Wednesday, August 7, 2013

Education, education, education. Did I mention education?


·         Christmas Eve, 1997, it was a story of “Not a creature was stirring, except for the email administrator”. I had started a new job in October as an Applications Manager for an LLP to whom email was crucial. One of my challenges moving forward was to migrate the company from Groupwise mail to MS Exchange. The Groupwise system had been having a lot of issues, according to the CIO. He felt that the aging technology was causing undue stress on the company’s partners and, therefore, undue stress on him. Until such time as we were able to schedule the migration, it was my responsibility to stabilize the existing email system to reduce the noise about email. That afternoon, I remember reaming out an attorney for sending pictures of his daughter at a horse stable to over twelve relatives. His emails were slowing down the delivery of the dancing elves that others had sent. Stuck between those files were some crucial contracts that had an expiration date of midnight. The glut of files took time to clean out and caused mail to be backed up for hours. Thankfully, Exchange is easier to cleanup and bandwidth is cheaper.

·         In 2000, I was told by an older partner at the LLP, “You can’t fix stupid”. He in fact called the person who caused the 3rd or 4th outage due to an outbreak of the Iloveyou virus. I was standing in his office while he bellowed at the unfortunate person, “Are you insane or just stupid?” Although we had gotten quite proficient at our response to the breakouts, time down for attorneys meant less billable hours.  After that incident, we thought out of the box and came up with a solution to prevent a spread of the virus, before the antivirus companies came out with signatures, and over a year before we bought an email filter solution.

·         When Michael Jackson’s memorial service was streamed across the internet, we actually had to shut down streaming (possible only because of the technology we had already purchased) and access to social websites to keep end users from shutting down or slowing access to our revenue generating web-based applications.

·         Going over a corporate file server (inevitably looking for disk space), we first targeted media files. Over 30% of the directories had a variety of non-work-related music, video and photos. Before you ask, yes, there were policies that employees signed off on that notated there should be no such files saved on corporate systems.

·         Performing a social engineering “test”, employee after employee failed (including technologists who felt they should investigate a dropped memory stick in case it fell into the wrong hands) to follow corporate guidelines.

Looking back, end user behavior hasn’t significantly changed. Luckily, technology has evolved to manage these situations with more success than in the past. But is that what makes the most sense?

·         Email filter - There are multiple products and services that manage this better than any threatening phone call and far less expensive than dealing with a data breach.

·         Antivirus/Malware solutions are absolute MUSTS.

·         Disk Space management products - Data quotas can be set up at system creation but once a system is in place, it’s impossible to go back and perform cleanup without manual involvement. A good ole dos batch file scheduled to run once a week can go a long way toward keeping servers clear of media files that shouldn’t be there.

·         Patching solutions – I appreciate the simplicity and ease of patching with a managed solution but depending upon the size of a company, it may not be feasible. This has to be a cost benefit decision on the part of technology. How many hours and techs does it take to patch the environment? Can this be done manually in a timely enough basis that it prevents exploits? If the answer is no, then consider a management solution that offers sufficient flexibility so that patching can be managed in a risk adverse manner.

·         Intrusion Detection System – Consider this as a risk proposition. If you are a financial services company, the risk may be greater than the cost of reacting to a breach. With security industry prescribed firewall configurations and port blocking on subnets, it is possible to adequately defend your parameter. With other security restrictions in place, it IS possible to detect and defend against fraudulent insider behavior.

Creating a stable, structured and secure technology environment does not happen out of luck, not forever.

Taking a layered approach:

·         Begin with end user and technology team education,

·         Taylor your policies and procedures to support the risk footprint the corporation is willing to support,

·         Don’t jump to the conclusion that expensive software solutions will fix all of your problems. Without adequate processes and procedures in place, a team will fail, regardless of the tools provided.

·         Implement built-in support tools

o   Don’t ignore the value of logging,

o   Don’t ignore the value of team-led strategy sessions for issue reviews,

·         Invest in your team’s education and morale

·         Invest in solid vendor partnerships. They will be as interested in your success as you are.
 
