By Mark Brousseau
Despite the lousy economy, document imaging solutions continue to enjoy strong adoption among organizations of all sizes. No wonder: the technology is proven to deliver tremendous operations and business benefits, including lower processing costs, streamlined storage and retrieval, and better information tracking and reporting.
But even the strongest business case for document imaging can be undermined by crucial errors during system deployment, says Brett Rodgers (brodgers@ibml.com), manager, Solution Consulting, Americas, at ibml (www.ibml.com), a Birmingham, AL-based document imaging solutions provider.
If you want to keep your document imaging business case on track (and who doesn't?), Rodgers suggests avoiding the following 10 all-too-common foul-ups during system deployment:
1. Incorrect sizing of the necessary number of document scanners.
2. Not including all stakeholders (business and IT) in the requirements definition.
3. Buying technology without first conducting a proof of concept.
4. Making decisions on front-end and back-end software separately.
5. Not coordinating software and hardware vendors during system deployment.
6. Not using a phased implementation approach (biting off too much at once).
7. Letting "fear of change" take over.
8. Not thinking LEAN.
9. Not cutting the paper cord.
10. Not "sharing" -- as in utilizing shared services.
What was your biggest mistake when deploying document imaging?
Showing posts with label data management. Show all posts
Showing posts with label data management. Show all posts
Thursday, May 26, 2011
Tuesday, April 12, 2011
Going to school on workflow
By Mark Brousseau
Kansas State University (KSU) has increased productivity, raised efficiency and reallocated staff by deploying Perceptive Software’s ImageNow enterprise content platform in its admissions office. Rhiannon Englert of application manager and ImageNow client administrator, undergraduate admissions, shared the university’s story yesterday at Perceptive Software’s Inspire 2011 user conference in Las Vegas.
Founded in 1863 and located in Manhattan, Kansas, KSU offers more than 250 majors and programs and serves over 23,500 students. The university’s admissions office has about 50 ImageNow users, and holds about 30 seat licenses at a time.
The university processes about 20,000 applications and 20,000 transcripts per year.
Before deploying ImageNow in 2002, the university previously used a “very large and very loud filing-drawer system” for managing its admissions documents. “It was a very clunky system and took up a lot of space,” Englert said. “By deploying ImageNow, we were able to replace that system with three workstations.”
Until three years ago, KSU used its ImageNow solution primarily for electronic document storage. The school’s workflow was used largely for basic tasks and was centered on an in-house routing slip and back-end document scanning
In this paper-driven environment, the university would date-stamp incoming admissions documents and then send them to its document processing staff, who would perform data entry and make any necessary notations directly on the original documents. The documents then would go to an evaluator-level employee for more processing, and any action that needed to be taken. Once this step was complete, the documents would be scanned and electronically linked to a student ID number.
This process created some challenges, Englert said, starting with the labor involved in manual data entry. “We also were concerned about the location of documents during processing: the only person who knew the location of a document was the person who was processing it,” Englert explained. Similarly, there was no way to quantify the processing workload. “Employees would say, ‘We have a huge stack of transcripts to process,’ but they could didn’t know how many,” Englert said.
That all changed in 2009 when the university upgraded to version 6.3 of ImageNow.
As part of its upgrade to the new version of software, the university evaluated its business process, looking for ways to improve efficiency and eliminate the “vicious cycle” of paper-driven processes, Englert said. Not surprisingly, the university decided to implement a paperless workflow in its admissions office. As a result, incoming documents – including applications and supporting documents – are now scanned upon receipt and then enter electronic workflow queues based on the document type or business process. The electronic documents are then linked to a student identification number in KSU’s PeopleSoft system, processed and archived.
With such a big change in how work is managed, it’s not surprising that Englert’s team had some concerns early on, including: how information would be displayed on monitors; whether they could make electronic annotations on documents: the clarity of document images (for determining the authenticity of transcripts); and the impact on processing turnaround. Some employees also were anxious about the system’s workload monitoring tools, and that someone would be watching them.
The university tackled these issues head-on (i.e. providing all employees with two monitors for easy image viewing) and kept communication to staff flowing.
The benefits have been significant. As a result of moving to a paperless workflow, the university increased efficiency, improved turnaround times, and reallocated staff – all at a time when its budgets are extremely tight. The workload tracking has proven to be a powerful tool for supervisors, helping them better understand staff workloads and turnaround times, and prioritize work when necessary. Englert said it is also easier to locate documents with ImageNow’s search capabilities. .
“During high-volume times, documents are now available in ImageNow within hours or a few days as opposed to several days or weeks,” Englert commented.
Now, the university is looking for more ways to take its processes to the next level.
Kansas State University (KSU) has increased productivity, raised efficiency and reallocated staff by deploying Perceptive Software’s ImageNow enterprise content platform in its admissions office. Rhiannon Englert of application manager and ImageNow client administrator, undergraduate admissions, shared the university’s story yesterday at Perceptive Software’s Inspire 2011 user conference in Las Vegas.
