth. Networks tend to go through cyclical evolutions approximately every five years when the ever-increasing plethora of other network dependent technologies build up a critical mass and force change on the network. Like every other technology the IT manager must face, these changes must be adapted to and managed effectively because of the pressure they place on the networks that keep Information Technology’s life-blood flowing.


Convergence

Voice over IP (VoIP) has been in the workplace for some time now and most networks have already adopted, or planned for, this technology. Those which have not will need to in short order – if your shop won’t ever use VoIP as it exists today, other convergence requirements will be around the corner. Even if your shop is not using a VoIP technology today, it is foreseeable that the other business areas or the telco providers will provide sufficient momentum or incentive for this change to take place.

Support of VoIP solutions can include the requirement for Power Over Ethernet (POE), Virtual Local Area Networks (VLANs), and traffic prioritization. These technologies have in the recent past outstripped the ability of legacy NMS’ to properly monitor and manage them.

Network-based video conferencing and streaming audio for training and other business (and often non-business) related requirements may not require POE but demand traffic prioritization and VLAN capability on the network. Finding a corporate network solution in place today that does not support either VLAN or traffic prioritization is rare, but what about the NMS that monitors and reports upon these technologies?

The other factor to consider with respect to convergence and it’s impact on NMS choices is that convergence based technologies entering the workplace tend to be very high-profile in as far as the public image and business operation of the workplace are concerned. When the telephones don’t work, or the customer WebEx sessions fail to operate smoothly, customer perception of the organization is negatively impacted.

A NMS choice needs to be designed to support convergence technologies, or be a supported integration with a point solution from the convergence technology vendor (i.e.; have a proven “plug-in” capability with your Cisco IP telephony management toolset).


Mobility
An increasing demand is placed on today’s networks to support mobile computing solutions from laptops and Personal Digital Assistants (PDAs) to wireless VoIP devices. This is by no means an inclusive list, but clearly the expanded use of these types of end-user computing technologies is driving the increase in deployment of wireless networking technologies.

As more wireless Local Area Networks (WLANs) are deployed, a trend is occurring where many shops are looking seriously at the continued value in having multiple physical Ethernet drops for every person’s work area.

The increased dependence on WLANs for business critical functions is a change in networks that is driven in from the network edge, as opposed to outwards from the network core. Having the end-users bring more of these technologies into the workplace with the expectation that they will have access to the same business functionality that they have had from their hard-wired desktop systems is driving this requirement at a nearly exponential growth rate.

Deployment of wireless network technologies to keep pace with the demand can be a risky business, and your selection of NMS needs to be able to keep pace with these demands. If your organization is seeing the growth in wireless technologies ensure that you select an NMS that will have the scalability to add monitoring for the quantity of Wireless Access Points (WAPs) that will be deployed. This can be a significant additional number of “managed nodes.” You will also need to make some strategic decisions as to whether you will be monitoring the wireless devices attaching to the WAPs.

A further consideration when selecting a NMS for a wireless environment is the support for the control and management infrastructure used between the WAPs and the wired network. Often large wireless deployments will have centralized controllers that manage groups of WAPs. These architectures will also likely need enhanced ability to monitor security related aspects.


Security
A trend in networking is the ability to apply security controls at the network edge. This useful concept requires underpinning technology that needs to tie back into your NMS for control and audit purposes. Access to network ports is managed by intelligent edge switches that leverage RADIUS technology and tie it back into the directory systems; thus controlling who is authorized to connect physically or wirelessly to the network.
However you implement this, your NMS of choice needs to be aware of “bad connections” and forward those alarms to your network and/or security people. Perhaps there’s even automated controls you want to leverage for this, but regardless, you’ll need an NMS that is ready to work alongside these identity-driven networks.

When senior management (or worse, external auditors) come knocking asking for reports of network use how will you provide that information? Find out what kinds of audit/reporting requirements your organization may require of the network for privacy or other mandated legal compliance reasons, and use those as further criteria in your NMS selection.

