Sunday, May 31, 2009

CyberSecurity Role

New cyber-security role to be created in US Government. The information and network security strategy will be refreshed. Cross-governmental integration and public / private partnerships will be used to strengthen the quality of this effort. Protection of privacy remains a key principle. ...

... "Today, I want to focus on the important responsibilities this office will fulfill: orchestrating and integrating all cybersecurity policies for the government; working closely with the Office of Management and Budget to ensure agency budgets reflect those priorities; and, in the event of major cyber incident or attack, coordinating our response. To ensure that federal cyber policies enhance our security and our prosperity, my Cybersecurity Coordinator will be a member of the National Security Staff as well as the staff of my National Economic Council. To ensure that policies keep faith with our fundamental values, this office will also include an official with a portfolio specifically dedicated to safeguarding the privacy and civil liberties of the American people. " ...


Via The White House: Cyber Infrastructure

Labels: , , , , , , , ,

Wednesday, October 01, 2008

Cyber Security Aware

State CIO promote awareness of cyber security. Here are eight best practices and advice for protecting children. ...

... "National Cyber Security Awareness Month is designed to increase the public’s awareness of cyber security and crime issues, so that citizens can take precautions to avoid those threats on the Internet. " ...


Via National Association of State Chief Information Officers: National Cyber Security Awareness Month

Labels: , ,

Friday, December 21, 2007

Info Security Risks Still Elevated

Firewalls secure. Virus software up to date. Feeling secure. Think again. The information security battle rages on. ...

... "According to Stewart, information security is no longer just a battle against a virus or spam attack. There are oftentimes legal, identity-based and geopolitical factors involved. As examples, he points to identity theft at major retailers and a recent distributed denial-of-service attack allegedly launched by politically motivated hackers within Russia on its neighbor Estonia this spring. The cyber attack, which reportedly stemmed from outrage over Estonian authorities' decision to move a Soviet-era war memorial from a park, shut down many of the country's government Web sites. " ...


Via Cisco: Inaugural Report on Global Security Landscape

Labels: , , , ,

Saturday, May 05, 2007

2012 Olympics IT Project

Olympics technology discussion gets started. ...

2012 Olympics

... "She said there was potential for another IT project failure in the way the technology was being allocated. " ...


Via BBC NEWS: 2012 Olympics Technology

Labels: , , , , ,

Tuesday, February 20, 2007

Federal-IT Project Management Progress

Federal government makes progress in IT project management
Feds make progress on the IT project management front, close gaps in security, and have more work to do on talent. ...

... "OMB also reported that, based on current agency submissions, 83 percent of major IT investments have qualified project managers compared with approximately 70 percent reported in last year's submissions. " ...


Via GCN: IT Perspective on the Federal Budget

Labels: , , , , ,

Tuesday, December 12, 2006

Data Security Breach: High Impact Public Event

UCLA discusses its data security breach
UCLA deals with painful security event in open, transparent way. The security investigation shows that the security breach was exploited to seek Social Security numbers and started as early as October 2005. The university has established a website specifically to handle this event. ...

... "UCLA is alerting approximately 800,000 people that their names and certain personal information are contained in a restricted database that was illegally and fraudulently accessed by a sophisticated computer hacker. " ...


Via UCLA: UCLA Warns of Unauthorized Access to Restricted Database

Labels: , , ,

Wednesday, November 22, 2006

Managing the Grey Areas: Lessons from the Leadership Quadrant Seminar

On November 15th and 16th, I conducted a seminar with productivity consultant Jerome Jewell called The Leadership Quadrant: 4 Ps for Organizational Excellence. The 4 Ps are Principles, People, Productivity, and Process. It was held at the National Constitution Center in Philadelphia, and we incorporated the museum’s rousing multi-media show, Freedom Rising, into the seminar.

The seminar participants came from the healthcare, criminal intelligence, and manufacturing sectors, which led to some fascinating discussion and dynamics. With any seminar, the value to all in attendance is magnified by the contributions of the participants, and this was no exception.