Founded in 1863 and located in Manhattan, Kansas, KSU offers more than 250 majors and programs and serves over 23,500 students. The university’s admissions office has about 50 ImageNow users, and holds about 30 seat licenses at a time.
The university processes about 20,000 applications and 20,000 transcripts per year.
Before deploying ImageNow in 2002, the university previously used a “very large and very loud filing-drawer system” for managing its admissions documents. “It was a very clunky system and took up a lot of space,” Englert said. “By deploying ImageNow, we were able to replace that system with three workstations.”
Until three years ago, KSU used its ImageNow solution primarily for electronic document storage. The school’s workflow was used largely for basic tasks and was centered on an in-house routing slip and back-end document scanning
In this paper-driven environment, the university would date-stamp incoming admissions documents and then send them to its document processing staff, who would perform data entry and make any necessary notations directly on the original documents. The documents then would go to an evaluator-level employee for more processing, and any action that needed to be taken. Once this step was complete, the documents would be scanned and electronically linked to a student ID number.
This process created some challenges, Englert said, starting with the labor involved in manual data entry. “We also were concerned about the location of documents during processing: the only person who knew the location of a document was the person who was processing it,” Englert explained. Similarly, there was no way to quantify the processing workload. “Employees would say, ‘We have a huge stack of transcripts to process,’ but they could didn’t know how many,” Englert said.
That all changed in 2009 when the university upgraded to version 6.3 of ImageNow.
As part of its upgrade to the new version of software, the university evaluated its business process, looking for ways to improve efficiency and eliminate the “vicious cycle” of paper-driven processes, Englert said. Not surprisingly, the university decided to implement a paperless workflow in its admissions office. As a result, incoming documents – including applications and supporting documents – are now scanned upon receipt and then enter electronic workflow queues based on the document type or business process. The electronic documents are then linked to a student identification number in KSU’s PeopleSoft system, processed and archived.
With such a big change in how work is managed, it’s not surprising that Englert’s team had some concerns early on, including: how information would be displayed on monitors; whether they could make electronic annotations on documents: the clarity of document images (for determining the authenticity of transcripts); and the impact on processing turnaround. Some employees also were anxious about the system’s workload monitoring tools, and that someone would be watching them.
The university tackled these issues head-on (i.e. providing all employees with two monitors for easy image viewing) and kept communication to staff flowing.
The benefits have been significant. As a result of moving to a paperless workflow, the university increased efficiency, improved turnaround times, and reallocated staff – all at a time when its budgets are extremely tight. The workload tracking has proven to be a powerful tool for supervisors, helping them better understand staff workloads and turnaround times, and prioritize work when necessary. Englert said it is also easier to locate documents with ImageNow’s search capabilities. .
“During high-volume times, documents are now available in ImageNow within hours or a few days as opposed to several days or weeks,” Englert commented.
Now, the university is looking for more ways to take its processes to the next level.
Thursday, March 24, 2011
info360 wrap-up
Posted by Mark Brousseau
Some odds and ends from AIIM’s info360 event this week in Washington, D.C.:
… d.velop technologies announced the launch of its ecspand for SharePoint enterprise content management (ECM) solution in the United States. Over the past two years, d.velop also introduced ecspand in Europe, the Middle East and Africa. d.velop exhibited in the info360 Microsoft pavilion.
… Colligo Networks and GimmalSoft forged a partnership and will integrate Colligo’s email management software into GimmalSoft’s SharePoint-based records management solution. The partnership will fulfill the DoD 5015.2 design criteria in GimmalSoft’s solution. DoD 5015.2 is the U.S. Department of Defense’s design criteria standard for electronic records management solutions.
… Document collaboration provider Workshare said it was awarded Microsoft Certified Gold ISV Partner status in the Microsoft Partner Program. The Gold ISV certification requires the highest level of competence and expertise with Microsoft technologies. By achieving Gold competency, partners receive benefits such as increased customer visibility through branding and accessibility, as well as training and support. Workshare has been a Microsoft Gold partner since 2005.
… Laserfiche demonstrated its DOD 5015.2-certified records management solution for SharePoint 2010. Laserfiche claims that its SharePoint 2010 integration was the first to obtain DoD 5015.2 certification. With the joint certification, Laserfiche now works with SharePoint 2010 to provide a unified business collaboration platform with enterprise content management (ECM) functionality.
… Datawatch released an enhanced version of its enterprise report management, archive and distribution solution. Called Datawatch BDS V8, the software adds certification for Red Hat LINUX, several new security features, and report and document redaction and translation.
What did you see at AIIM’s info360?
Some odds and ends from AIIM’s info360 event this week in Washington, D.C.:
… d.velop technologies announced the launch of its ecspand for SharePoint enterprise content management (ECM) solution in the United States. Over the past two years, d.velop also introduced ecspand in Europe, the Middle East and Africa. d.velop exhibited in the info360 Microsoft pavilion.
