<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: directions]]></title>
    <link>http://securityratty.com/tag/directions</link>
    <description></description>
    <pubDate>Tue, 27 May 2008 08:03:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[National Security Perspectives A Post-Election Insider View]]></title>
      <link>http://securityratty.com/article/caa8257ee971993e58e1b834379f8c71</link>
      <guid>http://securityratty.com/article/caa8257ee971993e58e1b834379f8c71</guid>
      <description><![CDATA[Recently I participated in an event entitled National Security Perspectives held at the famous Congressional Country Club in Maryland . The featured panelists had impressive credentials from the NSA ,...]]></description>
      <content:encoded><![CDATA[<p>Recently I participated in an event entitled National Security Perspectives held at the famous <a href="http://www.ccclub.org/" target="_blank">Congressional Country Club in Maryland</a>. The featured panelists had impressive credentials from the <a href="http://www.nsa.gov/" target="_blank">NSA</a>, <a href="http://www.dhs.gov/" target="_blank">DHS</a> and the <a href="https://www.cia.gov/" target="_blank">CIA</a>. The topics of discussion ranged from Current Geopolitical Threats and Evolving Technology Demands to predictions about the New Administrations Intelligence, Defense and Homeland Security focus.</p>
<p>The panelists were:<br />
<a href="http://en.wikipedia.org/wiki/National_Security_Agency" target="_blank">William P. Crowell</a> – former Deputy Director of the National Security Agency<br />
<a href="http://www.whitehouse.gov/government/m_jackson-bio.html" target="_blank">Michael P. Jackson</a> – Deputy Secretary, Department of Homeland Security<br />
<a href="http://en.wikipedia.org/wiki/Jose_Rodriguez_(intelligence)" target="_blank">Jose A. Rodriguez, Jr</a>. – former Director CIA, National Clandestine Service &amp; CIA, DCI Counterterrorist Center</p>
<p>Overall, it was a very nicely arranged event on a brisk fall evening with about 100 CXO attendees; mostly large but some small government contractors and a few product companies like ScienceLogic that conduct business with military, intelligence and the public sector.</p>
<p>No surprise, given the financial crisis the economy is suffering from that the panelists said we also have a <a href="http://obsidianwings.blogs.com/obsidian_wings/2008/11/defictits-actua.html" target="_blank">crisis coming on the Federal budget front</a>. This will put enormous pressure on the way Administration thinks, and how and where to spend the $$.</p>
<p>Obama’s tone regarding the issues he will be confronting in the world during the election was encouraging. Make the world more non-partisan and take on the threats that we have in front of us head-on!</p>
<p>The panel was very upfront about current threats. William Crowell said,</p>
<blockquote><p>“It is highly imprudent to believe that there will not be another 9-11. We have to fund and support the work to stop other attacks. We can only mitigate risk but we can’t eliminate risk. We have to try to absorb the sense of urgency and wake up every day looking at the intelligence screens as if 9-11 happened within the last couple of months.”</p></blockquote>
<p>He added,</p>
<blockquote><p>“They (the intelligence community) need the innovation, sense of commitment and urgency that comes from the private sector – a sense of mutual commitment to that mission.”</p></blockquote>
<p>Predicted Priorities for investment for DHS:</p>
<ol>
<li>Cyber attack as the top issue</li>
<li>Nuclear threats including dirty bomb</li>
<li>Chemical and biological attacks</li>
<li>Explosive attacks against critical infrastructure with maximum # of lives and or financial disruption / loss.</li>
<li>Large scale natural disasters – hurricane + earthquakes</li>
<li>Border penetration - identity management and border management issues</li>
</ol>
<p>An <a href="http://www.barackobama.com/index.php" target="_blank">Obama administration</a> will spend dollars around these threat vectors. They will want to spend $$ to help state and local governments. Grants to state and local governments should significantly increase with the Obama administration, so think about how you will increase your focus on the state and local government spending initiatives.</p>
<p><a href="http://lawprofessors.typepad.com/immigration/2008/11/pressure-on-oba.html" target="_blank">Secure border investments</a> – the panelists believe that the new administration will feel compelled to invest here. Michael P. Jackson bluntly said, “You have to make investments in border tools to get meaningful immigration reform.”</p>
<p>Panelists agreed that the 1<sup>st</sup> year will be an intense period of scrutiny about fundamental directions. We can’t afford it all at DHS; it is dramatically under budgeted. At TSA/DOT and then at DHS, we spent about $4 Billion on technology investments since 9-11; those investments are now reaching the end of the original service life.</p>
<p>One gripe from the panel that I found humorous: “We don’t have a group of people who think like entrepreneurs.” It is insane how long things last when you buy things in the government. As an example, we are still replacing vacuum tubes in some of the very old FAA gear… this is well beyond what any reasonable person would think these initial investments should/would last.</p>
<p>Final Thoughts:<br />