In the seminar, which included sections on principles, emotional intelligence, systemic thinking, talent management, innovation, project management, and more, the collective group highlighted a number of “grey areas” that a manager must frequently weigh when making decisions.

Some questions arose, such as:

"What if someone no longer likes a role they excel at and prefers a role they're poor at?"

"Do people always need to see the big picture?"

"Should one person be expected to serve the role of a manager, leader, and administrator? A strategist and tactician? A generalist?"

"How do you strike a balance between effective time management and remaining available to your staff?"

"Are recurring meetings effective or are they time wasters?"

In line with these questions, below are some of the factors that managers must consider:

  • People’s individual needs vs. organizational goals
  • Big picture inclusiveness vs. security (or the desire to give people narrow focus)
  • Using generalists vs. specialists (and where the specialty should focus – on a functional area or on a particular skill)
  • Effective time management vs. flexibility and being available to your staff’s needs
  • Recurring meetings vs. consideration for people’s time
  • Informing vs. influencing (for deciding whether to email or meet; even then, the decision is not always straightforward)
  • Innovation vs. execution (knowing when to move from ideation to “getting things done”)
  • Systemic (whole view) thinking vs. systematic thinking (routine, repeatable process)
  • Vigilance vs. delegation (how much is safe to delegate, and to whom?)
  • Firm principles vs. ethical dilemmas (should a firm principle ever be bypassed?)

In all of these cases, the group determined that the answer isn’t always black and white, and that each situation requires weighing these items. The trick is to observe, orient, decide and act quickly (referencing Colonel John Boyd’s OODA principle).

On the item of firm principles vs. ethical dilemmas, the group applied lessons from various cases throughout history where the US Constitution was challenged. It was obvious that there was no “one size fits all” answer.

With more recent events, consider OJ Simpson’s book. If you manage a bookstore with a principle of defending freedom of speech, do you carry O.J. Simpson’s new book, even though it is "ethically challenged," to say the least? Most large-chain bookstores creatively tried to satisfy both sides of the equation by donating all of the proceeds to the victims’ families. Of course, in the end, the book was canceled, but for a while, this was a real challenge to bookstores.

All of this reaffirms that management is abstract, not concrete. Managers cannot have all the answers; but they can and must insure that the right questions are considered, and they must have the courage to make decisions.

Labels: , , , , , , , , , , , ,

Tuesday, November 21, 2006

IT Governance: Data Security Matters

Take data security seriously and dedicate time in the IT governance agenda for it. Define security policy and create roles / accountability for it through postion of information security officer. ...

... "Formalize an IT governance process with documented policies and controls. Representatives from different departments, including IT, should develop this manual together as a task force led by the ISO. " ...


Via Miami Herald: Link

Labels: , , , , , ,

Monday, November 13, 2006

Principled Leadership: Giuliani

Giuliani explores presidential candidacy and fashions himself as a principled leader. Can he hold his own with Napoleon? ...

Giuliani on leadership principles

... "Leaders need to be optimists. Their vision is beyond the present, and it's set on a future of real peace and security, Giuliani said. Some call it stubbornness. I call it principled leadership. " ...


Via Yahoo! News: Link

Labels: , , ,

Sunday, November 05, 2006

Asset Management: Secure, Track Your Laptops

A number of interesting experiences and lessons are at play here for Starbucks ... The need for better security of private employee data. Traceability of its information technology assets. In this case, the company is not even sure that the assets are out of its possession. And, finally, transparency. Starbucks is being pretty open about the situation, as embarrassing as it is. They'll learn and improve from the experience. ...