… Colligo Networks and GimmalSoft forged a partnership and will integrate Colligo’s email management software into GimmalSoft’s SharePoint-based records management solution. The partnership will fulfill the DoD 5015.2 design criteria in GimmalSoft’s solution. DoD 5015.2 is the U.S. Department of Defense’s design criteria standard for electronic records management solutions.
… Document collaboration provider Workshare said it was awarded Microsoft Certified Gold ISV Partner status in the Microsoft Partner Program. The Gold ISV certification requires the highest level of competence and expertise with Microsoft technologies. By achieving Gold competency, partners receive benefits such as increased customer visibility through branding and accessibility, as well as training and support. Workshare has been a Microsoft Gold partner since 2005.
… Laserfiche demonstrated its DOD 5015.2-certified records management solution for SharePoint 2010. Laserfiche claims that its SharePoint 2010 integration was the first to obtain DoD 5015.2 certification. With the joint certification, Laserfiche now works with SharePoint 2010 to provide a unified business collaboration platform with enterprise content management (ECM) functionality.
… Datawatch released an enhanced version of its enterprise report management, archive and distribution solution. Called Datawatch BDS V8, the software adds certification for Red Hat LINUX, several new security features, and report and document redaction and translation.
What did you see at AIIM’s info360?
Labels:
AIIM,
data management,
document imaging,
ecm,
ICR,
LINUX,
Mark Brousseau,
OCR,
page scanning,
SharePoint,
TAWPI,
workflow
Government e-discovery trends
Posted by Mark Brousseau
The chief information officer increasingly is joining the chief council in setting e-Discovery strategy within government organizations. That's according to a survey by USIS, an Altegrity company, conducted among government leaders from the federal e-Discovery community.
Among the other findings of the survey:
• Information management, data collection, and producing discoverable results in a timely manner are major concerns.
• More than one-third of respondents said the preservation and collection stage of electronic data discovery (EDD) needs the most improvement.
• Organizations that place a strong emphasis on the EDD process and strategy tend to have better e-Discovery processes.
• Among respondents whose organizations do not place an emphasis on the EDD process, not a single one reported being satisfied with their e-Discovery process.
“This survey reinforces how important it is to have good information management practices in place for the e-Discovery program and the burden it can place on a team when those practices simply aren’t there,” notes Michael Santelli, president of USIS’ Information Management Division (LABAT). “Being proactive about managing data can also save money. It is not uncommon to hear that the cost of one litigation would have paid for the technology and services to better manage the data.”
What do you think?
The chief information officer increasingly is joining the chief council in setting e-Discovery strategy within government organizations. That's according to a survey by USIS, an Altegrity company, conducted among government leaders from the federal e-Discovery community.
Among the other findings of the survey:
• Information management, data collection, and producing discoverable results in a timely manner are major concerns.
• More than one-third of respondents said the preservation and collection stage of electronic data discovery (EDD) needs the most improvement.
• Organizations that place a strong emphasis on the EDD process and strategy tend to have better e-Discovery processes.
• Among respondents whose organizations do not place an emphasis on the EDD process, not a single one reported being satisfied with their e-Discovery process.
“This survey reinforces how important it is to have good information management practices in place for the e-Discovery program and the burden it can place on a team when those practices simply aren’t there,” notes Michael Santelli, president of USIS’ Information Management Division (LABAT). “Being proactive about managing data can also save money. It is not uncommon to hear that the cost of one litigation would have paid for the technology and services to better manage the data.”
What do you think?
Labels:
AIIM,
archive,
data capture,
data management,
data storage,
document imaging,
e-discovery,
ecm,
Mark Brousseau,
page scanning,
TAWPI
Monday, December 20, 2010
Holiday Travel and IT Security Risks
Posted by Mark Brousseau
Tis the season to be jolly – and to leave sensitive corporate information behind at the airport!
According to telephone interviews with the lost property offices of 15 UK airports, including Heathrow and Luton, over 5,100 mobile phones and 3,844 laptops have been left behind so far this year; with the majority still unclaimed and many more expected to be left over the Christmas holiday peak season. This figure is likely to be just the tip of the iceberg as ABTA expect over 4 million people to be travelling over this period, and the overall figures do not take into account all those devices that were stolen, or kept by the ‘lucky’ finder.
The survey, carried out by Credant Technologies, also found that in the majority of cases, those devices that aren’t reclaimed are then either sold at auction or donated to charities. However the fact is that these devices may still contain information that could be available for the new owner. With ID theft from mobile phones and other lost devices at an all time high, users should really take special care this Christmas when travelling.
According to a representative at Luton Airport, the most common place devices are forgotten is at the security check point as it’s a very pressured environment with numerous distractions. Often, once the travelers have boarded the plane and left the country it’s just too expensive to return for the device, which in most instances will be covered by insurance, resulting in the majority going unclaimed.