I actually think that the Obama Administration will be quite favorable to COTS software products, SaaS offerings, and creative financing initiatives from the private sector. The government just won’t have the capital budget to do everything it wants to accomplish. I would say if you look at how intelligently and aggressively <a href="http://www.concurringopinions.com/archives/2008/11/obama_and_techn.html" target="_blank">Obama used technology</a> to assist his campaign, the odds are good that this new breed of IT talent (which is already really comfortable with SaaS products, blogs, wiki’s, hosted/outsourced Cloud solutions… this team really understands the latest technology trends) will quickly work to bring these new IT paradigms to the Federal marketplace. Clearly the private sector can help the Government achieve more with lower capital budgets – beginning to provide services rather than transaction-based selling. Another clear idea is to think about leasing as a better way to work with the government which going forward will have increased budgets restrictions.</p>
<p>They will likely be in confrontation with members of Congress that won’t change fast enough, however the future of our nation’s ability to fight terror lies in becoming more efficient and effective. It requires the government be flexible enough to figure out what <a href="http://blogs.techrepublic.com.com/hiner/?p=880" target="_blank">jobs and IT functions to outsource</a> in a nimble and smart way. My prediction: this is great news for Service Providers. Overall the next 4 years should be great for our business as well as the Managed Service Provider/SaaS industry!</p>
<p><em><span style="color: #333333;"> </span></em></p>
]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 11:13:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/secure border investments">secure border investments</category>
      <category domain="http://securityratty.com/tag/investments">investments</category>
      <category domain="http://securityratty.com/tag/government contractors">government contractors</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/threats">threats</category>
      <category domain="http://securityratty.com/tag/government achieve">government achieve</category>
      <category domain="http://securityratty.com/tag/initial investments shouldwould">initial investments shouldwould</category>
      <category domain="http://securityratty.com/tag/obama administration">obama administration</category>
      <category domain="http://securityratty.com/tag/current threats">current threats</category>
      <source url="http://blog.sciencelogic.com/national-security-perspectives-a-post-election-insider-view/11/2008">National Security Perspectives A Post-Election Insider View</source>
    </item>
    <item>
      <title><![CDATA[Whit Diffie on Encryption and PKI]]></title>
      <link>http://securityratty.com/article/9bbc634ff8c02a25e17a3372b0a6a286</link>
      <guid>http://securityratty.com/article/9bbc634ff8c02a25e17a3372b0a6a286</guid>
      <description><![CDATA[In the 1970s, Whitfield Diffie co-wrote the recipe for one of today's most widely used security algorithms in a paper called &quot;New Directions in Cryptography.&quot; The paper was a blueprint of what came to...]]></description>
      <content:encoded><![CDATA[In the 1970s, Whitfield Diffie co-wrote the recipe for one of today's most widely used security algorithms in a paper called "New Directions in Cryptography." The paper was a blueprint of what came to be known the Diffie-Hellman key exchange, a seismic advancement in Public Key Infrastructure (PKI) technology that makes secure online transactions possible. It's part of such popular protocols as the Secure Sockets Layer (SSL) and Secure Shell (SSH).<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=12011?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=12011?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 09 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/diffie-hellman key exchange">diffie-hellman key exchange</category>
      <category domain="http://securityratty.com/tag/secure sockets layer">secure sockets layer</category>
      <category domain="http://securityratty.com/tag/public key infrastructure">public key infrastructure</category>
      <category domain="http://securityratty.com/tag/secure online transactions">secure online transactions</category>
      <category domain="http://securityratty.com/tag/whitfield diffie co-wrote">whitfield diffie co-wrote</category>
      <category domain="http://securityratty.com/tag/popular protocols">popular protocols</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <category domain="http://securityratty.com/tag/pki">pki</category>
      <category domain="http://securityratty.com/tag/seismic advancement">seismic advancement</category>
      <source url="http://www.networkworld.com/news/2008/111008-whit-diffie-on-encryption-and.html?fsrc=rss-security">Whit Diffie on Encryption and PKI</source>
    </item>
    <item>
      <title><![CDATA[Sniffers class for the ISSA Kentuckiana]]></title>
      <link>http://securityratty.com/article/8ea74add13ca2d1aebf8eb66f54d28e6</link>
      <guid>http://securityratty.com/article/8ea74add13ca2d1aebf8eb66f54d28e6</guid>
      <description><![CDATA[I'm teaching another free class for the ISSA, hope some of my readers can make it. Here are the details: Who : Presented by Adrian Crenshaw of IronGeek.com What : &quot;Using Sniffers Effectively&quot; -...]]></description>