... "Starbucks Corporation announced that four retired (no longer in regular use) laptops have been identified as missing from the Starbucks Corporate Support Center in Seattle. Two of the laptops contained the private information, including names and social security numbers, of nearly 60,000 United States partners (employees) and less than 80 Canadian partners and contractors at all levels employed across the organization prior to Dec.31, 2003. At this time, there is no indication that the private information in question has been misused or that the devices are in the hands of someone intending to misuse the information. These laptops may still be in the possession of Starbucks, however we cannot currently locate them. In accordance with Starbucks standards for information security, the laptops were password protected. " ...


Via Starbucks: Link

Labels: , , ,

Tuesday, May 23, 2006

CIO Drives Enterprise Architecture Standardization and Best Practices: A Common Theme ...

United Business Media will standardize its enterprise architecture ...
CIO drives standards and best practices to moderate IT spending to acceptable percent of sales. A recurring theme. Where's the innovation or differentiation? ...

... "In terms of governance and best practice that means things like the introduction of the Prince 2 project management principles, IT information library (ITIL) guidelines for IT infrastructure and BS7799 certification for security. " ...

CIO Drives Enterprise Architecture Standardization and Best Practices: A Common Theme: Via silicon.com: United Business Media CIO Matthew Graham-Hyde ...

Labels: , , , , , , , , , ,

Monday, May 08, 2006

New IT Security Courses for Project Managers

Alan Calder and IT Governance Limited are now offering two courses for those saddled with trying to bring their organization up to the new ISO 27001 security standard.

One is a one-day introductory course for IT managers, project managers, and business managers. The fact that it's priced at about $720 and explains how to implement the standard in-house without expensive consultants makes it very appealing.

The other is a three-day intensive class that covers the whole implementation process and framework.

Both courses are in London in June.

For those that are managing IT security initiatives, these courses look well worthwhile.

Labels: , , , , , ,

Wednesday, March 15, 2006

CIO Role: Innovate or Perish ...

Much of the information technology (IT) organization is becoming a commodity, and, like many in the IT profession, CIO's know that they must innovate or perish in the capabilities and services that they as leaders deliver to an enterprise. The CIO role is evolving and there is a trend underway to expand the role into shared services leadership, chief process improvement officer, and other job variants. United Airlines CIO expands his horizons and, hopefully, the career paths of the IT organization. ...

... "Garry Kelly, who is currently serving as United's chief information officer, will assume additional responsibilities. Kelly will assume oversight for enterprise-wide strategic sourcing and continuous improvement, in addition to his information technology responsibilities. He oversees all aspects of information technology functions at United, including corporate IT strategy, applications development, technical operations, information security and infrastructure planning. In addition, he is also responsible for industrial/process engineering and the operations research functions at United. Kelly will report directly to Glenn Tilton, United's president, chairman and chief executive officer. He is replacing Rick Poulton, who has elected to leave the company. " ...

CIO Role: Innovate or Perish: Via United Airlines: United Airlines Expands Chief Information Officer Garry Kelly's Role ...

CIO's must innovate or perish in their careers ...

Labels: , , , , , , ,

Monday, January 16, 2006

Alan Calder Hosts SOX Webinar

Alan Calder, the leading IT Security and Governance guru, will be hosting a webinar on January 25th to talk about ISO 27001 (the new security standard) and how it creates a full-range solution for Sarbanes-Oxley compliance, drawing from CobiT, ITIL and ISO 17799.

For more, here's the info...

Alan Calder on IT Governance, information security and ISO 27001 (BS7799): SOX webinar

Labels: , , , , ,

Thursday, December 29, 2005

ITIL Managed Services: Security Outsourcing ...

Firm sees growth opportunity in recurring revenue for ITIL-compliant managed services in security. ...

... "Complexity has reached a point that you need to unify criteria, you need a security policy, then you need an administrator with expertise in ITIL for all of this. So the companies are now saying it is cheaper to outsource all this and not worry about security than to train and maintain such a person, Vuoso said." ...

ITIL Managed Services: Security Outsourcing: Via Business News Americas - Latin America's Business Information Leader: Etek unit: Service revenues to match consulting in 2006 ...