The basic underpinning network management technology in use today is the Simple Network Management Protocol, or SNMP. SNMP versions 1 and 2c (the most frequently used versions) are infamously insecure. These protocols should never be used outside of the secure perimeter of your network, and even regarded dubiously for use inside. Most network gear you buy today support the use of SNMPv3, the secure encrypted version of SNMP. The challenge comes when evaluating the NMS, as many still do not support SNMPv3 out of the box. This is certainly something to check for.

If a part of your network is outsourced, and you still want or need to manage it, you will need to have an NMS that is capable of understanding proxy-based SNMP management, likely as well as SNMPv3. Many network outsourcing companies will not provide this proxied monitoring so you should be checking with your service provider before making this a NMS criterion.


Configuration

How is your organization dealing with issues of network device inventory, version control, and change management? Should your NMS be part of the solution or part of the problem?
Your NMS choice does not necessarily have to be part of a framework solution with a full Configuration Management Database (CMDB), but it should at least have significantly advanced polling and collection abilities to keep current on what is out in your network. As well, this data should at the very least be readily exportable to your CMDB choice of today or tomorrow. The polling intervals should be readily configurable, so that you can have different polling intervals for network nodes of different importance.

When considering polling, you should also learn about the polling technology that the NMS uses. Is it basic ICMP (ping) status for up-down? Or is it slightly more complex SNMP-based? As discussed in the security section, consider the versions of SNMP to be used. Additionally, try to understand what kind of polling engine the NMS uses and how it differentiates and adds/removes risk from the management of your network. This is the kind of area where an expert consultant in NMS comes in very handy.

Is it important to you to centrally manage the firmware and configuration of your network topology? There are many point-solution tools from the hardware vendors that provide this, as well as third-party application specifically designed for this functionality. You should determine whether your need are better suited by integrating this functionality into your NMS, or obtaining a NMS that provides this ability. Wanting your NMS to handle your complete configuration management needs will dramatically shorten the list of available products, so it is advised to focus more on the compatibility aspect and leverage the point solution for firmware and configuration management, while letting the NMS manage discovery & status.


Business Driven Requirements
Every decision made in IT is governed by or directly affected by business drivers and requirements. Various requirements for your NMS selection are going to be driven from what is currently happening with other business areas of your organization, or strategic initiatives.

We spoke early in the security discussion about regulatory compliance issues around having data collected and reported for audit, but other areas of consideration should be around mergers or acquisitions, planned growth, or outsourcing. All of these factors require a NMS that is scalable and quick to update its understanding of your changing network topology. It may also require that you have the ability to provide secured, limited access to the NMS for third-parties who have shared interests in the support and maintenance of the network.

Does the organization have any plans around Data Centre consolidation? This kind of activity will mean reduced core network nodes, but increased edge nodes, and an increased backhaul of network traffic. This again leads to scalability of the solution, speed and accuracy of the discovery and polling mechanisms, and the ability to extract the network inventory information readily.

Green IT initiatives may have some impact on your NMS selection as well. While power reduction strategies likely point towards data centre consolidation, they can have other unexpected outcomes for the network, like increased virtualization, possibly outsourcing of certain services, and often less printing means more electronic data movement and the ability to get large files quickly back and forth from the core to the edge on mobile devices.

Ensure that your NMS selection takes these kinds of items into consideration by its ability to provide management to the network edge (or beyond) with speed and accuracy, and a fast and accurate causal engine to help reduce the time spent diagnosing problems that affect the delivery of data to the other business users. They may not always be network problems, but can you back that up objectively and quickly when the VP is standing in your door?

Another area to consider is managing the network as a delivered service to your customers and the data collection, analysis, and reporting requirements for that. Service Delivery Management in the NMS is also rare but tends to be a feature available more commonly when you are using framework solutions. You can get to this point without a framework if you carefully consider how you will make the measurements of the Service Level Agreements and Service Level Objectives available to the customers of your network, both internal and external to the organization.