      <content:encoded><![CDATA[I'm teaching another free class for the ISSA, hope some of my readers can make it. Here are the details:<br/><B>Who</B>: Presented by Adrian Crenshaw of IronGeek.com<br/><B>What</B>: "Using Sniffers Effectively" - hands-on workshop with network analyzers such as Wireshark and Cain.<br/><B>When</B>: Sat, November 8, 2008 9:00 AM - 12:30 PM<br/><B>Where</B>: Louisville Technical Institute - Room 364, 3901 Atkinson Square Drive, Louisville KY 402018 (502) 456-6509<br/><B>Directions</B>: From 264 East get off on 1st Newburg Rd exit, Turn RIGHT at Bishop Lane, Turn RIGHT at Atkinson Dr./Atkinson Square Dr., Go .2 miles, Turn right at LOUISVILLE TECHNICAL/INTERIOR DESIGN INSTITUTE. Park in front parking lot. Go in Main Lobby to sign in.<br/><B>Why</B>: ISSA Kentuckiana's mission is to be the Louisville Leader in Information Security and Awareness. We want to provide relevant educational opportunities to members that enable learning, career growth, and should enable certification and technical advancement. <br/><B>Cost</B>: FREE! - Bring your own laptop or use one of the classroom PC's<br/><B>How to sign up</B>: send email to education (at) issa-kentuckiana (dot) org
<p><a href="http://feedads.googleadservices.com/~a/NzgSH-IM3cBWm_VnvqM5mNuYrR4/a"><img src="http://feedads.googleadservices.com/~a/NzgSH-IM3cBWm_VnvqM5mNuYrR4/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/qKS-TigPx0o" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 20:20:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/atkinson square drive">atkinson square drive</category>
      <category domain="http://securityratty.com/tag/atkinson square">atkinson square</category>
      <category domain="http://securityratty.com/tag/louisville">louisville</category>
      <category domain="http://securityratty.com/tag/louisville technical institute">louisville technical institute</category>
      <category domain="http://securityratty.com/tag/issa">issa</category>
      <category domain="http://securityratty.com/tag/atkinson">atkinson</category>
      <category domain="http://securityratty.com/tag/issa kentuckiana">issa kentuckiana</category>
      <category domain="http://securityratty.com/tag/louisville leader">louisville leader</category>
      <category domain="http://securityratty.com/tag/free class">free class</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/qKS-TigPx0o/">Sniffers class for the ISSA Kentuckiana</source>
    </item>
    <item>
      <title><![CDATA[A Wild Tangent]]></title>
      <link>http://securityratty.com/article/1fb899c4ea43a76a35b277f5db58f34b</link>
      <guid>http://securityratty.com/article/1fb899c4ea43a76a35b277f5db58f34b</guid>
      <description><![CDATA[As I sit at Dulles Airport outside DC, waiting for yet another delayed flight, I feel compelled to write a post about traveling as part of the cost of doing business. This morning I had a flight...]]></description>
      <content:encoded><![CDATA[<p>As I sit at Dulles Airport outside DC, waiting for yet another delayed flight, I feel compelled to write a post about traveling as part of the cost of doing business.  This morning I had a flight scheduled that was supposed to leave at 6:45am.  During dinner last night I got an e-mail from United stating that the flight would instead be leaving at 7:30a.  As I arrived at the airport this morning I received another e-mail saying it would instead leave at 8:15a.  Since then the flight time has been announced as 7:45, 7:10 and now 7:16.  Is there anyone left out there that wonders why the airlines are always struggling?  Who really wants to put themselves through the <a href="http://www.usatoday.com/money/industries/travel/2008-05-29-fly-delays-hassles_N.htm" target="_blank">torture of travel</a>?  I look forward to the day that we all have a <a href="http://www.cisco.com/en/US/netsol/ns669/networking_solutions_solution_segment_home.html" target="_blank">Cisco Telepresence</a> type set-up at our offices and even &#8220;face-to-face&#8221; meetings can be virtual.</p>
<p>What&#8217;s really set me off this morning is the back and forth on the flight time.  I know that there are many things that can cause a flight delay, but to move the departure time, in both directions, four times within one hour, how is that possible?  I can only imagine the reaction of ScienceLogic customers if we announced the release date for the next version of the product and then proceeded to change it four times that week.  There really isn&#8217;t another business in the world, other than the airlines, that could get away with this.</p>
<p>Assuming I eventually get to <a href="http://www.interop.com/" target="_blank">Interop NY</a>, I will be on the look out for vendors that are working on ways to send me to my next meeting over Gigabit Ethernet!</p>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 16:39:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flight">flight</category>
      <category domain="http://securityratty.com/tag/flight time">flight time</category>
      <category domain="http://securityratty.com/tag/flight delay">flight delay</category>
      <category domain="http://securityratty.com/tag/dulles airport">dulles airport</category>
      <category domain="http://securityratty.com/tag/airport">airport</category>
      <category domain="http://securityratty.com/tag/sciencelogic customers">sciencelogic customers</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/departure time">departure time</category>
      <category domain="http://securityratty.com/tag/e-mail">e-mail</category>
      <source url="http://blog.sciencelogic.com/a-wild-tangent/09/2008">A Wild Tangent</source>
    </item>
    <item>
      <title><![CDATA[Customers Being Heard Dell OEM Customer Advisory Council]]></title>
