December 30, 2013

Managing Cyber Security Threats from Inside
In addition to NetFlow, security information and event management (SIEM) provides additional information about anomalous server or network behavior. SIEM solutions gather logs from various devices and systems, aggregating them into a correlation server. An event correlation application then mines unusual patterns or patterns known to be related to malicious behavior. Questionable activity is reported to security via email, SMS, or a Web portal.


Breaking down an IPv6 address: What it all mean
Let’s take a long hard look at an IPv6 address. Amazon supply IPv6 addresses with their EC2 cloud computers. ... There’s a lot of meaning packed into that strange-looking identifier. A few companies have tackled IPv6 but to most it’s just plain confusing. Why is it so confusing? And how can you decipher what it means? Connect to your AWS EC2 instance, find your network interface and its IPv6 address, and let’s do some serious IPv6 breakdown.


Introducing Enhanced Mitigation Experience Toolkit (EMET) 4.1
Many customers across the world now include EMET as part of their defense-in-depth strategy and appreciate how EMET helps businesses prevent attackers from gaining access to computers systems. Today, we’re releasing a new version, EMET 4.1, with updates that simplify configuration and accelerate deployment. EMET anticipates the most common techniques adversaries might use and shields computer systems against those security threats.


Software License Audits: Myths, Facts, and Microsoft
In this report, you’ll learn how ITAM and SAM in the Cloud “reboot” Microsoft software license audit preparation. By “reboot,” we mean shuttering some processes, optimizing others, erasing the problem, and starting a fresh new approach to audits. You’ll get a step-by-step action plan to prepare for an audit now. and you’ll learn the specific areas in which ITAM and SAM on the Cloud slash time- to-compliance-position while increasing accuracy and reducing organizational angst. With the ease, speed, and agility provided by Cloud-based ITAM and SAM, Microsoft audits become just “sheep in wolves’ clothing.”


Top 5 IT security webinars in 2013
2013 was the year IT security grew up. Leaks and prominent hacks were the focus for major news outlets and adoption of mobile and new targeted attacks were on the minds of IT security teams. ... The best IT security teams have moved from chasing security to proactively developing risk-based approaches and integrating their security practice with the business priorities of their organizations and the tools and services in the market have begun to reflect that. Without further ado, here are the top 5 IT security webinars in 2013:


Know your storage needs before installing a solid-state drive
With SSDs, Martin said, different drives are suited to different workloads, so it is important to select the right drive for your organization's needs. "SSDs, random, sequential, depending on the make, some of them are better than others, some it's the other way," he said. "It's a different animal." And, he noted, hard disk drives do well with sequential reads. So, depending on the workload, traditional disk may suit your needs.


2013: The tech year in cartoons
From Tim Cook's 'pay cut' to Steve Ballmer's 'retirement,' here's a look at some of the year's biggest IT stories from the pen of Computerworld's editorial cartoonist, John Klossner.


Carey Smith, on Becoming the Team’s ‘Hyperlink’
"I’m sort of a peripatetic manager, and I sometimes describe myself as a “hyperlink.” I have an office, but most of the time I just walk around and try to determine if we’ve got any problems. It might be a minor thing, but I’ll take that and then try to track it back. Sometimes you step on people’s toes, but the point is that everything and everybody are connected in some fashion. And they’re connected, if nothing else, through me doing this sort of thing."


Meet Business Demands by Making BI Effective and Relevant
To realize the full value of BI, businesses need to acknowledge how a solution fits with key business processes. The goal is to equip business users with consistent and specific information throughout all levels of the organization so each group or business unit can best understand and apply the information. The full spectrum of users—from the executive team to line-of-business managers—can use solutions that are relevant to their day-to-day responsibilities.


What does it take to transform an organization before a crisis hits
What can leaders do before the depth and scope of their companies’ crises come into focus? How can they initiate major transformations proactively? As researchers and managers who have been involved in numerous corporate transformations in recent years, we have learned that applying standard formulae to corporate transformations is, at best, ineffective and, at worst, dangerous. What’s needed is a new approach that enables executives to transform organizations proactively without resorting to fear.



Quote for the day:

"You cannot tailor-make the situations in life but you can tailor-make the attitudes to fit those situations." -- Zig Ziglar

December 29, 2013

5 Top Social Media Trends For 2014
"It's no longer passed over as a fad or something that's going away any time soon," he said. "Social media is now part of our fabric of society, like mobile phones and computers -- it's a staple of our everyday life." In 2014, expect a shift in priorities: a bigger focus on social media monetization, user-generated content, a great acceptance of sharing information, and more. Here's a look at the big trends for next year.