Lastly, the biggest impact that business driven requirements have on NMS selection is that of diminishing budgets and the requirement of doing more, or the same, with less. This can lead you to consider how to budget for your NMS & its ongoing support and maintenance, but also gives you the opportunity to consider making it an operational cost by leveraging some form of “Software as a Service.” Many vendors provide this solution, where for monthly or annual fees they will manage your NMS and provide the output you require from it by either hosting the NMS remotely (debatable due to security considerations) or implementing and maintaining the NMS on your site.

Tuesday, June 16, 2009

HPSU 2009 - Part 2


I helped set up the Vivit booth with other local chapter leaders and the board of directors, grabbed a really quick (but heavy!) breakfast, then squeezed into the mainstage room for the keynote presentations.

They kicked things off with some brilliant animated clips outlining the current challenges faced by IT - including IT business alignment, the current "new" economy, virtualisation, and cloud computing amongst other things.

Jake Johanssen was our host for the morning. A stand-up comedian which is a really different take but made things much more entertaining than they've been before at 08:00 on a Tuesday morning. The typical jabs at Canadians were made, but Jake threw in some other topical humour that was quite engaging. He really got the crowd warmed up well. The room was definitely smaller than previous years, but it was filled. We're waiting to hear attendance numbers overall. Some interesting trivia about the impact of the economy is that 27% of conferences in Vegas were cancelled this year.

Andy Isherwood VP & GM of HP Software Services
Andy started off thanking for people to come given the economic restraints - a message that brings home where things are at globally an across the US. His discourse started with a focus on budgets being cut between 0 - 40%, and a lot of uncertainty in HP's customers. Andy asked the audience to consider the situation as an opportunity to be innovative. The HP opinion is to try and get ahead of the economic recovery curve by aligning with business, reducing costs, consolidation, and increased efficiency.
Three examples were provided of 3 organisations that have achieved a quick ROI:
  • JetBlue
73% decrease in testing costs, 80% reduction in post production failures, 3x increase in testing efficiency, 70% increase in test virtualisation.
  • Altec
10% app downtime reduction, 20% faster response time, 15% increase in customer satisfaction
  • T-Mobile (US-Washington)
Significant cost savings through efficiency improvements, 50% decrease in ERP group testting time, 75% reduction in ERP port-prod defects, greater application availability.

These three are the winners of the HP Software Solutions 2009 awards of excellence

It's always nice to hear that organisations have done wonderful things, but the key question is always "So where do you start?"
HP's keynote answer to this was:
  • Operational focus to provide a transformational focus over time.
  • Cost optimisation to move capital to fund innovation initiatives
  • Focus on execution of automation, financial management, virtualisation, and consolidation.
This is to me really just new wrappings and graphics on an existing message. I have to wonder why we need to keep making this message heard - is it just not getting through to IT leaders or are those leaders hearing and getting the message, but unable to execute because of other factors - economy, difficulty in showing ROI, ? Sounds like this area needs exploring - future topic?

Andy followed up with the HP message that they are about solutions, not products. The delivery options they are flogging are in-house, EDS, Cloud Services SaaS, and HP Partners (oh yeah, them.) I'm still waiting to hear something positive about the EDS acquisition from a customer perspective - I'll be visiting their booth on the showfloor later today to see what I can learn.

Andy touched on what's new in the IT services offering from HP, which is "Cloud Assure", IT financial management, IT performance analytics, and IT resource optimisation.

The marketing branding from HP has changed this year to a new four words; Optimise (technology portfolio - IT Mgt Software), Leverage (biz info), Elevate (biz performance), and Improve (customer experience).

Andy discussed about HP support, and claimed that customer satisfaction is at an all-time high based on improvements made over the last two years. A big piece apparently was "in-sourcing" aspects of the HP support organisations - interesting. He did claim that he was under no illusions that things were ideal. He also commented that things need improvement with customers getting stuck at L1 when things don't get escalated timely, and at L3 when software changes that need to be made aren't happening fast enough.

The services organisation was discussed and that it has been tightly embedded into HP Software overall and is using optmisations like knowledge management to increase IP. Andy also noted that he feels this is not in conflict with the partner environment, but I think this statement is at odds with what is actually happening (actions speak louder than words) in particular the changes that have been made to partner status making it basically impossible for independent and small consulting organisations to have partner status (and benefits) with HP.