But the device’s value is the last thing organisations should be worrying about, explains Seán Glynn, vice president at Credant Technologies, “What is much more concerning are the copious volumes of sensitive data these devices contain – often unsecured and easily accessed. Without protecting mobile phones, laptops and even USBs with something even as basic as a password, a malicious third party can have easy access to the corporate network, email accounts and all the files stored on the device including the contact lists. Users also store such things as passwords, bank details and other personal information on the device making it child’s play to impersonate the user and steal their identity – both personal and corporate.”
Credant Technologies provides the following eight tips to secure corporate information during holiday travel:
1. As you leave - whether it’s the check-in desk, security check point, or even the train station, make sure you take everything with you, including your mobile devices. A few seconds to check could potentially save you hours of frustration and embarrassment.
2. Protect your mobile device: with at least a password (and ensure that it is a strong one, containing letters, numbers and symbols). Better still, use an encryption solution so that even if your device is left behind, the data on it is not accessible to anyone who finds it.
3. Don’t elect to automatically complete online credentials, such as corporate network log in details, so that if you and your device should become separated, it cannot operate without you.
4. Back-up your device and remove any sensitive information that you do not need. If it’s not there it can’t be breached.
5. As in tip 4, remove SMS and emails that you don’t need anymore - you’d be surprised how many people keep their default password emails on their mobiles and other hugely sensitive information like PINs, bank account details or passwords!
6. Don't leave your mobile device open to access (e.g. leaving Bluetooth or WiFi turned on) somewhere visible and unsecured.
7. Include your name and contact details in the device so that, if it should be lost, it can easily be returned to you. Some operators have a registration service to facilitate this.
8. Finally, speak to your IT department before you leave the office this year – that’s what they’re there for. They’ll help make sure your device is better protected should it find itself languishing all alone at the airport.
What do you think?
Tis the season to be jolly – and to leave sensitive corporate information behind at the airport!
According to telephone interviews with the lost property offices of 15 UK airports, including Heathrow and Luton, over 5,100 mobile phones and 3,844 laptops have been left behind so far this year; with the majority still unclaimed and many more expected to be left over the Christmas holiday peak season. This figure is likely to be just the tip of the iceberg as ABTA expect over 4 million people to be travelling over this period, and the overall figures do not take into account all those devices that were stolen, or kept by the ‘lucky’ finder.
The survey, carried out by Credant Technologies, also found that in the majority of cases, those devices that aren’t reclaimed are then either sold at auction or donated to charities. However the fact is that these devices may still contain information that could be available for the new owner. With ID theft from mobile phones and other lost devices at an all time high, users should really take special care this Christmas when travelling.
According to a representative at Luton Airport, the most common place devices are forgotten is at the security check point as it’s a very pressured environment with numerous distractions. Often, once the travelers have boarded the plane and left the country it’s just too expensive to return for the device, which in most instances will be covered by insurance, resulting in the majority going unclaimed.
But the device’s value is the last thing organisations should be worrying about, explains Seán Glynn, vice president at Credant Technologies, “What is much more concerning are the copious volumes of sensitive data these devices contain – often unsecured and easily accessed. Without protecting mobile phones, laptops and even USBs with something even as basic as a password, a malicious third party can have easy access to the corporate network, email accounts and all the files stored on the device including the contact lists. Users also store such things as passwords, bank details and other personal information on the device making it child’s play to impersonate the user and steal their identity – both personal and corporate.”
Credant Technologies provides the following eight tips to secure corporate information during holiday travel:
1. As you leave - whether it’s the check-in desk, security check point, or even the train station, make sure you take everything with you, including your mobile devices. A few seconds to check could potentially save you hours of frustration and embarrassment.
2. Protect your mobile device: with at least a password (and ensure that it is a strong one, containing letters, numbers and symbols). Better still, use an encryption solution so that even if your device is left behind, the data on it is not accessible to anyone who finds it.
3. Don’t elect to automatically complete online credentials, such as corporate network log in details, so that if you and your device should become separated, it cannot operate without you.
4. Back-up your device and remove any sensitive information that you do not need. If it’s not there it can’t be breached.
5. As in tip 4, remove SMS and emails that you don’t need anymore - you’d be surprised how many people keep their default password emails on their mobiles and other hugely sensitive information like PINs, bank account details or passwords!
6. Don't leave your mobile device open to access (e.g. leaving Bluetooth or WiFi turned on) somewhere visible and unsecured.
7. Include your name and contact details in the device so that, if it should be lost, it can easily be returned to you. Some operators have a registration service to facilitate this.
8. Finally, speak to your IT department before you leave the office this year – that’s what they’re there for. They’ll help make sure your device is better protected should it find itself languishing all alone at the airport.
What do you think?
Tuesday, November 23, 2010
Network Security Facing Dual Challenge
By Dan Joe Barry, Napatech
Network security systems are under pressure. You might not be experiencing it yet, but you will soon. The dual challenge of dealing with more attacks at higher speeds threatens to undermine the stability of the most important commercial platforms of the 21st century; namely the Internet.