The Three Power-People You Need on Your Team
The enemy of success is isolation. The higher you go the easier isolation becomes, but, it’s a devastating problem at all levels of leadership. Isolated leaders fear conspiracies and feel misunderstood. Worse yet, ivory-tower leaders resort to control through authority. Us/them thinking destroys influence. Defeat isolation and enhance success by developing a high-power inner circle.


Proposing Architecture and Process Governance for Risk Mitigation in Organizational Change
Transformation does present new and complex challenges entailing the need for a number of changes, mainly organizational and governance processes. It is therefore necessary to study and analyze the potential risks which may arise from such changes and transformations. This thesis proposes an integrated approach to managing the risks associated with both outsourcing and the transformation of the FTC into a civilian entity mainly in terms of change management, organizational and governance process, using Enterprise Architecture (EA) as leverage, supported by other disciplines and methodologies.


The Chief Data Officer: An executive whose time has come
It takes more than a steep investment, however, to squeeze business value out of data. Companies have to establish an entire system to use data to drive competitive advantage. I believe that the head of this system should be the Chief Data Officer (CDO), an executive whose time to shine has finally come. The sooner businesses can empower a CDO, the sooner they can turn data into a business weapon to achieve business success similar to the aforementioned companies.


Probability and Monte Carlo methods
A common use of the Monte Carlo method is to perform numerical integration on a function that may be difficult to integrate analytically. This may seem surprising at first, but the intuition is rather straight forward. The key is to think about the problem geometrically and connect this with probability. Let’s take a simple polynomial function, say to illustrate the idea.


The Big Lie of Strategic Planning
Strategic plans all tend to look pretty much the same. They usually have three major parts. The first is a vision or mission statement that sets out a relatively lofty and aspirational goal. The second is a list of initiatives—such as product launches, geographic expansions, and construction projects—that the organization will carry out in pursuit of the goal. This part of the strategic plan tends to be very organized but also very long. The length of the list is generally constrained only by affordability.


Monty Taylor and Jim Blair on CI and Test Automation at OpenStack
The OpenStack community has a team working on CI and test automation for the OpenStack developers submitting code. They run their own infrastructure - an OpenStack cloud by itself. Given the complexity of the project, with dozens of dependent projects and over 300 contributors submitting patches every month, standard CI systems simply wouldn't work. We talked with Monty Taylor and James Blair to investigate the build and test challenges they face, and how they managed to tackle them.


Data protection and privacy law for developers
Data protection in EU countries is based on what's known as a "directive" - in this case, its 95/46/ec. The directive is prescriptive in some areas, and in others leaves things up to the interpretation of the national government. This means that in general, data protection and privacy legislation across the different countries of the EU is more or less the same, with some local differences. It's difficult to get things perfectly right in all jurisdictions, but if you start with the core rules, you are most of the way there.


Big Data and the Role of Intuition
Major big data projects to create new products and services are often driven by intuition as well. Google’s self-driving car, for example, is described by its leaders as a big data project. Sebastian Thrun, a Google Fellow and Stanford professor, leads the project. He had an intuition that self-driving cars were possible well before all the necessary data, maps, and infrastructure were available. Motivated in part by the death of a friend in a traffic accident, he said in an interview that he formed a team to address the problem at Stanford without knowing what he was doing.


Establishing Enterprise Architecture Metrics: Seven Essential Steps
Today, the value of EA has become preeminent for most companies integrating their enterprisewide business applications. Many practitioners realize that in a rapidly changing and evolving business environment, an enterprise must measure, manage, and improve its flexibility in successfully deploying integration initiatives. EA can engage both the business and IT teams from the beginning, and EA metrics can present a consistent vehicle to measure most of the critical elements of business value.



Quote for the day:

"Goals are like stepping-stones to the stars. They should never be used to put a ceiling or a limit on achievement." -- Denis Waitley

December 28, 2013

Aaron Levie: The most refreshing voice in the enterprise
At a time when enterprise IT is laboring under constant pressure from reduced budgets, outsourcing pressure, and escalating security challenges, Levie stands out as one of the most refreshing voices in the technology industry. He still believes there's a lot of great work to be done in the enterprise and he's not just a talking a good game. At Box he's leading a team that is hyper-focused on solving enterprise problems.