Andy closed by thanking the audience for their trust & confidence in HP, our time invested here at the show, and enforced his message that HP is proud to be a customers partner, ready to listen and act with the customers to see success for everyone.


Betty Smith VP of Process at John Hancock & President Emeritus with Vivit
Betty started with a discussion about the first HP software (Mercury) project around TestDirector to improve defect management on their internal web site and replacing spreadsheets and access databases with a centralised tool. They then migrated TestDirector to other software bases in a 6 week period once the initial pilot project had completed. SOme impressive numbers to be sure.

Betty discussed the complexities of the John Hancock/Manulife Financial organisation and the desire to drive efficency and competitive advantage.

She highlighted three main points of how this is done:
  • Establish point solutions that provide value - JH does not support long implementations - any job must be finished between 2-6 months.
  • Extend the solution to other areas - cross the silos & work across the organisation
  • Create the longer term vision and focus on a match between IT & business goals. This provides JH an end state that is adaptable but stable, and leads to lifecycle management.

Products suites in particular that JH has implemented include Quality Management, Asset Management - (DDM, uCMDB). Betty claimed an increased efficiency for chargebacks from 3 weeks to one day using these new systems & processes. Performance Centre, and Business Availability Centre were also discussed, both of these are based out of centralised teams that work across all silos to support the business units.

Further, the discussion touched on Service Catalogue and Service manager being centralised and underpinned by uCMDB.
PPM started off as point solutions within numerous business units, but information wasn't being shared well. The PPM project consolidated and eliminated various applications to standardise on a single platform. Another key advantage of the project was that it defined centralised PM practices and processes.

Betty's main claim was that she works off of a simple end-state vision which she shared grahically with the audience. It had some interesting approaches illustrated in the diagram.

Betty discussed techniques that JH used to increase awareness and support including "show & tell" monthly meetings of internal SIGs cross-organisation, developed user forums in sharepoint, and allow for the solutions to be showcased. JH puts on monthly roadshows for the senior mgt level to validate direction and what si importnat to each of the BUs, allow an oppoortunity to adjust priorities, and these are run with individiaul biz units to really understand what is driving them and what areas they can help them improve in.

Betty discussed the regulatory requirements of a financial organisation and the abilities her successful projects have given to free up resources previously committed to audit compliance work - also this allows JH to demonstrate governance of off-shore vendors by having everyone use a centralised consistent solution. Engagement of governing bodies around risk management & expense management is another example of working across biz units. By engaging them in the use of the tools they contribute to the setting of policies and drive the use of the tools as a standard for the organisation.

Betty cited that process is over 50% of a project implementation; making the point that technology doesn't stand on its own without solid process that's oriented to your biz units & directions.

Betty summarised by emphasing that success is achieved by building incrementally focussing on low hanging fruit and creating an end-state vision.

Wednesday, March 4, 2009

The eMail You Wish Never Was



We've all done it at least once. Ideally, you only do it once.
You get caught in a moment when you are "up-to-your-eyeballs" when an email comes into your In-Box that is legitimately urgent to someone else, but just not to you at the moment.

At that instant you have some choices... quickly respond with an email back to effectively say "I'll look at this once I have a moment", flag it for follow-up but just don't reply, or pick up the phone for a brief conversation. The first and third options are both quite viable,and common sense dictates that the second option works well for you but puts you in risk of continually receiving more emails.

The problem with the first or third options in responding will come about in HOW you respond. Remember, you're not getting this email while you're casually reading my blog or sipping a coffee at your desk. Imagine yourself at the single busiest point you've been at in the past three years of work; and in executing some of that work you've needed to use your email... while accessing your email to compose a quick note to clarify some work you are delegating you notice "the message" in question.

Now we've set the scenario, and this is where the challenge comes. On 360 days of the year, this isn't an issue, but on one of those TOP FIVE busiest days you have in a year, either the content, tone, or a past interaction makes this email you receive be the straw that breaks the camels back.