What can be done to address these challenges and avert the economic impact of an Internet collapse?
For many, the Internet is synonymous with web browsing, email and chat. But, the Internet and, IP-based networks in general, are now the foundation for a host of commercial services with significant impact on our daily lives.
On-line shopping is familiar to many, as is net-banking, but the financial world has now become reliant on the Internet for executing banking and investment transactions, sometimes thousands per second. Government services have also moved on-line. The Internet is used extensively in education and healthcare to provide distance services and expert consultation. The advent of cloud computing means that corporations will be more reliant than ever on the Internet to support their business.
In short, without the Internet, our lives would come to a grinding halt.
The development of the Internet as a commercial platform has not gone un-noticed by criminal organizations, which are exceptionally innovative in finding new ways of generating revenue! They have displaced the amateur hacker enthusiasts as the key threat to the Internet.
The open and global advantages of the Internet are now suddenly disadvantages as cybercriminals can attack from any location in the world, beyond the reach of domestic law enforcement agencies.
To understand the scope of the network security challenge, consider figures from Trend Micro, a leading provider of network security solutions, who have reported an explosive growth in the number of unique malware samples (i.e. types of attack) over the last 20 years.
Network security system vendors are struggling to respond to these new attacks as quickly as they occur. In a sense, they are playing a cat-and-mouse game with adversaries who are at least as intelligent and innovative at exploiting weaknesses in networks and applications, as they are at detecting attacks.
Higher data rates compound the challenge facing network security system vendors. IP networks are now being upgraded from 1 Gbps to 10 Gbps link speeds with 40 Gbps and 100 Gbps on the horizon. At 1 Gbps, a network security system needs to analyze up to 1.5 million packets per second. At 10 Gbps, this becomes 15 million packets per second. This is per port and only in 1 direction.
The challenge for network security system vendors is to ensure that their systems:
• Can handle up to 15 million packets per second per port in each direction
• Have the necessary processing power and memory to analyze packets in real-time
• Can scale to detect millions of new malware samples and higher line rates
The traditional approach to building network security systems is to build customized hardware including ASIC chip development. However, with the exponential growth in malware and higher line-rates, network security systems need to scale in both terms of data handling and computing power on a regular basis. This in turn means that the lifetime of a product revision will be shorter.
This begs the question: can network security system vendors keep up and have they got the deep pockets required to fund custom hardware and chip development on a regular basis?
It also leads to the question: is there another way?
High-performance network security systems can be based on standard, off-the-shelf PC servers when these are combined with Intelligent Real-time Network Analysis adapters for handling full line-rate data.The advantage of this approach is that it takes advantage of the strong roadmap of PC server and CPU chip vendors who are updating their performance and the number of processing cores they support on a yearly basis.
Basing high-performance network security system development on standard PC servers with Intelligent Real-time Network Analysis adapters provides a path to addressing the dual challenge of more malware at higher line-rates. It provides a cost-efficient, yet high-performance model that allows network security system vendors to focus on their expertise, namely combating cybercriminals and protecting the vital commercial platform that the Internet has become.
What do you think?
Network security systems are under pressure. You might not be experiencing it yet, but you will soon. The dual challenge of dealing with more attacks at higher speeds threatens to undermine the stability of the most important commercial platforms of the 21st century; namely the Internet.
What can be done to address these challenges and avert the economic impact of an Internet collapse?
For many, the Internet is synonymous with web browsing, email and chat. But, the Internet and, IP-based networks in general, are now the foundation for a host of commercial services with significant impact on our daily lives.
On-line shopping is familiar to many, as is net-banking, but the financial world has now become reliant on the Internet for executing banking and investment transactions, sometimes thousands per second. Government services have also moved on-line. The Internet is used extensively in education and healthcare to provide distance services and expert consultation. The advent of cloud computing means that corporations will be more reliant than ever on the Internet to support their business.
In short, without the Internet, our lives would come to a grinding halt.
The development of the Internet as a commercial platform has not gone un-noticed by criminal organizations, which are exceptionally innovative in finding new ways of generating revenue! They have displaced the amateur hacker enthusiasts as the key threat to the Internet.
The open and global advantages of the Internet are now suddenly disadvantages as cybercriminals can attack from any location in the world, beyond the reach of domestic law enforcement agencies.
To understand the scope of the network security challenge, consider figures from Trend Micro, a leading provider of network security solutions, who have reported an explosive growth in the number of unique malware samples (i.e. types of attack) over the last 20 years.
Network security system vendors are struggling to respond to these new attacks as quickly as they occur. In a sense, they are playing a cat-and-mouse game with adversaries who are at least as intelligent and innovative at exploiting weaknesses in networks and applications, as they are at detecting attacks.