And honestly, prayer never hurt.

 

 

 

Thursday, May 30, 2013

Protecting your online identity


Small businesses have so much to potentially lose in the event of a data breach. Whereas a larger corporation may have insurance and/or forgiving customers, smaller companies are far more vulnerable to the possibility of losing their business, their customers, and their credibility.
While one can never state that they are 100% confident they will never be breached, taking a layered approach will at least provide multiple deterrents.

Start with your pc:

1)      Changing the local administrator userid. To do this,

a.       Log onto the pc as the administrator

b.      Go to the Start Button and select Control Panel

                                                               i.      Go to User Accounts

                                                             ii.      Rename the Administrator Account.

2)      Disable the Guest account

a.       Log onto the pc as the new administrator account you’ve renamed

b.      Go to the Start Button and select Control Panel

                                                               i.      Go to User Accounts

                                                             ii.      Select the Guest Account

                                                            iii.      Select Turn Off

3)      Don’t use the administrator userid for everyday work purposes

a.       Create a standard user userid

b.      Log onto the pc as the administrator

c.       Go to the Start Button and select Control Panel

                                                               i.      Go to User Accounts

                                                             ii.      Select Create New Account

                                                            iii.      Type in the name of the account

                                                           iv.      Select Standard User

4)      Turn on Windows Update (this can occasionally create problems – confirm with vendors if you have customized software written that depends on certain settings that Windows Update could turn off or install. (An example is the version of Internet Explorer you are running).

a.       Log onto the pc as the administrator

b.      Go the Start Button and select Control Panel

                                                               i.      Select System and Security

                                                             ii.      Select Windows Update

                                                            iii.      Turn Automatic Updates on

5)      Use complex passwords and change your passwords every 60-90 days

a.       Complex passwords consist of a mixture of characters

                                                               i.      Use Lower and Upper alpha characters

                                                             ii.      Use at least one number

                                                            iii.      Use special characters

b.      The password should be at least eight characters but preferably more than ten

c.       Use a passphrase. Something like Iliveinflorida

d.      Perform a character replacement

                                                               i.      Instead of I, use the number 1

                                                             ii.      Always put an exclamation point at the beginning or endings of your phrase

                                                            iii.      Instead of O, use the number zero

                                                           iv.      Instead of an A, use the @ symbol

                                                             v.      Instead of an E, use the number 3

e.      Use different passwords for applications or web portals

6)      Maintain up to date Antivirus and Malware Software

a.       Purchase one that has a pc tune-up component and you’ll insure your pc’s will be more stable as well

b.      Monitor that virus updates are occurring and scans, both full and quick are taking place                        

7)      Be aware of who is accessing confidential, sensitive and/or customer data

a.       “Trust but confirm”

b.      Don’t “overshare” online – once something is out on the internet, it’ll never be private again

These are basics but they are the first step to creating a layered approach to securing your pc and therefore, your online identity.

The next blog will deal with internet browser settings.

Wednesday, May 15, 2013

Lessons to learn from Jurassic Park

Jurassic Park; what a brilliant concept. A new product that would be a draw to a high percentage of people, regardless of race, creed, or gender, and no competition, what a dream for any business owner. Unfortunately, it failed. Why? A lack of structure, design and processes brought about the complete downfall of the greatest re-creation ever thought of.

One of my favorite lines is said by Jeff Goldbloom’s character, Ian Malcolm, “but John, if the Pirates of the Caribbean breaks, the pirates don’t eat the guests” – I appreciate that fact as a Disney World attendee.
Vision and Scope

·         A zealot running an organization without some counter-controls is a poorly structured company or department. Even brilliant entrepreneurs need a respected counterpart or cohort who will consider the risk of scope and direction.

·         Just because you “can”, doesn’t always mean you should (That’s an Ian Malcolm quote)

·         If you can do it, someone else can figure out how too as well. How do you deal with competition? Intellectual espionage is not just a movie creation.

