Apr 15

BCS Logo

BCS Service Management Specialist Group

Subject: Multi-sourcing – How Ready Are You?

Date: Monday 10 May 2010

Time: Registration & refreshments at 18:00 with talks commencing at 18:30. Finishing around 20:00 followed by wine, finger food and informal networking.

Venue: BCS, The Davidson Building, 5 Southampton Street, London, WC2E 7HA.

See http://www.bcs.org/upload/pdf/london-office-guide.pdf

for directions.

Speaker: Daniel Jones, Partner at TPI

Synopsis:

Many organisations today are working with multi-sourced IT services; some have arrived at this state through disjointed sourcing activities whilst others have set out with the strategic objective of working with best of breed providers, spreading their risks by avoiding lock-in to a single supplier and at the same time realising IT cost reductions. The rise of Business Process Outsourcing, cloud based services and globalisation are all contributing to pressure for adoption of multi-sourced IT services.

A new approach is required for end to end governance and performance management that enables organisations to realise their objectives in a multi-sourced model. This talk sets out risks and challenges that accompany Multi-sourcing, and proposes the approaches necessary to achieve the intended level of service performance and the planned financial outcome. Examples from both Public and Private Sectors will be explored.

About Daniel: A graduate of the London Business School, Daniel has spent over 20 years in consultancy, application development and IT services in senior roles for a number of major service providers and working with clients in the Media, Pharmaceuticals, Retail, Financial Services, Pharmaceuticals and Public Sectors. Prior to joining TPI he was the Managing Director, Civil Government and Healthcare at EDS, responsible for the delivery of BPO and IT services to a portfolio of clients, many of them operating with multiple suppliers. He is currently responsible for TPI’s Public Sector business.

Registration: This event is free to current BCS members and £15.00 (+VAT) for non members.

please use www.bcs.org/events/registration to register for this event.

Mar 30

In the quest for metrics that describe what we do in the data centre and how efficiently we do it, we’ve nailed PUE which despite it’s shortcomings has been adopted as the first simple metric to describe the inefficiency in getting power from the utility feed to the IT equipment.

So what’s next? PUE is not and cannot be the end of the story. What do we need to define and describe next as PUE only gets us so far? Is it data centre or IT productivity? There have been many attempts to describe the “useful work” done by a data centre, but those that have tried know it is far from a simple problem. We’ve seen DCeP, CUPS, CADE, DPPE and others trying to do so but none have quite hit the mark.

We are right now at a turning point in our industry, following our last event we (Intellect and DCSG) have begun discussions with DECC (Department for Energy & Climate Change) on data centres as an industry establishing an industry wide Climate Change Agreement (CCA) as an alternative to being penalised within the Carbon Reduction Committment (CRC).

Establishing a CCA requires the industry to define and measure its productivity in some way so the metrics we agree and define to measure ourselves will make a significant difference to our future as a sector, certainly from a regulatory perspective within the UK initially and then further afield.

But what metric will be most useful for measuring the productivity your data centre? Or are we all on the wrong path? What’s the best way of demonstrating to your manager\CIO\board that your data centres are as efficient as they can be and delivering value for your business?

Come along to the latest DCSG Event to listen to the options from the industry’s leading figures on what they this is the best way to proceed. The evening will be split into two parts with the second half of the evening giving way to a panel discussion and debate. As is the norm with DCSG events, the audience normally have just as much (if not more!) to say than the panelists!

Always interesting, insightful and surprisingly entertaining this is a DCSG Event you shouldn’t miss!

This Event will be run in association with the Green Grid EMEA.

via Data Centre Specialist Group – Measuring Up? Metrics and your data centre.

Feb 18

Take the Disaster Out of Disaster Recovery

Easily manage and implement your recovery plan with VMware vCenter Site Recovery Manager.

Watch our new VMware vCenter Site Recovery Manager video

Build, Manage and Execute ReliableDisaster Recovery Plans

As an integrated element of VMware vSphere, VMware vCenter Site Recovery Manager helps you:

Accelerate recovery for the virtual environment through automationEnsure reliable recovery by enabling non-disruptive testing

Simplify recovery by eliminating complex manual recovery steps and centralizing management of recovery plans

Accelerate RecoveryEnsure that you are able to meet your recovery time objectives RTOs by automating the recovery process.

VMware vCenter Site Recovery Manager eliminates the slow manual steps of recovery, turning the complex paper runbooks associated with traditional disaster recovery into an integrated part of your virtual infrastructure management.

Ensure Reliable RecoveryEliminate common causes of failure during recovery and make it possible to test your recovery plans thoroughly and easily.By automating recovery, VMware vCenter Site Recovery Manager eliminates error-prone manual steps in the recovery process and ensures that recovery procedures will be consistently executed as intended.

VMware vCenter Site Recovery Manager also makes it easy to execute non-disruptive tests of recovery plans within an isolated testing environment so that you can ensure that they are up to date and will execute successfully. Simplify Disaster RecoverySimplify and centralize the process of creating, updating and managing recovery plans.