Labels: , , ,

Wednesday, December 28, 2005

SOX 404 Solution: IT Controls Automation

New software release incorporates controls automation, testing, and reporting in a comprehensive library of business processes. ...

... "With the new release, MetricStream Design now enables users to identify any control as a process-level application control or a process-level general IT control or a process-level manual control. In addition, MetricStream Design now enables users to capture general IT controls by defining IT as a separate function with various processes such as acquisition, change management, service level monitoring, security, incident management etc and enabling customers to easily comply with COBIT, ISO17799 and ITIL standards. MetricStream Assess now provides a framework that automates the testing of process level application controls and reports the results for the entire test - including manual and application controls, in an integrated manner and also provides an out-of-the-box library containing more than 1500 tests for automating the testing of application level controls in general ledger, procure-to-pay, order-to-cash, inventory / cost Accounting, asset management and payroll processes. " ...

SOX 404 Solution: IT Controls Automation: Via MetricStream: MetricStream adds full support for IT Controls and Automation of Application Control Testing in its SOx 404 Solution ...

Labels: , , , , , , , ,

Wednesday, November 30, 2005

Microsoft Security: Risk Govern Audit ...

Microsoft is making concerted effort on security management, appealing to technology independent partners with services focused on security policy, governance, compliance, risk assessment, risk management and auditing, while balancing its focus on infrastructure security, the technical perspective. ...

Microsoft Security: Risk Govern Audit: Via ISACA: Microsoft Partner Program Includes ISACA Certification in Restructure of Its Security Solutions Competency ...

... "Having a skilled and innovative security partner ecosystem is central to the company’s approach and, therefore, a large part of the effort has been significant changes to the Microsoft Partner Program, Security Solutions Competency, announced this week in partnership with long-established certification programs from Information Systems Audit and Control Association® (ISACA®) and International Information Systems Security Certification Consortium (ISC)2. " ...


Michael Domingo provides update on Microsoft's updated approach to security, which balances the technical with the strategic security management: risk, govern, audit. ...

Via Microsoft Certified Professional Magazine: Security Competency Gets Revamped

... "Microsoft says it has taken a technology agnostic approach within its Security Solutions competency, splitting it into two specializations that address technical issues and the other that looks at security policy and risk management, governance, and auditing. " ...


With more than 47,000 members who live and work in more than 140 countries, the Information Systems Audit and Control Association® (ISACA®) is a recognized worldwide leader in IT governance, control, security and assurance. Founded in 1969, ISACA sponsors international conferences, publishes the Information Systems Control Journal®, develops international information systems auditing and control standards, and administers the globally respected Certified Information Systems Auditor™ (CISA®) designation, earned by more than 40,000 professionals since inception, and the Certified Information Security Manager® (CISM®) designation, a groundbreaking credential earned by 5,200 professionals.

Labels: , , , , , , , , , , ,

Wednesday, November 23, 2005

The New ISO 27001 Security Standard; Get Prepared! Listen to Alan Calder's Podcast

As I've mentioned before, the perfect storm is headed our way. As more companies move toward hosted solutions and the threat of a pandemic computer virus looms, organizations worldwide could be crippled.

Enter the new ISO 27001 Security Standard.

Alan Calder, the leading IT Governance and Security expert and CEO of IT Governance, Ltd., issued a podcast last week talking about ISO 27001 and its impacts. Best of all, Calder offers several eBooks for all levels of audiences, as well as an ISO 27001 toolkit, which allows organizations to become ISO 27001-compliant without expensive consultants.

Here's what Calder's company, IT Governance Ltd. has to say about the new standard:

  • ISO 17799:2005 and BS 7799 are the international best practice information security management standards, defining and guiding Information Security Management System (ISMS) development.
  • BS7799 is the basis for the new international standard ISO 27001, which was introduced in October 2005. Internationalisation will create a global upsurge in demand for ISMS certification.
  • ISO 27001 will become the international touchstone for effective, secure information management practices that protect organisations and ensure their compliance with data protection, privacy and computer misuse regulations.
  • As with ISO 9000, the new standard will become a prerequisite for many businesses wishing to secure new customers and contracts. It is therefore as much a business issue as an IT issue.