·         What John Hammond created was a new ecosystem where extinct animals and plants interacted with native animals and plants. He “thought” he created a theme park. The two have nothing in common and in fact, have very different needs and goals.  “All theme parks have issues.” His words, not mine. (or rather Michael Creighton’s). Be sure that you have adequately defined your intentions. Be true to those.

Design

·         I would be thrilled to see brontosauruses and triceratops walking around. I wouldn’t have to see a T-Rex to be satisfied. Why couldn’t herbivores have been Phase 1 and carnivores been Phase 2 after a series of Lessons Learned meetings? Of course, that too could bring its own set of issues.

·         Who defined the DMZ? Poisonous dinosaurs that walked around on the way to the Pier? Sounds like a bad plan to me. (business comparison – data should only be placed in control areas with fences)
Process

·         Poor project management. Experts in the subject matter were only approached after a catastrophic issue had occurred.

·         Poor hiring procedures – Dennis Nedry, the genius from Cambridge, was a poor hire. A good background check would probably have showed that he had credit issues that could negatively impact a top-secret and highly profitable business.

·         No Separation of Duty – Nedry was a programmer who 1) wrote code, 2) introduced it into production (without testing) and 3) also had access to the secure area where the frozen dinosaur embryos were stored. In his role, he did not have a responsibility for the embryos. That should have been restricted to a business need only role. At a minimum, someone should be reviewing who does what, where and when.

·         Introducing code into production environment without peer review – This allowed Nedry to turn off the security systems so he his covert actions could escape notice.

·         Fail-safes had variables that Subject Matter Experts saw the holes in, versus  internal architects.

·         Lack of disaster recovery plans and testing, (how do you get to the point of bringing in a focus group to sign off on the environment without having undergone a full disaster recovery test?)

o   Fail-safes had variables that Subject Matter Experts saw the holes in, versus  internal architects, (withholding lysine, female vs male frog dna)

o   Key systems had dependencies that endangered the overall stability of the environment,

o   Raptors – testing the defenses – pay attention to predators inside and out, (who knew they could open doors, who knew they were testing fences to identify weaknesses?)

o   Underestimating the potential for chaos,

o   Who thought it was a good idea to put the master power controls physically past the raptor environment?

·         Underestimating what you don’t know – bring in Subject Matter Experts, if for no other reason than to put a stamp on your architecture and plan,

·         Poor hardware/memory configuration of systems – if compute cycles are so intensive that they are able to bring down security systems, the environment is not sufficiently robust to be in production. Of course, its possible that Nedry’s excuse was simply a lie – but wouldn’t Mr. Samuels have known that?

·         Just because you “can”, doesn’t always mean you should

Hindsight is 20/20 but the majority of the issues created by John Hammond’s zealous attitude could have been foreseen if he had brought the right people in at the right time and had the right processes and disciplines in place. The brilliance of brainstorming is that different professionals’ experiences contribute to the overall plan and experience. Jurassic Park is a terrific example of what could go wrong in a business. Lessons learned?

·         Pitch your idea to someone you respect
·         Bring in “no-men or maybe-men” versus yes-men
·         Plan
·         Plan some more (you can be on the cutting edge and still follow this advice)
·         Create a structure that resists weaknesses
·         Test
·         Communicate
·         Succeed

Saturday, April 20, 2013

The $100k Door Stop

In my spare time, I enjoy decorating. My sons’ bedroom is decorated in a pirate’s theme and they love it. They are constantly running down the hall between the living room, their play room and their bedroom. At times, you just need to listen for the sound of little feet slamming on the floor or the sound of their bedroom door being flung open and make sure you’re out of the line of fire. I won’t tell you how many times I’ve had to jump out of the way to avoid being run over.