      <link>http://securityratty.com/article/b5bf6c31cfb46c51caf3436e68450bcd</link>
      <guid>http://securityratty.com/article/b5bf6c31cfb46c51caf3436e68450bcd</guid>
      <description><![CDATA[It was a surprise and a great honor when Dell asked us to participate on their Industry Solutions Group (ISG) OEM Customer Advisory Council even more so when I met some of the other members from...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 10px 10px 0px; border-right-width: 0px" height="234" alt="dell" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/dell.jpg" width="240" align="left" border="0"> It was a surprise and a great honor when Dell asked us to participate on their <a href="http://www.dell.com/content/topics/global.aspx/sitelets/solutions/industry_application/oem_solutions/oem_industry_solutions_group?c=us&amp;cs=555&amp;l=en&amp;s=biz&amp;redirect=1" target="_blank">Industry Solutions Group (ISG) OEM Customer Advisory Council</a> – even more so when I met some of the other members from companies like Google, Teradata, Siemens Medical and Cisco. Not so shabby.</p>
<p>I arrived in Austin Sunday night to get ready for a factory tour on Monday, a kickoff dinner and then two days of briefings from Dell executives, including Michael Dell himself! Dell’s ISG business is growing at a very fast pace and continues to build momentum and focus within the broader organization.</p>
<p>We had a nice <a href="http://www.lockergnome.com/blade/2008/08/02/microsoft-has-oems-adding-defender-one-care-to-pcs/" target="_blank">overview of the product roadmap</a>, including some of the exciting enhancements Dell is making to their <a href="http://gigaom.com/2008/09/04/pc-makers-give-storage-startups-a-boost/" target="_blank">storage products</a> <a href="http://blogs.smugmug.com/don/2007/10/01/dell-md3000-great-das-db-storage/" target="_blank">such as the MD3000</a> and the new <a href="http://jpowell.blogs.com/jason_powell_church_it/2008/04/equallogic-app.html" target="_blank">EqualLogic PS5000 series iSCSI</a> solutions.</p>
<p>I really enjoyed the Council meeting and it reminds me all over again; what I admire about Dell is the way they and Michael Dell himself stay close to the customer. The entire purpose of this event is to “get it right” and determine meaningful ways to embrace change (including change in the manufacturing process) in order to make their customers more successful. Ah shucks, you may say that all companies behave this way… well I must tell you that is not true and at times, I find it difficult as we continue to grow to stay as close as I would like to all of our customers varying needs and directions.</p>
<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="228" alt="Ideastorm" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/ideastorm1.jpg" width="456" border="0"> </p>
<p>This concept of <a href="http://www.briansolis.com/2008/07/comcast-cares-and-why-your-business.html" target="_blank">gathering, internalizing and embracing customer feedback is a simple principle</a> of Business Success stories. <a href="http://www.beingpeterkim.com/2008/09/ive-been-thinki.html" target="_blank">Always trying to improve</a> the pace of change and build meaningful sticky relationships with customers. Dell’s very successful <a href="http://www.dellideastorm.com/" target="_blank">Ideastorm</a> site where customers post <a href="http://www.pronetadvertising.com/articles/how-richard-binhammer-is-changing-the-face-of-dell-online34379.html" target="_blank">product feedback and are active participants</a> in the Dell community is a <a href="http://www.bloggingstocks.com/2008/07/07/how-dell-can-leap-ahead-in-consumer-laptop-sales/" target="_blank">great example of how to do this right</a>. No other hardware vendor that we have worked with or attempted to work with has ever gone to the extent of embracing change that Dell has during our 5-year relationship.</p>
<p>From the custom factory integration services to the attention to detail in the order and manufacturing, and logistics processes, Dell helps us execute for our customers and I must admit that we could not have built the business as quickly or efficiently without Dell!</p>
<p>So thank you Michael Dell for building a business that embraces change and is focused on helping your ISG customers succeed.</p>
]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 11:54:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dell">dell</category>
      <category domain="http://securityratty.com/tag/michael dell">michael dell</category>
      <category domain="http://securityratty.com/tag/dells isg business">dells isg business</category>
      <category domain="http://securityratty.com/tag/isg">isg</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/dell community">dell community</category>
      <category domain="http://securityratty.com/tag/dell helps">dell helps</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/dell executives">dell executives</category>
      <source url="http://blog.sciencelogic.com/customers-being-heard-dell-oem-customer-advisory-council/09/2008">Customers Being Heard Dell OEM Customer Advisory Council</source>
    </item>
    <item>
      <title><![CDATA[Monitoring P2P Networks]]></title>
      <link>http://securityratty.com/article/e2525ed966d30506e3fee3375e62db16</link>
      <guid>http://securityratty.com/article/e2525ed966d30506e3fee3375e62db16</guid>
      <description><![CDATA[Interesting paper: &quot; Challenges and Directions for Monitoring P2P File Sharing Networks or Why My Printer Received a DMCA Takedown Notice &quot;: Abstract -- We reverse engineer copyright enforcement in...]]></description>