Higher data rates compound the challenge facing network security system vendors. IP networks are now being upgraded from 1 Gbps to 10 Gbps link speeds with 40 Gbps and 100 Gbps on the horizon. At 1 Gbps, a network security system needs to analyze up to 1.5 million packets per second. At 10 Gbps, this becomes 15 million packets per second. This is per port and only in 1 direction.
The challenge for network security system vendors is to ensure that their systems:
• Can handle up to 15 million packets per second per port in each direction
• Have the necessary processing power and memory to analyze packets in real-time
• Can scale to detect millions of new malware samples and higher line rates
The traditional approach to building network security systems is to build customized hardware including ASIC chip development. However, with the exponential growth in malware and higher line-rates, network security systems need to scale in both terms of data handling and computing power on a regular basis. This in turn means that the lifetime of a product revision will be shorter.
This begs the question: can network security system vendors keep up and have they got the deep pockets required to fund custom hardware and chip development on a regular basis?
It also leads to the question: is there another way?
High-performance network security systems can be based on standard, off-the-shelf PC servers when these are combined with Intelligent Real-time Network Analysis adapters for handling full line-rate data.The advantage of this approach is that it takes advantage of the strong roadmap of PC server and CPU chip vendors who are updating their performance and the number of processing cores they support on a yearly basis.
Basing high-performance network security system development on standard PC servers with Intelligent Real-time Network Analysis adapters provides a path to addressing the dual challenge of more malware at higher line-rates. It provides a cost-efficient, yet high-performance model that allows network security system vendors to focus on their expertise, namely combating cybercriminals and protecting the vital commercial platform that the Internet has become.
What do you think?
Tuesday, November 2, 2010
Privacy Laws Must Change with the Times
By Todd Thibodeaux and David Valdez
A brave new world of technological innovation is emerging - some would say it has already emerged. Although we cannot predict the next killer app or revolutionary invention, we can be fairly sure that it will involve the use of personally identifiable information. Consumers have enthusiastically adopted personalized applications of all varieties, yet the way things stand now they must be prepared to sacrifice something at least as valuable: their privacy.
Congress is just beginning the complex process of developing legislation to protect consumer privacy while nurturing innovation in products and services. An important way to achieve the delicate balance between encouraging technology and preserving privacy is for Congress to expand the capabilities of the Federal Trade Commission (FTC) to ensure that it can keep up with the rapidly evolving marketplace.
In the mid to late 1990s, the FTC began reviewing how websites collected and managed consumers’ personally identifiable information. This led to the creation of a set of self-regulatory rules known as the Fair Information Practice Principles, which created four basic obligations: (1) consumers must be notified as to whether their online information is being collected, (2) consumers must provide consent as to whether or not they want their online information collected, (3) consumers must be able to view information a company has collected about them and verify its accuracy, and (4) businesses must undertake measures to ensure that information is accurate and stored securely.
The framework of the Fair Information Practice Principles is a good place to start when considering future privacy legislation. Over the past two decades it has demonstrated a suitable balance between responsible privacy standards and room for innovation. However, as technology evolves, the FTC should be able to keep up. The FTC should be provided with the discretion and flexibility to adapt, update and strengthen the Fair Information Practice Principles as well as its own role in safeguarding consumer privacy in response to changing technologies and consumer needs.
The FTC, in partnership with the private sector, should create privacy notices that are easy to read and understand in conjunction with an education campaign to inform consumers about their rights. Many privacy notices are dense and contain so much legalize that the notices become ineffective because consumers don’t read them.
Congress should provide the FTC with the resources to create an Online Consumer Protection bureau that focuses exclusively on online crimes such as identify theft, e-mail scams, and privacy enforcement. This would expand the FTC’s capabilities to investigate, prosecute and enforce consequences against breaches of privacy.
Any attempt to impose new privacy standards should distinguish between good actors that slip-up inadvertently versus bad actors that aim to cause trouble. A safe harbor program will accomplish this task by reducing liability if actions are preformed in good faith. Safe harbor programs provide a combination of carrot and stick which allow the FTC to execute different programs for different actors.
As policymakers continue to deliberate the best path for balancing the various stakeholder interests around the issue of online privacy, they must remember that any proposed legislation should not be absolute. The current set of privacy principles adopted by the FTC has worked well for over a decade and should serve as a framework for any new legislation. Technology is a moving target and privacy laws should be sufficiently flexible to adapt.
Todd Thibodeaux is CEO and president of CompTIA, a non-profit trade association advancing the global interests of information technology (IT) professionals and businesses (www.comptia.org). Todd can be reached at tthibodeaux@comptia.org. David Valdez is the organization’s senior director of public advocacy. David can be reached at dvaldez@comptia.org.
A brave new world of technological innovation is emerging - some would say it has already emerged. Although we cannot predict the next killer app or revolutionary invention, we can be fairly sure that it will involve the use of personally identifiable information. Consumers have enthusiastically adopted personalized applications of all varieties, yet the way things stand now they must be prepared to sacrifice something at least as valuable: their privacy.