Testing Basics May Have Averted Obamacare Health Site Fiasco
According to CBS, the security testing was never completed. Fox uncovered a testing bulletin from the day before launch which revealed the site could only handle 1,100 users “before response time gets too high.” The Washington Examiner revealed, via an anonymous source, that the full testing was delayed until just a few days before the launch and instead of the 4 to 6 months of testing that should have been conducted it was only tested for 4 to 6 days.


Welcome to the Lean Service Desk, Part 4: Root Cause Analysis
Lean encourages a structured, disciplined problem-solving approach that is more like informal scientific inquiry. For that reason, we are interested in identifying the root causes of the problem as a precondition to trying to identify solutions. By separating these activities in a very deliberate way, it’s possible to gain enough understanding of the problem to increase the chances of finding solutions that in fact address it.


The Ideas that Shaped Management in 2013
Compiling extremely long lists, struggling to shorten them, and over-thinking it all, when the point should just be to gather some really good reading for you for any free time you happen to find over the holiday. So this year, instead, we thought about the pieces that most surprised us or provoked us to think differently about an intractable problem or perennial question in management, we reviewed the whole year of data to remind ourselves what our readers found most compelling, and we looked for patterns in the subjects our authors raised most frequently and independently of our editorial urging


Do You Know What Life Will Be Like In 5 Years? IBM's Top Scientist Does
In the 5 in 5 report IBM’s top scientists report on what the world, supported by smart sensing and computing, will look like in five years. ... In five years, cities will be sentient. More buses will automatically run when there are more people to fill them. And doctors will use your DNA to tailor medical advice and smart computing to diagnose and plan treatment for big diseases like cancer not in months, but in minutes.


Merchant Warehouse Provides Visual Overview of the State of the Payments Industry
Focused on 4 main quadrants, the Merchant Warehouse State of the Payments Industry will examine and provide up-to-date information covering all aspects of the payment industry from consumer credit trends to important information on regulations and technology. While individual sections will be update regularly as new information and data become available, each quarter Merchant Warehouse will deliver a new report highlighting major updates and trends ensuring that our audience is fully aware of where the industry is and more importantly where it is headed.


Global Stock Exchanges Band Together on Cybersecurity Initiative
In addition to developing cybersecurity best practices, the Cyber Security Committee will focus on establishing a communication framework among participants based on mutual trust and, notably, facilitating information sharing, including threat intelligence, attack trends and useful policies, standards and technologies. Part of that will also be enhancing dialogue with policy makers, regulators and government organizations on cyber-threats and supporting improved defenses from both external and internal attacks.


Establishing Data Governance Policies: Four Issues to Get Them Right
A first-rate data governance policy improves an organization’s ability to demonstrate regulatory compliance, respond to legal inquiries, reduce risk and increase data quality and business process management for increased employee effectiveness and better decision-making. ... Faced with rapidly growing data volumes, varieties and obligations, it is imperative that organizations have data governance policies and technologies that support them in place. The following four steps can help any company manage their data assets


COBIT 5 and the Process Capability Model Improvements Provided for IT Governance Process 
Starting from a general overview of this framework, the structure of the Process Capability Model will be analysed in detail in this paper. Then, a comparison with the Maturity Model of the previous version of the COBIT framework will be discussed. At the end of this paper, it will be seen that the new Process Capability approach results in an improvement of the assessment process; and in particular, in the formality and the rigor of the assessment.


Retrospectives Applied as “PROspectives"
Don’t worry if the PROspective needs more time than planned. As long as the participants - the owners and beneficiaries of the PROspective - are willing to continue, it is fine. You, as the facilitator, are responsible for keeping the process on track to enable reflection, learning, and inventing actions for improvements. If you think the team has lost track of that and the meeting has become a waste of time then share that impression with the participants. If they want to go on anyway, it is their decision. You are the enabler, not the director.



Quote for the day:

"Men meet with failure because of their lack of persistence in creating new plans to take the place of those which fail." -- Napolean Hill

December 27, 2013

The Big Picture for Big Data
Several weeks ago, Information Management had the opportunity to sit down for a wide-ranging discussion with Dr. Rob Walker, vice president of decision management at Pegasystems, the Cambridge, MA-based provider of BPM and CRM solutions. Walker, who holds a PhD in computer science and began his career pioneering predictive analytics at Capgemini in the 1980s, shared his perspectives on the growth of big data and the challenges faced by companies as they struggle to derive real business value from the multitude of data management technologies that ‘big data’ represents.