      <content:encoded><![CDATA[<p>Interesting paper: "<a href="http://dmca.cs.washington.edu/dmca_hotsec08.pdf">Challenges and Directions for Monitoring P2P File Sharing Networks or Why My Printer Received a DMCA Takedown Notice</a>":</p>

<blockquote>Abstract -- We reverse engineer copyright enforcement in the popular BitTorrent file sharing network and find that a common approach for identifying infringing users is not conclusive. We describe simple techniques for implicating arbitrary network endpoints in illegal content sharing and demonstrate the effectiveness of these techniques experimentally, attracting real DMCA complaints for nonsense devices, e.g., IP printers and a wireless access point. We then step back and evaluate the challenges and possible future directions for pervasive monitoring in P2P file sharing networks.</blockquote>

<p><a href="http://dmca.cs.washington.edu/">Webpage</a> on the research.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=puuvpK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=puuvpK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=3GKIiK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=3GKIiK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 08:08:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/describe simple techniques">describe simple techniques</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/techniques">techniques</category>
      <category domain="http://securityratty.com/tag/p2p file">p2p file</category>
      <category domain="http://securityratty.com/tag/arbitrary network endpoints">arbitrary network endpoints</category>
      <category domain="http://securityratty.com/tag/dmca takedown notice">dmca takedown notice</category>
      <category domain="http://securityratty.com/tag/popular bittorrent file">popular bittorrent file</category>
      <category domain="http://securityratty.com/tag/real dmca complaints">real dmca complaints</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/monitoring_p2p.html">Monitoring P2P Networks</source>
    </item>
    <item>
      <title><![CDATA[Q&A with Doug McClure: Is BSM Lite the Answer?]]></title>
      <link>http://securityratty.com/article/183e734958786a07b2c4d4b988eb60cc</link>
      <guid>http://securityratty.com/article/183e734958786a07b2c4d4b988eb60cc</guid>
      <description><![CDATA[We had the opportunity to chat with Doug McClure , who is currently the Senior Managing Consultant for Business Service Management (BSM) and IT Service Management (ITSM) for the IBM Software Services...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 10px 10px 0px; border-right-width: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/07/dougmcclurefeb2008-web.jpg" border="0" alt="dougmcclureFeb2008-web" width="105" height="156" align="left" /> We had the opportunity to chat with <a href="http://dougmcclure.net/blog/" target="_blank">Doug McClure</a>, who is currently the Senior Managing Consultant for Business Service Management (BSM) and IT Service Management (ITSM) for the IBM Software Services for Tivoli (ISST) team at IBM Tivoli (part of Software Group (SWG)). He currently leads the Virtual BSM Practice within IBM Software Services for Tivoli.</p>
<p><em><strong>ScienceLogic:</strong></em> What is “BSM Lite” and how is it different from “heavy” BSM?</p>
<p><strong><em>Doug McClure:</em></strong> I think the concepts that <a href="http://netforecast.com/" target="_blank">Peter Sevcik from Net Forecast</a> initially <a href="http://www.networkworld.com/community/node/27818" target="_blank">outlined in his blog post</a> sum up what &#8220;BSM Lite&#8221; is all about: a simpler, less expensive, more responsive way of achieving the goals and objectives of Business Service Management (BSM).  He&#8217;s contrasted this nicely against what he termed &#8220;BSM Heavy&#8221; being the larger investments in time and resources to deploy domain specific tools and solutions each providing a view into the business service delivery with some aggregation and consolidation to tie up all of the disparate tool&#8217;s information into a concise end-to-end business service management story.</p>
<p>I&#8217;m pleased that he leveraged some of my thinking around a better working definition of what BSM really is from the <a href="http://dougmcclure.net/blog/business-service-management-bsm-defined/" target="_blank">BSM Defined page on my blog</a>. Of course, these definitions are going to vary depending on whom you talk with and how they see the overall BSM Maturity Model.  I&#8217;ve created a BSM Maturity Model that aligns with the famous Gartner IT maturity model.  I&#8217;d like to think that a &#8220;BSM Lite&#8221; solution is one attacking the low hanging fruit, enabling one to achieve value quicker, and in a more tactical manner.  The &#8220;BSM Heavy&#8221; solutions are capable of the same, but span all along the BSM Maturity Model by adding additional point solutions, products and technologies from their broader portfolio. </p>
<p><strong><em>ScienceLogic:</em></strong> Does “BSM Lite” just refer to the tools, or can it refer to the process and methodology as well?</p>
<p><strong><em>Doug McClure:</em></strong> I think that BSM is as much a philosophy as it is technology, process, people and methodology.  If we can get people to think, operate and respond differently than they do today with a focus on the business, customers, quality, revenue, or whatever else is most important to their business goals and objectives, than that is Business Service Management and could be &#8220;BSM Lite&#8221; if you will. </p>