Congress is just beginning the complex process of developing legislation to protect consumer privacy while nurturing innovation in products and services. An important way to achieve the delicate balance between encouraging technology and preserving privacy is for Congress to expand the capabilities of the Federal Trade Commission (FTC) to ensure that it can keep up with the rapidly evolving marketplace.
In the mid to late 1990s, the FTC began reviewing how websites collected and managed consumers’ personally identifiable information. This led to the creation of a set of self-regulatory rules known as the Fair Information Practice Principles, which created four basic obligations: (1) consumers must be notified as to whether their online information is being collected, (2) consumers must provide consent as to whether or not they want their online information collected, (3) consumers must be able to view information a company has collected about them and verify its accuracy, and (4) businesses must undertake measures to ensure that information is accurate and stored securely.
The framework of the Fair Information Practice Principles is a good place to start when considering future privacy legislation. Over the past two decades it has demonstrated a suitable balance between responsible privacy standards and room for innovation. However, as technology evolves, the FTC should be able to keep up. The FTC should be provided with the discretion and flexibility to adapt, update and strengthen the Fair Information Practice Principles as well as its own role in safeguarding consumer privacy in response to changing technologies and consumer needs.
The FTC, in partnership with the private sector, should create privacy notices that are easy to read and understand in conjunction with an education campaign to inform consumers about their rights. Many privacy notices are dense and contain so much legalize that the notices become ineffective because consumers don’t read them.
Congress should provide the FTC with the resources to create an Online Consumer Protection bureau that focuses exclusively on online crimes such as identify theft, e-mail scams, and privacy enforcement. This would expand the FTC’s capabilities to investigate, prosecute and enforce consequences against breaches of privacy.
Any attempt to impose new privacy standards should distinguish between good actors that slip-up inadvertently versus bad actors that aim to cause trouble. A safe harbor program will accomplish this task by reducing liability if actions are preformed in good faith. Safe harbor programs provide a combination of carrot and stick which allow the FTC to execute different programs for different actors.
As policymakers continue to deliberate the best path for balancing the various stakeholder interests around the issue of online privacy, they must remember that any proposed legislation should not be absolute. The current set of privacy principles adopted by the FTC has worked well for over a decade and should serve as a framework for any new legislation. Technology is a moving target and privacy laws should be sufficiently flexible to adapt.
Todd Thibodeaux is CEO and president of CompTIA, a non-profit trade association advancing the global interests of information technology (IT) professionals and businesses (www.comptia.org). Todd can be reached at tthibodeaux@comptia.org. David Valdez is the organization’s senior director of public advocacy. David can be reached at dvaldez@comptia.org.
Tuesday, October 26, 2010
E-Discovery: Addressing the Risks
By Rich Walsh of Viewpointe
At the heart of many risks facing companies today lurks e-discovery – the locating and accessing of electronically stored information (ESI) for purposes of litigation. ESI can be any electronically stored information – documents, emails, databases, etc. – potentially for use as evidence by lawyers in legal cases.
Compounding the risk to companies is the volume of data subject to e-discovery. In fact, the Association of Certified E-Discovery Specialists, a group dedicated to dealing with this problem, calls the deluge of electronically stored material used as evidence in civil actions the single biggest storyline in the legal world today.
In a recent cross-industry report commissioned by the Deloitte Forensic Center, “E-Discovery: Mitigating Risk Through Better Communication,” just 43 percent of the respondents felt that their companies were somewhat up for the e-discovery challenge. The report notes that in the e-discovery process legal, IT and other departments – those that don’t normally work together – are often thrown together “in a room” to do a difficult job under quite a bit of pressure. And with a lack of common language and systems among these groups, it only further muddies the process.
Where is all of this leading? The Deloitte report found that 49 percent of respondents expect their company’s IT department to have to work more on e-discovery efforts in the near future. So, on top of IT’s workload and limited budgets, adding new e-discovery work will further challenge their priorities. In preparation, companies will need to figure out, sooner than later, where (and even if) they have stored and can easily retrieve everything they might need to produce.
I’d love to hear from TAWPI members as how your companies may be preparing for this challenge. Any tips for colleagues? Share with us.
Rich Walsh is president, Document Archive & Repository Services at Viewpointe. He has more than 25 years of operational information technology experience.
At the heart of many risks facing companies today lurks e-discovery – the locating and accessing of electronically stored information (ESI) for purposes of litigation. ESI can be any electronically stored information – documents, emails, databases, etc. – potentially for use as evidence by lawyers in legal cases.
Compounding the risk to companies is the volume of data subject to e-discovery. In fact, the Association of Certified E-Discovery Specialists, a group dedicated to dealing with this problem, calls the deluge of electronically stored material used as evidence in civil actions the single biggest storyline in the legal world today.
