May 21, 2013

Enterprise architects: Please leave your framework at the door
There are a lot of valuable ideas in standard EA frameworks, but they need to be customised to be practical. Enterprise architects should use frameworks for inspiration on how to achieve specific outcomes, instead of trying to apply the entire structure to their organisation. What is needed is a "skinny" EA. Leading EA practitioners have refocused on a narrow set of business outcomes to slim down the work effort and maximize the impact of EA.


IT's new concern: 'Bring your own cloud'
"IT has to deal not only with bring-your-own devices but bring-your-own services," Gartner analyst Michael Gartenberg says. People will bypass even viable alternatives if they feel that the officially sanctioned professional cloud offering isn't equal to the task -- or if they have a personal cloud app they like better. "If it's digital and it's consumer, it's going to find its way into the office. People will come up with reasons for using it," he says.


4 VDI Success Tips from an Insider
Citrix is most definitely a front-runner, but that doesn't mean you should immediately disqualify solutions from VMware, Microsoft or Dell. Time has taught us that VDI is not an all-or-nothing proposition, it's not for everyone, nor is it right for all of your workloads. Even then, here are some guidelines you can follow when implementing a VDI project.


Five ways financial services firms can fight the biggest IT security threats
Financial institutions are in a race against cybercrime, and today’s cybercriminals are doing all it takes to come in first. For hackers, the ultimate prize is gaining access to data that can be sold to global criminal organizations. ... To get an idea of the scale of this problem, the 2012 Norton Cybercrime Report revealed that cybercrime cost Canadians $1.4 billion within a recent 12-month period, with the average victim losing $169.


JSON Spirit: A C++ JSON Parser/Generator Implemented with Boost Spirit
JSON is a text file format similar to XML, but less verbose. It has been called "XML lite". This article describes JSON Spirit, a C++ library that reads and writes JSON files or streams. It is written using the Boost Spirit parser generator. If you are already using Boost, you can use JSON Spirit without any additional dependencies.


Social Intelligence: The New Frontier for Business Intelligence
The ever expanding use of social media and mobile technologies has dramatically changed how we communicate and how we interact with the companies that sell to us. As channels of communication expand to include social media networks, blogs, forums and chat rooms, digital and physical lives are intersecting more than ever. What people do online provides an increasingly accurate picture of their customer profile, including lifestyle choices, buying preferences and brand perception.


40 years ago, Ethernet's fathers were the startup kids
"Our spec was, we wanted to connect 255 personal computers at a distance of a mile, at some number of hundreds of kilobits per second ... and we wanted to do it with a minimum of cabling, because the predecessor networks all had these rooms full of cables that we called 'rat's nests,'" Metcalfe said.


In Memory: Just Because You Can Doesn’t Mean You Should
A few pioneer database vendors realized that using memory as the prime storage resource was a good, albeit costly, idea. As the price of RAM has fallen (on average it seems to fall at about 30% per annum) more database vendors have begun to offer in-memory options and capabilities. Indeed it seems that the in-memory database might even become fashionable.


Q&A: Why WLAN test tools should evolve quickly -- but likely won't
As more enterprises shift their wireless LAN infrastructure from being a side feature to their primary access network, testing these environments is becoming increasingly crucial. Network design expert Peter Welcher of Chesapeake NetCraftsmen spoke to SearchNetworking about the impact of wireless LAN growth in the enterprise and what it means for network management tools and troubleshooting tactics.


CIO interview: Colin Rees, IT director, Domino's Pizza
Rees is also not fazed by cloud computing fears and security risks. “Part of the challenge is to separate reality and rumour,” he says.  “The reality is that the security risks are high even in an internal data centre if managed poorly. In fact, we have seen a big improvement in reliability and a reduction in downtime with cloud systems. Over time, the distinction between cloud and non-cloud will thin out,” he adds.



Quote for the day:

"Truly strong leaders find a way to be kind even when others aren't." -- Mary Jo Asmus

May 20, 2013

Realizing Efficient Enterprise Security Intelligence
Security intelligence is built on the same concepts that have made business intelligence an essential enterprise technology. It is the critical next step for organizations that recognize the importance of information security to their business health. In this IBM® Redguide™ publication, you see how security intelligence addresses the shortcomings and empowers organizations from Fortune 500 companies, to mid-sized enterprises, to government agencies, to maintain comprehensive and cost-effective information security


Countdown clock begins for Singapore data compliance
The date all data protection compliance project teams in Singapore have been waiting for has been announced. July 2, 2014, is D-Day when Personal Data Protection Act will come into effect and when organizations will need to complete data inventory mapping, process audits, staff training, and publication of various processes.