<p>Being that I work for IBM Tivoli, one of my personal objectives is to identify ways to use our key BSM enabling products in a more efficient, effective and BSM centric way. This was a huge driver for trying to hold DevCampTivoli focused on &#8220;Collaborative Development of End-to-End BSM Solutions&#8221;. </p>
<p>In my opinion, we don’t make things very easy for our clients and the answer can’t be to “buy this product, module or widget” to fill in the gaps.  In my opinion, we must establish a BSM overlay within IBM Tivoli’s development and product management organization that ensures that we have clearly thought about how to enable BSM with the hundreds or products that we sell.  In my opinion, every product release must incorporate the fundamentals of enabling BSM in addition to the core domain specific functionality intended. I hope to keep this spirit alive and get our smartest IBMers and clients thinking about the best way to take a &#8220;BSM Heavy&#8221; solution and make it &#8220;lighter&#8221;. I hope to share more about my plans here and guidance for the industry in general soon.</p>
<p>That said, I am always interested in consulting with clients and collaborate with peers in the industry to figure out how to get the focus on the people, process and technology as key components of their BSM strategies.  I am absolutely convinced that without a documented BSM strategy, roadmap and top level sponsorship within the business and IT, the chances of BSM success greatly diminish.</p>
<p><strong><em>ScienceLogic:</em></strong> Given the complexities involved in implementing a BSM strategy and dealing with the people and processes components of any business, how does “BSM Lite” really work? Should the expectations and outcomes be “lite” as well?</p>
<p><strong><em>Doug McClure:</em></strong> Time will tell if &#8220;BSM Lite&#8221; will work.  I&#8217;m seeing emerging companies that are already breaking down some of the barriers to BSM success.  I do not expect that those choosing to begin with a &#8220;BSM Lite&#8221; approach should expect &#8220;lite&#8221; outcomes. </p>
<p>The outcomes are the same regardless of the approach IF you&#8217;ve got a documented BSM strategy, roadmap and top level sponsorship in place before you begin. New features, capabilities and technologies will be needed as the needs of the business change and companies mature in BSM and fundamental IT management. This will likely force companies to move in more &#8220;BSM Heavy&#8221; directions to fill those gaps. </p>
<p>In my opinion, this is the ideal scenario now as it gives &#8220;BSM Lite&#8221; vendors opportunities to grow their products and solutions. It also GREATLY improves the chances for success with a &#8220;BSM Heavy&#8221; solution because the organization would have already had matured enough to approach a &#8220;BSM Heavy&#8221; solution than if they hadn&#8217;t done a &#8220;BSM Lite&#8221; solution in the past.</p>
<p><strong><em>ScienceLogic:</em></strong> Is “BSM Lite” more appropriate for a small or midsized organization, or does it apply equally to large companies? Is there an ideal profile for a company that can successfully implement a BSM strategy? Is there a different profile for “BSM Lite”?</p>
<p><strong><em>Doug McClure:</em></strong> From an economic perspective, the concepts of &#8220;BSM Lite&#8221; are appropriate for all companies.  Remember, with &#8220;BSM Lite&#8221; we&#8217;re focused on identifying ways to make the goals and objectives of BSM easier to implement and in a more cost effective way.  Any company concerned about their IT cost overhead should care about this, especially when the risks of starting out with a &#8220;BSM Heavy&#8221; type deployment are much greater and the time to value generally much longer.</p>
<p>The &#8220;ideal&#8221; profile for any company is one where the BSM initiative begins by establishing top level buy in through creation of a formal BSM strategy for the company. This BSM strategy personalizes how the company defines what BSM is, what value the company expects from it, and how it will use BSM as a competitive differentiator for delivery of its business and IT services, products, etc.</p>
<p>The organizational &#8220;profile&#8221; I&#8217;ve seen most successful is when implementing a BSM strategy originates from within or actively includes a group that many companies have now that serves as a liaison or relationship management role between the various lines of business and IT. Sometimes this group is often seen as the gatekeeper to filter (and hinder) business driven requirements into the IT organization. In the ideal scenario, this group works very closely with the business and IT (usually staffed by business people and not IT people) to understand both the business side and IT side of complex business services and applications. </p>
<p>Apart from the traditional IT components, what this group can do is help IT really understand the business perspective.  Analysis of the impact on the business in business terms is only possible by collaborating with a group such as this.  True value oriented BSM becomes attainable when we get to this level of IT and business alignment, cooperation, collaboration and communication.</p>