How application performance metrics keep healthcare software healthy
The application performance metrics you measure for a healthcare application should be focused on improving the customer end-user experience and positively affecting the quality of patient care. Metrics that measure how software applications perform is critical to improving patient care, satisfying regulatory requirements and allowing medical professionals to do a critical job without undue interference.


Top 10 Methods to Improve ETL Performance Using SSIS
SQL Server Integration Services (SSIS) is the tool in the ETL family that is useful for developing and managing an enterprise data warehouse. A data warehouse by its own characterization works on a huge volume of data and performance is a big challenge when managing a huge volume of data for any Architect or DBA. The author in this article discusses on improving ETL performance or design a high performing ETL system with the help of SSIS.


Next step for connected devices? Connect the devices
The thinking is that the big opportunity will be for platforms, or hubs, like SmartThings, vying to tie together the so-called Internet of Things (a press friendly name for the connected device category), said IDC analyst Jonathan Gaw. With consumers actually starting to pay attention to connected products, the need will come for an easy way to manage all of them, despite their different manufacturers and ecosystems, Gaw said. To be clear, connected devices still have a long way to go before they become a mainstay, or even more than an occasional fixture, in American homes.


The first 3D printed organ -- a liver -- is expected in 2014
Advances in the 3D printing of human tissue have moved fast enough that San Diego-based bio-printing company Organovo now expects to unveil the world's first printed organ -- a human liver -- next year. Like other forms of 3D printing, bio-printing lays down layer after layer of material -- in this case, live cells -- to form a solid physical entity -- in this case, human tissue. The major stumbling block in creating tissue continues to be manufacturing the vascular system needed to provide it with life-sustaining oxygen and nutrients.


Penny Pritzker, on Hearing the Whole Story
"And when we get close to saying we want to hire someone, I will talk to them about what could get them fired. If you want to get fired, here’s what you need to do: first, lie, cheat or steal. But the other thing that will get you fired is if you have a problem and you keep it to yourself. Problems are going to happen, and it’s my job to help you with your problem. What I’ve learned is that the most troublesome people don’t tell you 100 percent of the story, and keep some facts to themselves."


2013: The Year Of Security Certification Bashing
The idea that a certification means that a person was capable of passing the test at one time is a sad statement, as it indicates stagnation in one of the least stagnant of professions. No one who worked with packet filtering firewalls has stayed in that era. The progress of the industry simply will not allow it. Most certifications require either upgrade tests or continuing professional education credits to keep the certification in good standing. This is the same method in use by other professions, such as attorneys, doctors, and accounts.


NCSU study says Android vulnerabilities are mostly from manufacturers
Researchers analyzed the customized apps that manufacturers build on top of the baseline version of Android shipped from Google. The apps provide unique features and a look and feel that's meant to make the smartphone stand out in the market. Eighty percent of the apps that come with devices are created by the manufacturers, not Google. "It is worrisome to notice that vendor customizations were, on the whole, responsible for the bulk of the security problems suffered by each device," the study said.


Data Profiling and Data Governance: How Good is This Data?
When dealing with large volumes of data coming in from a variety of sources, in different formats, and delivered by different methods a data profiling automation solution becomes a necessity to efficiently analyze data. Data profiling functionality can often be found as part of a larger data quality technology suite. Profiling tools can quickly process and analyze large data sets and automatically produce a baseline profile, thus replacing the need to run manual queries.


Building a Real-time, Personalized Recommendation System with Kiji
A typical Kiji application will include some number of KijiScoring servers, which are stateless Java processes that can be scaled out, and that are able to run a ScoringFunction using a single entity’s data as input. A Kiji application will funnel client requests through the KijiScoring server, which determines whether or not data is fresh. If necessary, it will run a ScoringFunction to refresh any recommendations before they are passed back to the client, and write the recomputed data back to HBase for later use.