Financial services and the public cloud: Go or no go?
“You have to overcome a lot of resistence from regulated industries before moving their stuff to the public cloud … You’ll have a hard time with your auditors in the short term if you go to public cloud,” Perretta told me recently. But, he’s keeping his eyes open because the cost savings of the public cloud are too good to ignore if these other issues can be resolved.


Linux/Cdorked.A malware: Lighttpd and nginx web servers also affected
Before going any further, one point needs to be clear about Linux/Cdorked.A. We still don’t know for sure how this malicious software was deployed on the web servers. We believe the infection vector is not unique. It cannot be attributed solely to installations of cPanel because only a fraction of the infected servers are using this management software. One thing is clear, this malware does not propagate by itself and it does not exploit a vulnerability in a specific software.


Is the Software-Defined Data Center a Good Fit for Financial Services?
The main concern with using a public cloud is that services are typically provided in multi-tenant environments. ... As a result, financial services, healthcare and insurance companies usually bypass pubic cloud solutions in favor of implementing private clouds within wholly owned or dedicated data centers. The capabilities offered by the software-defined data center (SDDC) are perfect for private clouds, and accordingly, are an appropriate fit for financial services, healthcare and insurance companies ...


How technology is changing the way we think about security
Indeed, the prelude to "destructive" attacks are disruptive attacks, which incidentally appear to be coming from nations that sponsor terror. The Distributed Denial of Service (DDoS) attacks which the financial sector has experienced in recent months are a good example of disruptive attacks ... So what can we do about it? In a recent security brief, Big Data Fuels Intelligence Driven Security (pdf), experts from RSA, Northeastern University in the US and Booz Allen Hamilton, set out the components for a big data-oriented security management system


Visibility Fabric Architecture
Sitting between the IT infrastructure and the tools that need the access to the traffic traversing the network, the Visibility Fabric architecture is comprised of the GigaVUE® family of fabric nodes and patented, advanced-level intelligence that can aggregate, filter, replicate or modify traffic to centralized management, analysis and security tools. The Visibility Fabric architecture is modular and extensible—suitable for a variety of networks of different size and scale from 1Gb connectivity to 2.4Tb chassis-based solutions.


Collaborative Approach to Smart IT
As the CIO of a large merged entity, Dohsung Yum, CIO, The Attachmate Group, had the tough task of ensuring a smooth IT integration of four businesses. As a veteran of the IT industry, Yum advises senior IT executives on how to plan IT strategy and work out an effective collaborative approach and a smart project plan in a merger scenario


Business Architecture
Business Architecture should be expressed independently of how the business architecture will be mapped to the underlying application architecture and infrastructure architecture, but is more connected to the business/contextual view of the information/data architecture and will include the organisation architecture.


What does done look like? - Project World Collectable Card #6
The reason why your project exists, is because it has to fulfil a goal, create an end result. The organization has a challenge to conquer or an opportunity to take advantage of. The goal of your project is a powerful mechanism for alignment. Everyone is working towards the same result. But first you have to make sure we all have the same understanding of what “done” looks like.



Quote for the day:

"Close scrutiny will show that most "crisis situations" are opportunities to either advance, or stay where you are." -- Maxwell Maltz

May 19, 2013

How a Scrum Master Can Handle Impediments with a Team
The expectations and collaboration between the scrum master and the team are important to make impediments work. Impediments are handled in different ways, a look at how some scrum masters do it. In the blog post, Gunther Verheyen discusses the role of the scrum master with respect to impediments. Starting from the scrum guide, he explains that the scrum master is expected to remove impediments, but that doesn't mean that (s)he has to find them:


When was the last time you assessed your coding risk?
Many coding errors that are identified go unreported externally as they are either found very quickly, appear to be an isolated problem for a customer, or do not impact customers in a significant manner. What is most amazing is that many of these events are identified and reported to organisations by customers rather than through internal processes. Therefore, we ask the question.


Enterprise Architecture – Needing Governance and Compliance
Whilst acknowledging that exceptions to strict adherence to Enterprise Principles and Standards may be required, the impact can be managed as part of Governance andCompliance processes. The risks brought to the business by the exceptions, once identified, can be mitigated. A Framework plus Governance plus Compliance are all essential components of an Enterprise Architecture.


How to Lead Great Leaders
As a boss or team leader, you have to lead people every day. It makes life easier when you have established authority and your followers are generally compliant. But someday you may find yourself leading powerful leaders, perhaps for a board meeting, a nonprofit, or even a high-level management team. These focused and dynamic people create completely different challenges for a facilitator.