<p>If BSM is an IT only initiative, this will likely result in an IT centric perspective severely lacking in the necessary business perspective.  In these cases where IT doesn&#8217;t invest their BSM efforts with the business as an equal partner, the implementation ultimately becomes a &#8220;CYA&#8221; tool for IT and not achieve the desired value oriented expected.</p>
<p>To some degree &#8220;BSM Lite&#8221; may have an entirely different profile. If we see the price points, complexity and time to value change significantly we may see these types of deployments originate exclusively within the Line of Business. The possibility may exist where large enterprises operating in a shared IT services or IT outsourcing type model that the Line of Business brings in a &#8220;BSM Lite&#8221; solution to gain the visibility, checks and balances needed to ensure that the LoB’s needs are being met from the internal/external provider. I&#8217;d envision that &#8220;BSM Lite&#8221; may even be capable of operating within a &#8220;SaaS&#8221; model or other managed service type offering where the price points are below the signing levels triggering broader IT involvement and review.</p>
<p><em>To Be Continued&#8230;</em></p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Q%26amp%3BA+with+Doug+McClure%3A+Is+BSM+Lite+the+Answer%3F&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fqa-with-doug-mcclure-is-bsm-lite-the-answer%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 20:02:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lite">lite</category>
      <category domain="http://securityratty.com/tag/bsm heavy">bsm heavy</category>
      <category domain="http://securityratty.com/tag/bsm heavy directions">bsm heavy directions</category>
      <category domain="http://securityratty.com/tag/bsm">bsm</category>
      <category domain="http://securityratty.com/tag/outcomes">outcomes</category>
      <category domain="http://securityratty.com/tag/expect lite outcomes">expect lite outcomes</category>
      <category domain="http://securityratty.com/tag/bsm lite approach">bsm lite approach</category>
      <category domain="http://securityratty.com/tag/approach">approach</category>
      <category domain="http://securityratty.com/tag/bsm heavy solution">bsm heavy solution</category>
      <source url="http://blog.sciencelogic.com/qa-with-doug-mcclure-is-bsm-lite-the-answer/07/2008">Q&amp;A with Doug McClure: Is BSM Lite the Answer?</source>
    </item>
    <item>
      <title><![CDATA[IT Operations Management Audience Polls at the Gartner Conference]]></title>
      <link>http://securityratty.com/article/ed3926a9edd61b10b292d826e31778ec</link>
      <guid>http://securityratty.com/article/ed3926a9edd61b10b292d826e31778ec</guid>
      <description><![CDATA[Greetings from the Gartner IT Infrastucture, Operations &amp; Management Summit 2008 in warm and humid Florida
A couple of notes from the first days keynote address IT Operations Management Scenarios:...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="130" alt="Gartner IOM" src="http://blog.sciencelogic.com/wp-content/uploads/2008/06/gartner-iom.jpg" width="231" align="left" border="0"> Greetings from the <a href="http://www.gartner.com/it/page.jsp?id=603107" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.gartner.com');" target="_blank">Gartner IT Infrastucture, Operations &amp; Management Summit 2008</a> – in warm and humid Florida!
<p>A couple of notes from the first day&#8217;s&nbsp; keynote address <strong>“IT Operations Management Scenarios: Trends, Directions and Market Landscape”</strong> by <a href="http://agendabuilder.gartner.com/str24/WebPages/SessionList.aspx?Speaker=56" onclick="javascript:pageTracker._trackPageview('/outbound/article/agendabuilder.gartner.com');" target="_blank">Donna Scott – VP and Distinguished Analyst at Gartner Research</a>.
<p><strong>Donna:</strong> Today customers are looking for 100% availability for their externally facing business systems. Five 9’s are no longer enough. They expect IT to deliver the right services at the right cost with the right service levels.
<p><strong>My aside:</strong> How many of you are like me? When I listen to analysts or read the research, part of me is always asking – how applicable is this to me now? How rooted is what they are saying in the practical day-to-day operations that our customers need help with now? Well, how short-sighted of me.
<p><strong>Donna: </strong>“Best-in-class organizations manage through the day-to-day turbulence of change but also keep an eye on the long-term nirvana of IT operations management.” And that creating a continuous optimization culture is necessary to improve over time – this needs to be baked into the corporate IT culture. Food for thought for all of us.
<p>Interesting quick polls of the audience – some results were surprising; some were funny; and some were validating.
<p><strong>I. What are the Top 3 pressures on IT Infrastructure and Operations Management:</strong>
<p>1) 24 x7 availability: 82%
<p>2) Business continuity and disaster recovery: 70%
<p>3) Cost reduction and/or cost management: 67%
<p><em>On a personal note – supporting/deploying SOA came in at the bottom of this poll. Enough said.</em>
<p><strong>II. What grade would you give the IT Infrastructure and Operations Management vendors?</strong>
<p>A 1%
<p>B 14%
<p>C 49%
<p>D 17%
<p>F 4%
<p><em>Last year – the average grade ended up being C- so the grade went up slightly this year.</em>
<p><strong>III. What IT Infrastructure and Operations Management vendor are you most confident in to help achieve “ERP for IT”?</strong><em> (Dave will cover this topic later this week.)</em>
<p>HP 20%
<p>IBM 16%
<p>BMC 16%
<p>CA 4% (lingering bad rep?)