I was thinking the other day that it would be a good idea to get them a door stop for their bedroom door so there would be one less potential casualty in their mission to move as quickly from point A to point B with as few interruptions as possible. Well, I found one. I absolutely fell in love with this door stop. It’s a rope knot doorstop, sold by Ballard’s Design. For those interested, here is the URL:  http://www.ballarddesigns.com/rope-knot-doorstop/accessories/doorstops/10736?defattrib=&defattribvalue=&listIndex=0. The door stop’s price is $45. While that’s not an exorbitant amount of money, I think it’s a little pricey for a door stop, so I’m probably going to attempt a DYI project.

So, how does this in any way relate to technology? Let me tell you about a door stop that costs a tad bit more than $45.
A few years back, a peer, an Architect Manager walked into my office and delivered what I’m sure, he considered a landmine. “I just bought a server that your team will never be able to support.” Having been in the position for less than 6 months, I wasn’t sure exactly how to respond to the comment so merely said, “Great. Thanks.” He turned on his heel, seemingly disappointed at my lack of reaction. Internally, I was cursing life and this dysfunctional boob who was willing to sacrifice company stability for personal reasons.

In that particular instance, this Architect Manager purchased a system that no one in our company had ever supported and on top of that, the only requirement of any sort that was provided was that it be on an operating system that again, my engineers had never supported, Power Linux. That system became a very expensive door stop. It was delivered but no project plan had been developed for the system replacement. Once the business was engaged and a project plan created, it was found that the initial purchased needed an additional $100k or so of additional purchases to support the environment; storage, licenses, training, etc. The system sat for a year before any work was ever even started. 1/3 of the warranty period was eaten up waiting for teams to make plans and implement the solution. An additional six months went by before a timeline could be found to take a business outage. You see, this system was for a replacement of the support of the most crucial application in the company. It housed the largest database in the company. No small fete to replace. A three day outage would be necessary so Thanksgiving was the planned window. Teams across infrastructure, database, application support and the business were necessary for successful implementation.
The end of the story? A year later, the system was not performing properly, was impossible to update, the vendor did not provide reliable and experienced support and the business was again screaming about performance. A full system replacement was necessary in order to resolve the issues. The additional problem this time around? Our credibility was at risk.

This story is the perfect example of why IT purchases have to be scrutinized and considered from multiple views. At the time, no architectural standards existed for server environments. The only standards that existed were for desktops and those were sadly outdated with only a gig of RAM being the standard. You’re probably shaking your heads and wondering how it was possible to operate under such chaotic circumstances. The evolution to stability was not easy and was fraught with changes, both personnel and cultural. Otherwise, your IT purchases become extremely expensive doorstops and your IT department is taking away from your corporate stability and growth versus contributing.
·         First, you have to create, maintain and follow industry best practice supported architectural standards,
      o   By doing this, you insure decisions will withstand scrutiny
      o   You create an environment that is supportable and sustainable
            §  Purchasing systems that have the same core operating system or hardware is a key way    to reduce support cost
·         Next, a heck of a lot of planning needs to take place before hardware delivery is scheduled
      o   Who is going to provide the requirements?
      o   What is the system lifecycle going to be?
      o   How does this impact current business goals?
      o   What other projects are going on and how does this fit in with those?
      o   What is the priority?
      o   Is training necessary?
·         Engage business analysts and stakeholders whose involvement is key to the success of the project AND to the understanding of the application functions. (You may wonder why I added this bullet item because this may seem a natural approach. Some architects assume they understand the business well enough to avoid getting the business involved in the planning and implementation components.)
·         Schedule hardware delivery once you have established how much time is necessary for testing, configuration and training for your team
  o  Protect your precious warranty period (every day the system is in production past the initial warranty is at a costlier warranty level)
·         Allow your teams time for hardware burn-in (Hint:  less than a year)
·         Document baseline performance expectations
·         Document the Support Plan
·         Use both Architects and Support team engineers to plan these steps

I don’t know any business that wants to or can afford a $100k door stop. Maybe that $45 isn’t so bad after all.