Quote for the day:

"One of the most important tasks of a manager is to eliminate his people's excuses for failure." -- Robert Townsend

December 26, 2013

The top 10 cloud provider tips of 2013
Cloud service providers have had many different opportunities for growth this year, from developing cloud partner programs to building industry-specific cloud markets. Software-defined networking (SDN) was a hot topic for cloud providers this year with several of our most popular expert tips covering everything from overcoming barriers to SDN adoption to determining which model of SDN to deploy. Check out our full list of top cloud provider tips for 2013, including advice on FISMA compliance and an analysis of what "open" cloud services really mean.


Four Tech Predictions for 2014 (From PayPal’s CTO)
What happens when new products and services deliver capabilities that help innovators envision better ways of eliminating friction points that people have been living with for years? What happens is that you get the perfect conditions for the kind of rapid technology-driven transformation that has been gathering momentum in the payment industry for the past couple of years. It’s a transformation that promises to revolutionize commerce by rendering the transaction all but invisible while making the payments process itself a foundation for new experiences that connects consumers and merchants in powerful new ways.


Make a high-performance computing and high-availability datacentre
Datacentre professionals must note also that although the use of virtualisation provides a better level of inherent availability, it is not a universal panacea. Virtual images of applications, virtual storage pools and virtual network paths are still dependent on the physical resources assigned to them, and the datacentre design must take this into account. If the server running the virtual image fails, it will still be necessary to spin up a new image elsewhere on the physical server system and reassign connections.


Leading by Letting Go
The trouble was that the scripts, metrics, and rules were getting in the way. Heavily scripted representatives couldn’t form genuinely warm and empathic relationships. They sounded wooden and stilted. Real relationships are built on open, person-to-person communication, one caring human being to another. ... The results? Call-handling time edged up slightly at the very beginning, then dropped and kept falling. Likelihood-to-recommend scores doubled, indicating far more enthusiastic advocacy of American Express on the part of customers. Employee attrition was cut in half.


The reality of android soldiers and why laws for robots are doomed to failure
For Sharkey robot soldiers can't comply with the basic rules of war. They can't distinguish between a combatant or a civilian or between a wounded soldier and a legitimate target. "There are no AI robotic systems capable of doing that at all," he argues, pointing to one UK-built system that can tell the difference between a human and a car "but has problems with a dancing bear or a dog on its hind legs." A robot weapons system won't be able to judge proportionality either, he argues; that is, judge whether civilian losses are acceptable and in proportion to the military advantage gained by an attack.


SOA Best Practices in the Mobile Age
The new opportunity in APIs is BaaS, an extension to the service API model. The goal of BaaS is to convert common and useful elements of mobile application logic-storage, identity management, social network integration, photo enhancing into Representational State Transfer (REST) Web services that the application invokes as needed, making these services "back ends” to mobile apps. As a concept, BaaS is similar to Software as a Service (SaaS) and Platform as a Service (PaaS); it offers functionality as a Web service.


Martin: Issues to consider when using SSD
There may be a lot of benefits when you add solid-state storage to your environment: greater speed, lower costs of energy and greater efficiency. But the technology has a new set of issues you'll need to monitor. Dennis Martin, president of Demartek, discusses those variables in this Storage Decisions video. He noted that users of solid-state drives have to keep track of data writes to their drives, a practice that isn't necessary with hard disk.


Should everyone learn how to code?
Are good coders simply born and not made? Of course not. But it's true that the best are frequently self-taught and loved coding from the start. Without strong self-motivation, it's very, very difficult to slog your way through the painstaking labor and long hours required to become a decent programmer. To be an excellent one, you need a whole lot of experience, which is why I've heard hiring managers say they're more impressed by an applicant who wrote a mobile app at age 14 than one with a BSCS from a good school.


Venture capitalist proposes California 2.0, a plan for six new states
”Something’s not working in our state, and I’m convinced that it is with the existing system, the existing breadth of industry and varying interests. California is untenable and un-governable,” Draper told a sparsely attended news conference at the Silicon Valley school for entrepreneurship that he created and that bears his name. There were about 20 people in the room, although only six appeared to be reporters.


Visualizing Java Garbage Collection
Modern GC is highly efficient, far more so than manual allocation typical in earlier languages. People from other language backgrounds often focus on GC pauses without fully understanding the context that automatic memory management operates in. Mark & Sweep is the fundamental algorithm used for GC by Java (and other runtimes). In the Mark & Sweep algorithm you have references pointing from the frames of each stack's thread, which point into program heap.



Quote for the day:

"The final test of a leader is that he leaves behind him in other men, the conviction and the will to carry on."— -- Walter Lippmann