    To learn more, check out Alan Calder's podcast below...

    Alan Calder on IT Governance, information security and ISO 27001 (BS7799): Talking ISO 27001

Labels: , , , , , , , ,

Saturday, November 12, 2005

Earned Value Management System: Risk Perspective ...

ASC will identify, manage and mitigate risks on its military projects using Welcom's software, which complements its existing use of the earned value management capabilities. ...

Earned Value Management System: Risk Perspective: Via Welcom: Australian Submarine Builder ASC Pty Ltd Chooses WelcomRisk ...

... "ASC has been using our Cobra project cost and earned value management system since 2002, and we see the selection of WelcomRisk as a further endorsement of WST Pacific and Welcom's project portfolio management solutions, said Steve Cook, president of Welcom. " ...

Earned value management is complemented with a risk management perspective through software system ...

WelcomRisk is a formalized risk management tool for the proactive identification and mitigation of business risk, both threats and opportunities. WelcomRisk combines a user-friendly interface with a higher level of flexibility and granularity than other products. Its flexible integration capabilities and tight security provide companies with a better solution across the enterprise. WelcomRisk is part of WelcomSuite™, a comprehensive solution that supports portfolio analysis, project collaboration, planning and scheduling, and cost and earned value reporting.

Labels: , , , , , , , , ,

Thursday, November 10, 2005

IT Strategy: Integrate Mobile Technology and Workforce Mobility ...

Nokia offers advice on strengthening IT strategy by enabling workforce mobility through integrated mobile technology. ...

Via Nokia: Nokia identifies five phases of workforce mobility to help companies gauge and guide their use of mobile technology: Key stages help companies measure the value of their own approach to mobile technology and outline the building blocks necessary for a successful strategy ...

... "The five stages start from an organization's idea of mobile technology and the integration of mobility into an overall IT strategy, and play out the course of mobile technology to the point where the way business is done is forever changed. That shift is still ahead, but in between the two extremes lay several phases many companies can identify with now - from starting to mobilize workers as more of a matter of convenience, to taking the notion of mobility for granted and focusing on increased productivity. Integral to getting the most from mobile technology are several building blocks Nokia has identified that companies should keep in mind when developing and implementing a mobile strategy. These pieces consist of much of the same components that make up any IT strategy, including leveraging existing assets and infrastructure, addressing diverse user needs, and ensuring security, scalability and support is in place. " ...


Incorporate mobile technology in the IT strategy to drive workforce mobility ...

Labels: , , , ,

Tuesday, November 01, 2005

Enterprise Architecture: SEC Future State: Troux Metis ...

Troux and ISI partner to drive the enterprise architecture transformation at the SEC over the next few years. ...

Enterprise Architecture: SEC Future State: Troux Metis: Via Troux: SEC Taps Troux Technologies and ISI for Multi-Year Enterprise Architecture Program

... "Troux Technologies, the global leader in IT Governance and Enterprise Architecture (EA) solutions, and Integrated Systems, Inc., a foremost 8(a)-certified systems integrator, announced they have jointly won a multi-year contract from the U.S. Securities and Exchange Commission to implement the SEC's Enterprise Architecture and increase its business value. Under the agreement, Troux and ISI will collaborate to provide the SEC's Office of Information and Technology with consulting expertise in documenting the SEC's current state architecture, and in developing and maintaining future state target architectures. ... Troux's Metis Enterprise is an Enterprise Architecture and planning solution that provides the basis for the transformation from an organization's current state to an optimized future state. It is designed with a highly scalable database that accommodates the volume of enterprise-wide data required for successful organizational transformation. Additionally, Troux's Metis offers a unique analysis capability, leveraging both the current and future EA states. The automated data collection in Metis, from disparate sources across the organization, keeps information timely and relevant. " ...