Sunday, March 24, 2013

If you can’t count it, it doesn’t count


Early in my career, I worked as a Statistical Analyst. I learned that you virtually live and die by your numbers. I learned that if you can present numbers to back up a discussion, you are a world ahead of those who can’t. So, once I moved into technology and I would hear someone present a case that a system was having problems, I would ask for the numbers or if I were the engineer in question, I would present numbers.
On the other hand, I was sometimes surprised that the numbers didn’t support what I was hearing from end users, which raised serious question marks in my mind about where problems really lay. At that point, deep analysis is necessary to reach the true root cause.

For IT:
While I am an advocate of producing metrics, it is key that IT departments not rely so heavily on the metrics that they forget to listen to the end users. From end users, you may get different messages:
·         The network is slow,
·         The system is slow,
·         My pc is slow,
·         Everything is slow

The reality is, the numbers will tell the true story. That is, IF there are numbers. Mature IT departments, with seasoned Service Management teams, metrics to demonstrate:
·         System availability
       o   Outages due to 3rd party providers,
   o   Outages due to extenuating circumstances,
   o   Outages due to excessive system use,
       o   Outages due to human error,
       o   Mean time to recovery,
       o   Mean time between outages,
·         Percentage of systems nearing obsolescence,
·         Percentage of systems nearing end of warranty state,
·         Percentage of systems requiring patching exceptions,

For a team that hasn’t quite matured to the point of providing full-blown metrics yet, system availability, obsolescence state, warranty state and patching state are a great place to start.

If you’re on the IT side of the house, meet with the business on a regular basis. By doing this, you become someone they are confident is going to listen to their issues.  If you are on the business side of the company and your IT department isn’t providing these metrics, ask why.

For ERM:
When creating or maturing an ERM (Enterprise Risk Management Program), the same can be said for metrics. You live or die by your numbers. KRI’s (key risk indicators) assist a company’s management and/or Board of Directors become more risk aware. The BoD should not be the last group (behind the press) to know about risk issues. Technology risk items need to include those items listed above but also align and support the business risk attitude. Unfortunately, meaningful KRI’s are impossible to manage unless there is a sufficient amount of measurable data.

Keep in mind that KRI’s are ever-changing depending upon a company’s strategy and goals. This may be uncomfortable for those who are of the mind to build a system and then leave it alone – “if it ain’t broke, don’t fixit it”. Key Risk Indicators/factors do NOT work that way.
·         Link KRI’s to a company’s strategy,
       o   This allows for the development and awareness around key risk factors,
       o   Map KRI’s to strategic initiatives,

This allows management to become more proactive in preventing risk issues from occurring by observing metrics,
       o   B e careful that indicators actually provide a clear picture of the risk. Just having a metric doesn’t mean the metric has value.

·         KRI’s create a unique experience to evaluate and communicate the company’s strategy
   o   After reviewing the key risk indicators, it’s possible a company may rethink strategy based upon the risk associated.

Another advantage to an ERM is that focus becomes proactive versus trying to figure out after the fact why a project or system failed. That’s key to the success of a growing company. Think of it as an early warning system that can give you the advantage you need to avoid risk.

If you are having difficulties figuring out where to start, give CGSolutions of Jax a call. We can help you work through the inertia and get to the guts of a reliable and informative process.