Your thoughts run very quickly along the lines of "does this person have any idea how busy I am right now?" or "why is this issue MY problem right now?" I know mine have!

This is the point where you either quickly type up an email response or pick up the phone.

This is also the point where you can unwittingly make a mistake that can take some time to mend.

The reality is that 95% of the time, the sender of the email does NOT know how busy you are, and the issue was obviously of importance to them, but not urgent enough to warrant them placing a phone call to you. Generally speaking, that should be the first indicator that you do NOT need to reply this instant. But, our human nature and sense of ownership of situations as managers urges us to quickly plunk at the keyboard a hasty reply and click send, then blast off to the other 32 things desperately needing our attention at that moment.

An hour (or not even that long!) later you get the phone call that makes you realise that you wish you'd never clicked "send." In your haste, urgency, and certain level of frustration you've typed something you shouldn't have; something that under any "normal" circumstances you never would have, and now you've opened Pandora's box.

So my long-winded story has gotten us to the point where we have two things to cover: what we do now to deal with the situation and how we learn not to get into the situation again.

The only way to deal with a situation like this is to "eat crow." The reality is that while you have correctly perceived that someone else had no idea of how busy, stressed, harried you were at the moment they had electronically requested something of you that you felt was not your responsibility to have to deal with, you also sent off an email without considering or understanding how busy, stressed, or harried this individual was with what they were dealing with at that moment. It's entirely likely that the problem they were bringing to you "isn't yours" but perhaps they felt they had nowhere else to go, and were looking for help (regardless of how that request may have been phrased).

So now, as a responsible manager, it behooves us to go cap-in-hand to the individual you sent the electronic reply to and hold a brief but frank discussion, starting with a sincere apology for your tone, but focused on understanding their issue, helping them understand what you have on your plate, and coming up with some solution. You may not have their answer, but more than likely, once you understand WHY they were asking you in the first place, you can point them to someone else who does have the answers. And have this conversation face-to-face if at all possible; this kind of thing does not translate well over the phone, and further emails will only risk making things worse due to their intrinsic impersonal nature.

And finally, how do we avoid this kind of situation? As I suggested much earlier, if you are truly over-whelmed do NOT send an email or phone the individual without taking five minutes to think through your answer in the context of the question: "What is happening at this persons desk right now to prompt them to send me this email?" This is a great little trick guaranteed to put you in the right frame of mind to be helpful and avoid unnecessary workplace confrontations and stress.

Thursday, June 12, 2008

CMDBs Out of the Box

I've started to evaluate the software CMDB solutions from various vendors - HP, BMC, and IBM to start with. I'll be posting the findings of my research as I go along, but certainly welcome any feedback or input from those of you who may be looking at these products as well, or in fact may have already obtained/installed one.

The products I'm looking at in particular are:
  • HP Software uCMDB
  • BMC Atrium
  • IBM Tivoli Asset Management

Stay tuned for upcoming posts on my research into these, including the hands-on lab work I complete.

Monday, June 9, 2008

Greening Your IT - Power Savings & ROI

Everyone wants to be responsible about their energy consumption, and while from a corporate perspective, it looks great in press releases and marketing materials, it's a hard direction to move in if you can't justify the expense in an objective manner.

So how do you establish the actual return on investment for your energy optimization projects?

The most obvious method, and the best place to start, is by having an objective baseline of your current energy costs related to IT. Make sure not just to include desktop computers and monitors, but any associated peripherals. Include the networked and personal printers. Include the Blackberries and cellphones because of their chargers. How about scanners? Air-conditioning? UPS and power management systems also have a draw and should be measured. Network gear, KVM switches, and the list can go on. For an extensive list contact Tsunami.ca for our whitepaper on Green IT. This audit can take some time (and therefore money), particularly if you don't have a CMDB (Configuration Management Database) in place already.

Incidentally, if you do have a CMDB, or are currently undertaking a CMDB project, have you included energy consumption rates as a CI (Configuration Item)? It's worth thinking about...