Troux's Metis will be used to model the future state enterprise architecture at the SEC ...

Integrated Systems, Inc. is dedicated to the development and implementation of high quality technology- and process-based solutions for government and commercial clients. Founded by Indrani Seetharam in 2000, ISI is a Minority Woman-Owned 8(a)-Certified small business, currently providing sophisticated technical solutions to the U.S. Treasury, the Departments of Homeland Security (US VISIT Program), Transportation (National Highway Traffic Safety Administration), Energy, Agriculture and Education; the National Archive and Records Administration; the State of Delaware; and the US Navy Space Warfare Center (SPAWAR). ISI's focus areas include Enterprise Architecture, Information Assurance, Information Security, Certification and Accreditation, Independent Validation and Verification and Life-cycle Management. ISI develops practical, affordable, and deliverable solutions of significant value to its clients, on or ahead of schedule.

Troux Technologies (pronounced "true") is a global provider of IT Governance software that accelerates IT and business transformation. Troux's IT Governance solutions enable organizations to strategically plan the enterprise, capture and analyze critical IT and business data and deliver actionable decisions to transform the business. Troux's breakthrough technology provides the enterprise-class information, policies, and analytics critical for IT excellence. With Troux, organizations succeed in breaking the traditional IT silos and effectively aligning IT with core business goals. Based in Austin, Texas, Troux Technologies serves the Global 1000 and government marketplaces.

Labels: , , , , , , , , , , , , , , ,

Software as a Service: Microsoft Office Live: Project Collaboration ...

Microsoft Office Live will be released in beta in a software-as-a-service model (similar to Salesforce.com), which can support online project collaboration. ...

Via Scobleizer - Microsoft Geek Blogger: Matt Rolak says that Office Live is up

... "Matt Rolak links to the new Office Live site. " ...


... "Via Microsoft: Microsoft Office Live: Microsoft Office Live will offer you and your employees expert business management applications, such as customer, project, and document management tools, and a security-enhanced private Web site ... " ...

Labels: , , , ,

Wednesday, October 19, 2005

Increase IT Career Opportunities with Certifications & Education

This July 2005 article titled, "IT Certification: Increasing Women’s Career Opportunities" really could apply to anyone who may feel they aren't being taken as seriously as they should be. Some key points:
  • For whatever reasons, there are STILL few women in senior IT and business roles
  • Respected and relevant certifications/education can help to establish credibility and increase leadership opportunities (the key words are respected and relevant - if your company doesn't respect a Master's in Liberal Arts from City College, it probably isn't going to get you the corner office at THAT firm, but it may help you find your next job at a firm that values education in general; perhaps a Master's in Comp Sci or a certificate in Project Management from PMI (yes I am biased) would be more respected by your firm and relevant to your job, for example, and hey, it doesn't take as much time to achieve either)
  • Most respected certification programs demand continual education and training for retaining the designation (PMI's Project Management Professional (PMP) is no exception)
  • IT security and governance programs are reaching the top levels of organizations today - who are they going to choose to lead these important efforts? Someone with a string of respected and relevant certifications or not?

The answer is clear. Eat your alphabet soup - but pick out only the respected and relevant letters.

CertMag.com IT Certification: Increasing Women�s Career Opportunities

Labels: , , , , , , , , , ,

Thursday, October 13, 2005

Branded Project Management Methodology: Service Differentiator

CIBER leverages a branded project management methodology, CPMM, to differentiate its services in the information technology marketplace. It wins another e-government contract as key partner for hosting and portal management services ...

Branded Project Management Methodology: Service Differentiator: Via CIBER: CIBER Selected by City of Cleveland to be New Website Hosting and Management Partner ...