<p>Microsoft 8%
<p>Oracle 4%
<p>EMC 4%
<p>Other 5%
<p>And the winner was “NONE OF THE ABOVE” with 23% of the responses. </p>
<p><a href="http://sharethis.com/item?&wp=2.5.1&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=IT+Operations+Management+%26ndash%3B+Audience+Polls+at+the+Gartner+Conference&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fit-operations-management-audience-polls-at-the-gartner-conference%2F06%2F2008" onclick="javascript:pageTracker._trackPageview('/outbound/article/sharethis.com');">ShareThis</a></p>]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 11:09:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/operations">operations</category>
      <category domain="http://securityratty.com/tag/operations management">operations management</category>
      <category domain="http://securityratty.com/tag/operations management vendors">operations management vendors</category>
      <category domain="http://securityratty.com/tag/operations management scenarios">operations management scenarios</category>
      <category domain="http://securityratty.com/tag/operations management vendor">operations management vendor</category>
      <category domain="http://securityratty.com/tag/gartner">gartner</category>
      <category domain="http://securityratty.com/tag/donna">donna</category>
      <category domain="http://securityratty.com/tag/practical day-to-day operations">practical day-to-day operations</category>
      <category domain="http://securityratty.com/tag/gartner research">gartner research</category>
      <source url="http://blog.sciencelogic.com/it-operations-management-audience-polls-at-the-gartner-conference/06/2008">IT Operations Management Audience Polls at the Gartner Conference</source>
    </item>
    <item>
      <title><![CDATA[Laptop safety questions]]></title>
      <link>http://securityratty.com/article/824e8b73d5a37c697c78421efa2b4557</link>
      <guid>http://securityratty.com/article/824e8b73d5a37c697c78421efa2b4557</guid>
      <description><![CDATA[Let me say thanks to the Women's Business Council of the Southwest for inviting me to teach them about laptop safety. The business backgrounds of the members ranged from huge company manager to sole...]]></description>
      <content:encoded><![CDATA[Let me say thanks to the Women's Business Council of the Southwest for inviting me to teach them about laptop safety. The business backgrounds of the members ranged from huge company manager to sole proprietor to corporate lawyer and everything in between. That's what made their questions so interesting, because they came from all directions.]]></content:encoded>
      <pubDate>Wed, 11 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/laptop safety">laptop safety</category>
      <category domain="http://securityratty.com/tag/huge company manager">huge company manager</category>
      <category domain="http://securityratty.com/tag/sole proprietor">sole proprietor</category>
      <category domain="http://securityratty.com/tag/business council">business council</category>
      <category domain="http://securityratty.com/tag/business backgrounds">business backgrounds</category>
      <category domain="http://securityratty.com/tag/questions">questions</category>
      <category domain="http://securityratty.com/tag/directions">directions</category>
      <category domain="http://securityratty.com/tag/lawyer">lawyer</category>
      <source url="http://www.networkworld.com/columnists/2008/060908gaskin.html?fsrc=rss-security">Laptop safety questions</source>
    </item>
    <item>
      <title><![CDATA[How Do You Know It's The 21st Century?]]></title>
      <link>http://securityratty.com/article/6130e7bf0649a1b875b108ed70713371</link>
      <guid>http://securityratty.com/article/6130e7bf0649a1b875b108ed70713371</guid>
      <description><![CDATA[That's how - you read the directions for use on the newest multi barrel 40mm automatic cannon and it says &quot; requires only DC power and an ethernet connection for operations

Full story here

About me:...]]></description>
      <content:encoded><![CDATA[That's how - you read the directions for use on the newest <span style="font-size: 10pt;"><span style="font-family: arial,helvetica,sans-serif;"><span>multi barrel 40mm automatic cannon and <a href="http://www.metalstorm.com/content/view/82/166/">it says</a> "</span></span></span><span style="font-size: 10pt;"><span style="font-family: arial,helvetica,sans-serif;"><span><span>requires only DC power <span style="font-style: italic;">and an ethernet connection for operations</span>.</span></span></span></span><span style="font-size: 10pt;"><span style="font-family: arial,helvetica,sans-serif;"><span>"<br /><br />Full story <a href="http://blog.wired.com/defense/2008/05/metal-storm-iro.html">here</a>.<br /></span></span></span><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Bjps1H"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Bjps1H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=5OtxLH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=5OtxLH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=4EarzH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=4EarzH" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/299346576" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 27 May 2008 08:03:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ethernet connection">ethernet connection</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/operations">operations</category>
      <category domain="http://securityratty.com/tag/directions">directions</category>
      <category domain="http://securityratty.com/tag/requires">requires</category>
      <category domain="http://securityratty.com/tag/power">power</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/299346576/how-do-you-know-its-21st-century.html">How Do You Know It's The 21st Century?</source>
    </item>
  </channel>
</rss>