Once you have your baseline, you can now consider what initiatives your organization may undertake. Budget the cost of implementing those items, processes, or technologies (and are those costs that can be partially absorbed by budgets other than IT? ) and look at the energy reduction rates to calculate the initial, high-level ROI for the project.

But there's other ways to reduce those costs. In the Province of BC, BC Hydro has joint rebate programs with the Provincial Government that can make significant additions to your ROI calculations. If you are reading this from a location other than British Columbia the odds are that some similar rebates may be available for you as well.

Monday, March 17, 2008

HP Partner Enablement Galaxy - March Edition


St. Patrick's Day finds me back in New Orleans, and back at the HP Software Partner Enablement Galaxy (PEG) for ramping up my Ops Centre & Site Scope skills/knowledge.

So first off, Happy St. Patrick's day to everyone!

This morning started off with the general session from 8:00 to noon (well, 6:00 to 10:00 according to my body) but despite the fact that I don't handle jet lag well, I was able to be completely attentive. Steve Myers from HP started things off with over-views and clarification on HP's bail policy for people who decided to go out to Bourbon Street. Steve also shared some other interesting facts about PEG in general such as:
  • This PEG has 30% greater attendance than the last one
  • This PEG has a large Central/South American contingent
  • 155 "students" are here representing partner companies from Canada (yay!) to Argentina
  • This time 'round there are 8 tracks and 23 instructors
  • Onsite certification will be available this Friday
Jim Murphy came on stage to discuss the vivit training lined up for HP Software Universe in June and encourage everyone present to consider attending those sessions.

Steve finished up his sessions by letting us all know that PEG will be here once more, the week of Oct 6 2008.

Next up was Mike Procopio from HPSW to address the group on the HPSW Network Lifecycle Management initiatives, and how HP wants partners engaged in that. Mike went through the standard aligning IT to business pitch, and discussed the concern of CIO/CTOs of keeping the network operational, meeting SLAs, and cost-effective. An interesting factoid he brought up was an estimate of average network downtime impacting business bottom-lines at $70,000/minute. I'm thinking this is an average across Fortune 500s, but interesting factoid none-the-less.

Mike talked in depth about NNM8i, the Performance iSPI for NNM, change & config management, and AlarmPoint Express. Gotta say I've never personally been a huge AlarmPoint fan, but I will make the time to take a look at the new offering bundled with full purchases of NNM8i. Stay tuned for a review at some point.

A major point Mike made that clarified some confusion for me was that Performance iSPI is NOT intended to replace OVPI (or HP Software Performance Insight), but instead it appears to me to be more like a "pay for" integration piece that gives you "OVPI light" integrated into your NNMi architecture. Again, more on that topic as things develop!

Chuck Fugee & his team of SAs were introduced to everyone. Nice to meet them. :-)

Next up was Scott Strubel. I haven't had a chance to talk to Scott for a while; not surprising because he always seems to me to be one of the busiest execs in HP - although if you can find him he always does make some time to talk. Scott addressed us partner organizations about ways that the HP sales force and partners should be working together, the state of BTO (Business Technology Optimization) solutions today, what HP needs from the partners in as far as solution offerings go, and some re-iteration around HPSU in Vegas, and the Partner Summit to be held there.

Personally, I've never been a big fan of the Partner Summit when I've attended HPSU or OVFI conferences. It's nice that the big partners get their pats on the back & trophies, but the info there I find really oriented towards software sales and not implementation guys & gals. Give me case-studies or in-depth techie sessions anytime!

Scott is planning on being in Central Canada next week so heads up HP Canada Software Sales folks!

Scott made reference to the number he mentioned last October, of FTE and professional services consulting hours that HP software sales were planning on driving to the partner base. Then he informed us that it looks like HP is tracking to exceed those numbers. Good news for the partners! Well, the ones that HP is working actively with anyhow.