Don’t be an ‘idea killer’: 10 tips for cultivating creativity
The broader leadership equivalent would be an idea killer, wouldn’t it? An idea killer may be a boss who actively shoots down proposals, or passively lets them languish. It may be be a manager who doesn’t know what it takes to build a culture of effective brainstorming, networking and innovation. So that’s how I danced my way into crafting this list. It’s for leaders who never want to be known as idea killers:


Why Software Product Delivey is not Identical to a Car Delivery?
A well written SoW (Statement of Work) clearly lists down the acceptance criteria, which when met would constitute acceptance of the delivery by the client. For a given requirements, no two vendors would build an identical solution. That's due to the tools, technologies out there for use and the varying intellectual abilities of those involved in building the software.


Azul Systems release Zing Platform Edition for WebSphere Application Server
InfoQ interviewed Azul CEO Scott Sellers about the launch and about Azul Systems. "The Zing PE announcement is special in that we have introduced specific optimizations for WebSphere Application Server (WAS) that make it really easy to deploy Zing in the context of WAS deployments, which are traditionally complex, especially when deployed to multiple instances"


The Postdigital CIO: Transforming Business Through Innovation
Recognizing that businesses can harness these postdigital forces to produce breakthrough innovations that transform the competitive landscape, C-suite executives throughout industry sectors are turning to CIOs to play an increasingly strategic role. What are the possibilities for the CIO’s role in the postdigital era? Two examples illustrate the potential that some organizations have already captured.


JavaScript Design Patterns - The Revealing Module Pattern
Addy Osmani describes the Revealing Module pattern as: "The Revealing Module pattern came about as [Christian] Heilmann was frustrated with the fact that he had to repeat the name of the main object when he wanted to call one public method from another or access public variables. He also disliked the Module pattern's requirement of having to switch to object literal notation for the things he wished to make public"


ESB Persists As Application Integration Tool
ESB has entered yet another transitional phase. Jason Bloomberg, president of ZapThink, a Dovel Technologies company, says there's a lot of noise in the market for and against ESBs. "It's a little hard to cut through and find out what's really going on," Bloomberg says. "Customers are generally confused about the whole thing."



Quote for the day:

"Have no fear of perfection--you'll never reach it." -- Salvador Dali

May 18, 2013

Researchers uncover 'SafeNet,' a new global cyberespionage operation
"While determining the intent and identity of the attackers often remains difficult to ascertain, we determined that the SafeNet campaign is targeted and uses malware developed by a professional software engineer that may be connected to the cybercriminal underground in China," the Trend Micro researchers said in their paper.


The Journey from Big Data to Big Promise
While much around big data remains hype, many companies are in the fledging stages of drawing value from their big data corpus, and given an army of discussions and opinions around the topic, it’s still hard to find a clear roadmap to arrive at the Big Promise. ... basically analytics can be categorized into three categories functionally, they are Descriptive Analytics, Relationship Analytics, Prescriptive Analytics.


Why an Internet sales tax is such an incomprehensibly bad idea
It will result in further damaging our economy while also causing the loss of jobs while also causing states and the federal government to collect less revenue, not more. It's not just that consumers will buy less online if their purchases are taxed. It's that operating an online store that deals with sales tax accounting is a very non-trivial task.


When Rule Books Block the Road, Throw Them Out
“We’re not going to be governed by a culture that defines a set of rules. We’re going to be governed by a culture in which we hold ourselves accountable for great performance, and for understanding that we trust each other enough that people are going to make good decisions because they’re here for the right reasons.”


10 key questions about software-defined networking
SDN as a network solution is not nearly as far along as virtualization in the server and storage worlds. Nevertheless, SDN is coming — and the more IT decision-makers and business leaders know about it, the better they’ll be able to determine where and when to introduce it to their data centers. Here are 10 of the questions they’re asking about SDN.


9 takeaways from Google I/O that matter to users
Google held its sixth annual I/O developers conference this week. During a nearly four-hour keynote address Google executives outlined some of the more enhanced features they are working on, several of which are available now. While many were geared specifically toward developers, most of them apply directly to consumers. Here are some of the more intriguing announcements.


How the consumerization of the enterprise has affected two firms
The companies' approaches to the consumerization of the enterprise were as different as the size and distribution of their workforces: Slalom has about 2,000 employees spread out across the country, whereas Huber's previous employer had 45,000 global employees. Huber shared his perspectives on how two companies handle consumerization differently, from mobility management to cloud support and more:


Innovation Isn't Working At 4 Out Of 5 Companies
Alon thinks the questions left plenty of wiggle room for execs to give their innovation programs the benefit of the doubt. "We didn't frame it as 'everlasting' competitive advantage," Alon said. Another metric in the study shows that for every one of 15 different innovation areas, execs were less likely than they were three years ago to rate them "very satisfied." "Commercialization and launch" and "consistent innovation performance" fared particularly badly.