... "Following the transition, CIBER will perform an in-depth security assessment of the website system to establish additional functional requirements, including enhanced content management capabilities and increased security measurements. Based on those requirements and strengthened capabilities, CIBER will enhance the site using the CIBER Project Management Methodology (CPMM), which combines best practices from the fields of project management and quality assurance with practical insights gained from CIBER's extensive delivery experience. " ...

Labels: , , ,

Wednesday, October 12, 2005

IT Service Delivery Management: Excellence Model

Ah!, the sweet taste of ITSM IT services management ... Hershey's adopt Sun Micro's service excellence model to improve the delivery of business value. Sun has developed a portfolio of aligned IT services, called SunTone. ...

IT Service Delivery Management: Excellence Model: Via Sun Microsystems: The Hershey Company Continues To Use Sun Microsystems' SunTone Service Excellence Model to Improve IT Service Delivery Management ...

... "Sun Tone is part of Sun's integrated portfolio of aligned services that provide IT infrastructure planning, assessments, and resolution services for customer business issues. SunTone helps enterprises derive greater business value from IT, transforming IT from a support function to a provider of business-led services that create competitive advantage. SunTone Service Excellence Model provides guidance and a measurement system for Sun Tone users. The new SunTone Service Excellence Model 3.0 brings advancements in industry standard and regulatory compliance, major enhancements in security, greater manageability, and requirements for financial management.

By adopting the SunTone Service Excellence Model and consistently operating enterprise data center services in accordance with SunTone certification requirements, Hershey was able to improve service availability and operational efficiency. Hershey was also able to reduce the time and effort required to meet requirements for IT governance. Hershey's experience is representative of a current global market trend to adopt IT service management (ITSM) principles to improve IT governance, compliance, drive operational efficiencies and derive greater business value from IT. The SunTone Service Excellence Model covers all the elements involved in delivering IT services -- system architecture, operational processes, and human skills. " ...


The Hershey Company (NYSE: HSY) is a leading snack food company and the largest North American manufacturer of quality chocolate and non-chocolate confectionery products. With revenues of over $4 billion and more than 13,000 employees worldwide, The Hershey Company markets such well-known brands as Hershey's, Reese's, Hershey's Kisses, Kit Kat, Almond Joy, Mounds, Jolly Rancher, Twizzlers, Ice Breakers, and Mauna Loa, as well as innovative new products such as Take 5 and Hershey's Cookies.

Labels: , , , , , , , , , , , ,

Monday, October 10, 2005

IT Governance: SAP ESA Strategy

Implementing effective IT governance is suggested as a pre-requisite to the transition to SAP's enterprise services architecture, SAP ESA.

IT Governance: SAP ESA Strategy: Via Search SAP: Breaking down SAP's ESA strategy ...

... "... according to Naeem Hashmi, chief research officer of Information Frameworks, an IT research and strategic consulting group in Londonderry, N.H. Good IT governance and a hefty amount of planning should prepare most enterprises for the changes ahead, he said. " ...


SAP has developed a consortium-based strategy to its enterprise services architecture ESA:

... "SAP has established Enterprise Services-Ready to identify products that incorporate the Enterprise Services Architecture, leveraging the power of business process services in the enterprise. This standards based certification ensures that SAP and partner ISV solutions that are Enterprise Services-Ready are able to extend ESA functionality across the IT landscape, to help organizations design, deploy, run and maintain innovative business processes at lower cost and higher flexibility. Industry support for Enterprise Services-Ready and ESA as the enabler of flexible, next-generation business continues to grow, already adopted by Adobe, Avaya, Computer Associates, Dell, EMC, HP, Intel, Macromedia, Mercury, Microsoft, Network Appliance, Novell, Research In Motion, RSA Security, Symantec and VERITAS. " ...

Labels: , , , , , , , , , , ,

Friday, October 07, 2005

ITIL Microsoft Operations Framework Assessment ...

ITIL Microsoft Operations Framework Assessment: Transformation Success Story: Network Operations & Security Center ...