The last item from Scott that really caught my attention was the mention of HP shifting some percentage of it's software sales attention towards the upper end of the SMB market. There wasn't a lot of info on that, but as it's a space that Tsunami actively engages in I must admit that piqued my curiousity - More info please, Mr. Strubel! Perhaps my channel manager can update me after he's had his visit with Scott next week. ;-)

Last up was Victor Fadool from HPSW Professional Services. Victor spoke on a number of items, but I must confess that I glazed over a bit as it was very US oriented, and rarely discussed how the Canadian organization might find ways to work better with the Western Canadian partners... It was interesting to hear him make mention of work done in conjunction with some mysterious un-named partner at BC Hydro. Apparently Service Management work. Sounds like a good story, if the work has been as successful as it was promoted as being - so mystery partner(s), here's your invitation to contact me for an interview about the project, and give a presentation to our Vancouver local chapter of Vivit!

So that was the general session and the morning of DAY ONE. We next went to lunch where I was able to briefly chat to Scott Strubel and get a little more detail on what's up for Canada (I'm not posting that though, it'll be a suprise for my Canuck counter-parts!).

The afternoon got us started on our break-out sessions. Stay tuned for updated posts on those. I'm taking the OVOW8/SiteScope session, and I'll post all the late-breaking news I get from that. I know my customers are eager to hear more about OVOW 8.

Volunteering - Part 2

Wow, I'm bad at updating this blog. :-) That's got to be annoying for the 2 people who read it.
On the plus side, there's lots to talk about now.
The CSI:Vancouver conference is moving along for May, and just this past weekend the Program team (which I'm on) finished up the conference sessions. We've got a fantastic group of speakers ranging from international ITIL experts to local (BC) organizations who are willing to share their experiences with everyone else.
This week I'm out of town in New Orleans at the HP Partner Galaxy event (post to come on that!) so I'll have some cycles in my evening to work on ITManageCast.

At the same time, I've been working with some folks from Vivit (the former OpenView Forum International, HP Software users group) to put together sessions for this summers HP Software Universe in Las Vegas. We've got some great speakers lined up for those sessions which is great.

Back to CSI:Vancouver & itSMF Canada. With the speaker selection completed, and us having decided the order in which we want all the speakers, we now have sent out all the speaker agreements. Assuming that everyone agrees, and that there are no last minute cancellations we'll be good to go! No-one ever said this was going to be easy! Wait a minute, I think I did in my last post. D'Oh!

Well, the next steps are to get the presentation slide-deck template out to all the speakers, and get them to send us their slide-decks for their presentations. That way, we get to both review those, but also to make sure that the speakers are keeping on track and will be ready. So once that gets underway I'll update the blog with the results!

Wednesday, December 19, 2007

Managing Your Heterogeneous Environment - Part the First

What is a heterogeneous environment? Well, what it's not is a the place where a really smart straight guy lives. What I'm getting at is really every IT shop. You may say "Hey, we only run Windows" or "Dude, we're purely SUSE here" but stop for a moment and consider those switches, routers, and UPS' in your IT shop. Are they Microsoft? Novell? Yeah, didn't think so.

So what we've established at this time is that we all work in heterogeneous IT environments. And quite likely, certain aspects of them are managed. Probably quite well (I'm not making the assumption that you can't do your job). But what's the big picture? Are you viewing things as storage, servers, networks, applications, et al and each a world unto itself? This is quite likely the situation.

So back tracking again, we've got our IT shop made up of bits and pieces from various vendors, all working together to deliver some sort of service to our end-users. Now we want to manage the whole shooting match. Get all the system stats, performance data, and alarms into one consistent view.

Well, if you go to any of the tier one vendors, they'll tell you this is simple. "Buy our product, some consulting hours, and you're done." You're done alright. You can have the consultants come in and roll out a great solution, that works for the first few weeks. What you really need in place first to underpin this architecture and provide long-term valuable metrics on your heterogeneous IT environment is a baseline, strategy, and process. Tools can come later, and with the toolsets on the market today, can be largely interchangeable & interconnecting. That's not in any way to dismiss the amount of work it takes to set up the tools correctly in the first place, that IS a lot of work.

What I want to stress here is that managing a mixed IT environment; managing all of your systems components; having that BIG picture of IT service delivery needs a good baseline/audit of what's in place today, a top-down strategy going forward, and processes that work with your people & business practises.