VMware vCenter Site Recovery Manager guides users through the process of building, managing and executing disaster recovery plans.  It integrates seamlessly with VMware Infrastructure and VMware vCenter Server to make recovery plans significantly easier to manage and update. It also integrates easily with storage replication software from leading storage vendors to simplify the use of advanced replication software with VMware vSphere.

via VMware vCenter Site Recovery Manager -- Data Disaster Recovery for Servers.

Feb 08

This is not your grandfather’s winter games. Every Olympic city makes major investments in technology, security and infrastructure in the 21st Century, and the Vancouver Winter Games are no exception.  The Olympic Cauldron will be lit on February 12, 2010. And yet, the hard work began immediately after Canada was selected to host the 2010 Winter Olympics back in 2004.

Want some examples?

1)      Technology companies are certainly talking about their unique role in these Games.  Green technology is a central element. Check out this Canadian website on technology related to the Olympics.

2)      Stopping terrorism is essential. One article back in 2005 estimated that the security budget would be about $177 million with a 50-50 split between the federal and provincial governments, but USA Today called actual security spending to be closer to $1 billionMore than 1000 security cameras are in place for the Winter Olympics.

3)      Infrastructure development has been important. There are plenty of stories online about the people behind the scenes who make the Olympic Games happen. There are also stories about the technology being used. If you look hard enough, you’ll find just about every big IT company is involved in some way. One example is Sun, but AT&T and others are right there as well.

4)      The economic development aspects and wider role of the Olympics can be seen in YouTube videos like this one.

5)      The role of the city mayors and Vancouver Government overall has been a huge part of this story.

Bottom line, this is big business. Just like the involvement of the South African Government in preparing for the 2010 World Cup in June, the Vancouver Olympic Games required an incredible investment in everything that we do in government technology every day. The difference is the scale, and the number of people watching.

So when you watch that beautiful opening or closing ceremony, when the US Hockey Team is skating to victory or those international downhill skiers fly past your TV screen, remember the technology and security infrastructure that made it all possible.

Let the games begin…

Feb 08

If you own a bank account or use credit cards, chances are you’ve heard the term “PCI compliant.” But you probably don’t know what it means.

The term is heard more and more frequently these days as data breaches at merchants like TJX, parent of TJMaxx, and payment processors Heartland Payment Systems and RBS WorldPay land millions of card records in the hands of hackers. Criminals are using the data to make purchases and withdraw money from accounts of unsuspecting victims who did nothing wrong; they just owned a card.

It’s a huge and growing problem. More than 80 percent of data stolen in breaches is payment card data, according to the 2009 Verizon Business Data Breach Report.

CNET asked Bob Russo, general manager of the PCI Security Standards Council, to explain what is being done to keep criminals from accessing consumer payment card data.

Q: So, what does the PCI Security Standards Council do?

Russo: The council was formed in September 2006 by the five major credit card brands, Visa, MasterCard, American Express, Discover, and JCB [Japanese Credit Bureau]. It was formed because each one of the brands has their own compliance programs and they still do, but they all use this standard as the foundation for their programs. There was a time when you could pick up the phone, call one brand, ask a security question, get one answer, call another brand, ask the same question, and get a different answer. They all now use the standards that we manage as the foundation for those compliance questions.

What is the standard exactly?

Russo: It’s the PCI, which stands for Payment Card Industry, data security standard. It’s a set of 12 requirements that cover six goals. It’s very prescriptive. It says not only that you need to be secure but also it tells you how to become secure. It’s more about security than compliance. The goals are things like building and maintaining a secure network, protecting cardholder data and regularly monitoring and testing the networks. That’s the main standard. We manage three different standards. The first one covers everything from the physical security to logical security.

The second standard is PADSS, Payment Application Data Security Standard. These are for payment applications a merchant would buy off the shelf. For example, if you went to a restaurant and you ordered your meal and the waiter used a touch-screen terminal, that puts the order in the kitchen and it’s tied to an ordering database. The application also takes the credit card at the end of the meal. We make sure these applications aren’t storing prohibitive data, such as data on the magnetic strip on the card. If they stored that data and someone got a hold of it then they would be able to clone credit cards. There are literally thousands of applications out there and when it’s compliant with the standard it is listed on our Web site.

“We have seen no evidence that if someone were compliant that they would have been breached. The standard is working. You only read about the one, two, or four big breaches that happen. You don’t hear about the thousands of merchants who aren’t getting breached because they are compliant.”

–Bob Russo, general manager, PCI Security Standards Council

The last piece we manage is called PTS, PIN Transaction System. Anytime you enter a PIN number, for example, this standard would take effect. It looks at those PIN entry devices so when you go to a large department store and you buy something and you use a debit card they’ll hand you a PIN pad and you key in your number. We certify those devices as well as unattended payment terminals, such as those used at gas station [islands], ticket kiosks, and transit systems, like the Boston underground.

via PCI compliance: What it is and why it matters (Q&A) | InSecurity Complex – CNET News.

Jan 31

HAMPSHIRE, UK: 26th January 2010 — New research has found that annual revenues from cloud-based mobile applications will reach nearly $9.5 billion by 2014, fueled by the need for converged, collaborative services, the widespread adoption of mobile broadband services and the deployment of key technological enablers such as HTML5 and the Open Mobile Alliance’s Smart Card Web Server (SCWS).