Sunday, March 17, 2013

A Mother’s Choice/A Woman’s Choice


I’ve got about 8 IT blog topics documented to write on but this topic seems to be in the news a lot lately and near and dear to my heart. Please keep in mind that this blog is simply based upon my decisions and my hopes/dreams/my realizations of what works for me and my family.
The debate regarding what a woman’s role “should” be and “can” be has been around since I became a mother for the first time in 1982. At 21, I was a fulltime student and a fulltime Intake Specialist at a social agency servicing the blind. The decision to continue working was a financial one. When I had my second daughter in 1987, the decision to continue working was again financial, I was a single parent with two small children.  By that time, I had left the social agency for career growth and to be closer to home. I wanted to spend less time commuting and more time with my daughters.
I was fortunate in that I had a close-knit family and I was able to drop the girls off at my parents’ home before leaving for the office. They rode the school bus to and from my parents’ home. I felt like I had a checklist of items that I needed to have in order to insure my daughters’’ wellbeing.  They were with people who cared about their wellbeing, check. I was still available and engaged, check. My job as an Analyst afforded me the opportunity to work 40 – 45 hours a week and have weekends off. I was able to be a Brownie Troop leader, Sunday school teacher, an advocate for strong curriculum at school board meetings and an attentive mother.
Fast forward six years. I was in IT management for a national law firm (eventually they become international). I worked 50 – 55 hours per week. I was still active and engaged in the girls’ lives but I was also travelling for work at times. As my role increased, my father and I sat down and had a talk. He was proud of what I was accomplishing in my career and wanted to assure me that he and my mother would fill in where needed. My daughters were becoming used to running by the office and enjoyed opportunities such as Bring Your Daughter to Work Day. I made sure I was home at a reasonable time and turned on my pc when needed to work. The downside was the year I was on the road for over six months. I was gone during the week and home on weekends. Luckily by the time the project was over, the girls had only had two meltdowns. I dealt with the meltdowns by taking the girls onsite with me for a few sites. What I learned was that the three of us had an amazing connection and I needed to insure there were no more long projects.
The girls learned to send messages on my blackberry for me if I was in the middle of cooking or working with puppeteers at the Church building. They learned what made a good datacenter. They occasionally slept on the sofa in my office while I worked an issue. None of this impaired them as people.
Later when I worked for a large telecommunications company, one of my daughters napped during an all-nighter anti-virus configuration issue. The girls learned to be flexible. They learned that the hours at the office were what paid for the annual family vacation, cars and savings. I learned their thresholds for my time and attention. They survived a three month project when I worked 80-90 hours per week by a lot of phone calls and notes left on the bulletin board. The one rule I insisted on with my employer was that I would take every Sunday off. The girls and I made the most of our Sundays. They were older and better able to adjust; I was smarter about how I managed our time together and apart.
Fast forward to what seems like another lifetime. My daughters were off to college and a career. I had met my husband and a marriage a few years down the road I was the parent of twin sons. As Operations Infrastructure Director of a growing environment, I was focusing on stabilizing the environment. My husband, never having been a parent before, was relishing his new role. I was relishing having sons for the first time but was also basking in a more secure, stable and available work environment that my team had built. I was torn between priorities but knew I was making the right decisions for my family. My husband’s support was priceless. We were lucky enough to have a niece living with us who needed a part time job. We coordinated her hours so she could nanny and still be a full-time college student. They boys needs were met.
While there were times when I would have an all-night issue with hourly calls and then the next night have a baby that couldn’t sleep, they were not so frequent that they became a problem. More of a problem was the level of increasing stress at the office.  At some point, every professional has to weigh how much stress and its impact on their personal life is too much.
Fast forward a year and a half later. I’m the President of my own company. My sons are in Pre-Junior Kindergarten and excelling. My company is growing and becoming more demanding. I am basically living the dream I never knew I had. My husband and I work as a team with each of us doing what is necessary at any given time. We’ve pushed aside tradition roles and we work from our strengths. Do I feel guilt when I am away from my sons? No I don’t. They are with people who care about them and will help them become better people. They understand that work is necessary to buy “stuff”. We have more time together and its quality time. I don’t want them to sleep on my office sofa while I’m pulling an all-nighter, but it’s possible.
I’m not baking a lot of brownies or cookies these days but I still make a mean green eggs and ham upon request. We have art time as long as I don’t have a deadline but they understand what deadlines are, and how that means mommy has to focus or they have to stay in extended care.
My goal is to raise independent, self-starter citizens who have a strong work ethic and want to make the world a better place. I want them to understand self-control and self-discipline. Most importantly, I want them to know they are loved. I know I was successful with my daughters. I am confident my husband and I will do that for our sons. For my family, for myself, ultimately, the choices have worked.