Anecdotal evidence of Microsoft's experience with ITIL service processes: Capt. Nick Mossing, 83rd Communications Squadron, reports on ITIL transformation experience at the ACC Network Operations and Security Center, which provides network services ...

... "In February, Microsoft's ITIL experts led a one-week Microsoft Operations Framework assessment of the NOSC's IT Service Management functions. The target of the assessment was not technology, but business processes. Several independent studies have identified that over 80 percent of IT system downtime is due to people and processes, not technology. In March, Microsoft delivered a 106-page report providing 71 recommendations for IT best practices. Six months later, the ACC NOSC has completed just over half of the recommendations and the results have been remarkable. " ...

Labels: , , , , , ,

Friday, September 30, 2005

ITSecurity Professional: Project Career Path

ITSecurity Professional: Project Career Path: Via Musings on Information Security :: Who gets to manage security?

Discussion on career path progression for IT security professionals and how business experience gained from project management may be a catalyst for future success ...

... "In a company to manage risks it requires business sense which many security techies may not have - business sense involves communication skills, project management skills and political skills. " ...

Labels: , ,

Monday, August 29, 2005

Information Technology Architecture: Operational Excellence Projects ...

Information Technology Architecture: Operational Excellence Projects: Via Ecutel: Constellation Energy Selects Ecutel Viatores Mobile IP VPN: Re-engineers Mobile Remote-Access Capabilities for Field Services ...

IT architecture aligned with strategic goal of operational excellence drives project portfolio for Constellation Energy ...

... "Several years ago Constellation Energy developed a process for guiding their IT Architecture and Practices called Achieving Operational Excellence, or AOE. The program mandated common practices across operating units, reduction of IT vendors and utilization of standard off-the-shelf applications wherever feasible. Several projects were instituted as part of the AOE program, including a Field Resources Management (FRM) project. Wireless mobility was incorporated under the FRM project. " ...

Standardizing information technology architecture drive operational excellence project portfolio ...

Ecutel Systems, Inc. is a pioneering provider of networking and enterprise mobility solutions. The company’s next-generation, standards-based Mobile IP VPN products bring together security and seamless mobility to improve productivity throughout all facets of the enterprise, from simple and secure remote access for mobile workers to remote management for IT professionals on the go. Ecutel's products are currently sold worldwide and are used by hundreds of government, public safety, healthcare, education, and enterprise customers. The company's products include Viatores Mobile VPN and Infrastructure Command and Control (IC2).

Beth S. Perlman, Chief Information Officer and Senior Vice President, Constellation Energy: Beth S. Perlman joined Constellation Energy in 2002. As Chief Information Officer and Senior Vice President, Ms. Perlman is responsible for all company-wide information technology initiatives, including the standardization of systems and architecture.

Labels: , ,

Sunday, August 07, 2005

CA Niku ITGovernance Growth Engine?

CA Niku ITGovernance Growth Engine?: CA Completes Niku Acquisition to Extend Leadership in IT Governance

Will the CA Niku deal ($350MM) drive growth for CA in the IT governance space or limit the growth of a good EPM tool? Time will tell ...

... "With the acquisition of Niku, whose revenue grew 45 percent in its last fiscal year, CA gains a best-in-class offering in a market segment that is growing faster than the software industry as a whole. Niku's ITG solutions will be integrated with CA's BSO unit. CA's BSO solutions enable customers to align IT investments with business objectives, control IT costs, deliver IT as a service, and meet heightened compliance requirements. CA estimates the market for its BSO solutions at $7.9 billion in 2004 with an estimated compounded annual growth rate of 8 percent through 2008. " ...


Computer Associates International, Inc. (NYSE:CA), one of the world's largest management software companies, delivers software and services across operations, security, storage, life cycle and service management to optimize the performance, reliability and efficiency of enterprise IT environments. Founded in 1976, CA is headquartered in Islandia, N.Y., and serves customers in more than 140 countries.

Labels: , , , , , ,