The Juniper Research report found that enterprise applications will account for the majority of revenues over the next five years, with businesses increasingly seeking to capitalise on the ability of Platform as a Service (PaaS) providers to offer scalable, flexible data storage solutions allied to device agnostic, synchronised office services.

However, consumer-oriented apps will comprise an ever-larger proportion of total revenues, derived both from time-based subscriptions to services such as mobile online gaming and advertising from cloud-based social networks.

However, the mobile cloud applications & services report warned that many enterprise customers still remained wary of entrusting their personal data to remote third-parties, and that recent high-profile data losses amongst corporate mobile users in the USA would only exacerbate these concerns. According to report author Dr Windsor Holden, “Not only is it imperative for cloud providers to ensure that access to and storage of customer data is secure, but that the procedures that they put in place in this regard – including data backup strategies – are transparent to the customer.”

Other findings from the Juniper report include:

• While the onset of a cloud-based ecosystem may further erode the strength of the mobile operator/customer relationship, cloud offers operators the opportunity to develop new revenues streams as Infrastructure as a Service (IaaS) and PaaS providers

• Lack of network capacity may continue to be a constraint on the growth of network-based services even after LTE and WiMAX networks are deployed

Juniper Research assesses the current and future status of mobile cloud based on interviews, case studies and analysis from representatives of some of the leading organisations in this bleeding edge industry.

via Press Release: Mobile Cloud Application Revenues To Hit $9.5 billion by 2014, Driven by Converged Mobile Services, according to Juniper Research.

Jan 29

The book addresses disaster planning for small businesses in three stages: prepare, recover and respond.

The section on how to prepare for a disaster is the most detailed, and contains generic as well as practical suggestions.

The author provides logical common sense guidelines for the realities of how to prepare for, respond to and recover from problems, and this has a thoroughness brought about by experience.

The examples of specific problems encountered, which are provided throughout, help to keep the focus on why being prepared is important for the small business.

Specific suggestions whilst preparing are to not plan for the worst case only, as this causes planning paralysis and might result in the assumption that if it is not possible to plan for everything don’t bother to do anything at all. Also, the recommendation to prepare in a step-by-step fashion, prioritising what is important to your business, is key.

Part two covers the immediate response to a disaster, and the flexible implementation of the disaster planning. The final section addresses business recovery to the pre-disaster state.

Overall, the common sense suggestions are useful, but the detailed instructions on who to contact, how to register, and so on, are too USA-specific for a UK audience. I estimate the book is probably 75 per cent applicable outside the USA.

via Prepare for the Worst, Plan for the Best: Disaster Preparedness and Recovery for Small Businesses, 2nd Edition | Archive | Book Reviews | Opinion, News, Analysis | BCS – The Chartered Institute for IT.

Jan 24

We’ve come so very far in the way computer operating systems treat us, and in the way we treat those computer operating systems. They multitask, they animate, they reach into the internet and pull down our favorite parts, they rarely crash and they’re always on. It’s a far cry from a decade ago, but I think we could go so much further. The advent of the cheap, ubiquitous touchscreen, always-available internet and continually cheaper and more powerful hardware has revolutionized the phone industry, and I think it can also help the desktops and laptops we know and love do more for us. But a laptop isn’t a phone: we’re supposed to get a lot done on it, under some unrealistic deadlines, and some random company with big ideas can’t come along and reinvent the desktop OS in one fell swoop — that simply isn’t practical when we have things to do.

So what’s an OS to do? I think there are serious opportunities for evolution available to the Microsofts, Apples and Ubuntus of the world, but they involve embracing new technologies in new ways. And stealing a ton of ideas from phones. A finger on a screen is not a mouse on a pad, an internet browser is not the end-all be-all of the internet, and playing Crysis in a quad HD resolution at 60 fps is not the ultimate expression of gaming for 95% of the population.

Join me as I explore a few bits of legacy cruft that need to be addressed before the desktop OS can become as important to this decade as it was to the last one.

via Editorial: 10 outdated elements of desktop operating systems — Engadget.

Jan 23

Advised by Sir Tim Berners-Lee and Professor Nigel Shadbolt and others, government are opening up data for reuse. This site seeks to give a way into the wealth of government data and is under constant development. We want to work with you to make it better.We’re very aware that there are more people like you outside of government who have the skills and abilities to make wonderful things out of public data. These are our first steps in building a collaborative relationship with you.

via Unlocking innovation | data.gov.uk.

Jan 17

The German government has warned web users to find an alternative browser to Internet Explorer to protect security.

The warning from the Federal Office for Information Security comes after Microsoft admitted IE was the weak link in recent attacks on Google's systems.

Microsoft rejected the warning, saying that the risk to users was low and that the browsers' increased security setting would prevent any serious risk.

However, German authorities say that even this would not make IE fully safe.

Thomas Baumgaertner, a spokesman for Microsoft in Germany, said that while they were aware of the warning, they did not agree with it, saying that the attacks on Google were by “highly motivated people with a very specific agenda”.

via BBC News – German government warns against using MS Explorer.

preload preload preload