Pushdo botnet is evolving, becomes more resilient to takedown attempts
In March, security researchers from Damballa identified new malicious traffic patterns and were able to trace them back to a new variant of the Pushdo malware. "The latest variant of PushDo adds another dimension by using domain fluxing with Domain Generation Algorithms (DGAs) as a fallback mechanism to its normal command-and-control (C&C) communication methods," the Damballa researchers said Wednesday in a blog post.


The Immune System is Risk
An effective risk management system is the immune system of the organisation. It is built to identify and mitigate against the “bad” viruses (problems) and to ensure the promotion and proliferation of the benefits. It also provides processes to continuously monitor the effective performance of the organisation in mitigating the “bad” viruses.



Quote for the day:

"Company cultures are like country cultures. Never try to change one. Try, instead, to work with what you've got." -- Peter Drucker

May 17, 2013

IT performance measurement is critical for strategic business decision making process
Organizations are now beginning to look at how they measure IT performance against fast changing business and organizational needs as IT and the business are expected to work more closely to drive business growth. Dataquest spoke to Amit Chatterjee, country director, HP Software India, to get insights on the HP-Coleman-Parkes Research study conducted in late 2012 across the APacJ region to assess the changing nature of IT performance measurement.


Google issues YouTube ultimatum to Microsoft as Hatfield-McCoy feud heats up
The letter read. "We were surprised and disappointed that Microsoft chose to launch an application that deliberately deprives content creators of their rightful earnings, especially given that Windows Phone 8 users already have access to a fully-functional YouTube application based upon industry-standard HTML5 through the Web browser."


3 Ways Co-location Data Centres Are Helping Your Business
Aside from talking about big data exclusively, Ian shared his view on data storage and suggested that the importance is where the solution is being built: “If the solution is built on a rock rather than on sand, that could be the very difference between that solution being a strategic competitive advantage for a company or failing versus the competition.”


Cross-Platform Development with Portable Class Libraries
Portable Class Libraries (PCLs) allow you to write code that can be targeted at a combination of .NET frameworks. You select the frameworks you want to target when creating a PCL project to gain assembly portability across those frameworks. You do lose some functionality, however -- the feature set available to your library is the intersection set of the features in the selected frameworks


Google rolls out by-the-minute cloud billing, introduces a new NoSQL database
At its developer’s conference today, Google also announced a cloud-hosted database for managing non-relational data. Cloud Datastore includes auto-scaling and replication for high availability, along with the ability to run SQL-like queries, the company says. The database is a natural complement to Google BigQuery, a data analysis application that’s already part of the company’s cloud platform.


Is outsourcing the answer to IT innovation?
Innovation Process Outsourcing is a critical step in embedding innovation habits into an organisation's DNA. An experienced innovation firm will be intimately familiar with the difficulties of involving broad sets of enterprise stakeholders in a collaborative process. Working underneath the innovation leader, outsourced programme managers can be embedded into the organisation as change agents and campaign managers.


Do you Really Need to Embrace Analytics?
If you have not witnessed the deluge of big data and business analytics media coverage to date, then welcome back from the coma you were apparently in for the last couple of years. For the rest of you, perhaps you have the same nagging question that I have: Are big data and business analytics such a big deal that if our organization is late to the party in deploying them, we will never catch up to our competitors?
The company has vehemently denied and dismissed this as a mere ‘speculation'. But the fact is Polaris, going by a report in Times of India, it says, "IT majors Wipro, HCL Technologies, and L&T Infotech has evinced keen interest in buying Polaris' service business which constitutes up to 80% of its revenues. The deal size is pegged at anywhere between $300 mn to $350 mn and Axis Capital is facilitating the deal".


DDoS attack trends highlight increasing sophistication, larger size
Morales indicated that attackers are "doing a bit more of their homework" when it comes to understanding the attack surface of a potential target. For example, a bank might serve a lot of SSL-encrypted traffic to its online users, so attackers will employ methods specifically geared toward exploiting that traffic. "That's what the attackers do, is figure out where your least point of resistance is and they use that against you," he said.


Google Wallet makes payments possible through Gmail
To send money through Gmail, the user composing the email has to hover over the attachment paperclip, click a $ icon to attach money to the message, enter the amount, and send the mail, Travis Green, Google Wallet product manager, said in a blog post on Wednesday. The recipient will receive an email confirmation that the money was sent immediately after.



Quote for the day:

"Enterprise Architecture is NOT a project. It is a way of life." -- John A. Zachman