In a recent cross-industry report commissioned by the Deloitte Forensic Center, “E-Discovery: Mitigating Risk Through Better Communication,” just 43 percent of the respondents felt that their companies were somewhat up for the e-discovery challenge. The report notes that in the e-discovery process legal, IT and other departments – those that don’t normally work together – are often thrown together “in a room” to do a difficult job under quite a bit of pressure. And with a lack of common language and systems among these groups, it only further muddies the process.
Where is all of this leading? The Deloitte report found that 49 percent of respondents expect their company’s IT department to have to work more on e-discovery efforts in the near future. So, on top of IT’s workload and limited budgets, adding new e-discovery work will further challenge their priorities. In preparation, companies will need to figure out, sooner than later, where (and even if) they have stored and can easily retrieve everything they might need to produce.
I’d love to hear from TAWPI members as how your companies may be preparing for this challenge. Any tips for colleagues? Share with us.
Rich Walsh is president, Document Archive & Repository Services at Viewpointe. He has more than 25 years of operational information technology experience.
Monday, May 24, 2010
Dot connecting in the new data world
Posted by Mark Brousseau
The flood of digital information increases the need for accuracy -- including knowing which data to leave out. Scott Schumacher, Ph.D., a government security and technology expert with Initiate, an IBM Company, explains:
Remember when we used to ride around in our cars and listen to AM radio? Maybe you’re not quite old enough to remember, but there was a time when AM radio was all we had – and that was fine. There also used to be only a handful of television channels, which we had to get up out of our chairs to change. That was fine, too.
I don’t remember longing for a wider variety of music on the radio, or more channels to watch on TV. We had what we had, and it was all fine – it was all “good enough.”
There was also a time when the level of accuracy that our intelligence and law-enforcement systems offered was “fine.” We connected the dots well enough to eliminate the greatest threats.
Not any more.
Today, there is an intense push for accuracy in our data and, particularly, in our ability to accurately “connect the dots.” Why now? What’s changed? What’s pushing the accuracy button more than it’s been pushed before?
Turn off the radio, put down the remote, and I’ll explain.
What is accuracy?
I’m a mathematician. When I think of accuracy I think of numbers and percentages, of false-negatives and false-positives. But for law enforcement or intelligence officials, accuracy means tracking down and mitigating a potential risk before it happens.
Both perspectives are critical in understanding what accuracy is and how to improve your results.
Mathematically, accuracy is a pair of numbers. Accuracy compares the number of times you “miss” (present a false negative) and the number of times you incorrectly “hit” (present a false positive). Accuracy measures how well your process makes a decision – how well it can find a “true-positive” result amid the false negatives and false positives.
When you hear a phrase like, “our system is 95 percent accurate,” it usually refers to the false-negative rate – or the connections it missed. To gauge the true accuracy of that system, you also need to know the false-positive rate. If the system floods you with false positives, and touts a 95 percent accuracy rate (focusing on the things it missed), that’s not going to get you very far. You’re going to be spending all your time chasing false threats.
From an intelligence perspective, accuracy is just as much about keeping data apart as it is putting it together. If there were a security threat in a particular airport at a particular time, a less-than-accurate system might flag every person who was in the airport at that time as a suspect. A highly accurate system would be able to parse through the vast numbers of individuals in the airport at that time, “connect the dots” between those people and other data points within other records, and present a highly targeted list of suspects.
Accuracy is being able to make the best use of all the information you have – putting data together where necessary, and keeping it apart where necessary, to create a highly targeted list of “true-positive” results.
Why now?
The description of accuracy hasn’t changed since the time of AM-only radio, but the need has changed – because our circumstances have changed. Two primary factors are driving the push for greater accuracy:
• More information. Today’s law enforcement officials have to deal with millions of terabytes more data than they have ever had to work with in the past. Not only are there more records about more people – a simple function of our digital times – there is significantly more travel (international travel in particular), more people traveling on visas, more types of communication and a wider variety of threats.
• More fragmentation. As the amount of information grows, so do the different locations and different types of information. From local police records to state databases to federal watch lists – and all the different types of entities (people, phone numbers, weapons) that reside in each – intelligence and law enforcement officials are faced with a daunting task of connecting dots between and among all this information. Their job is akin to finding a needle in a haystack.
Adding to the challenge, the risks are greater for missing important connections – or, not connecting the dots between data that already exists. Being marginally accurate is no longer good enough.
Finding the right technology
Finding the right solution is all about understanding what accuracy is and what you should expect from a highly accurate system. The most effective technology will let you look at the right 10,000 things, not just the top 10,000 things. The right technology will help you reduce the noise, particularly the signal-to-noise ratio.
The most effective technology also will have a level of intelligence. Technology that produces the most accurate results will be able to account for errors and other misspellings – or purposeful deception, a practice common among persons of interest trying to avoid detection. That technology also will have the ability to recognize and account for cultural anomalies and unique factors in different languages.
The technology you use also has to be adaptable; it has to be able to allow you to introduce new information and new agents, as well as securely exchange information between – and allow appropriate access from – other reliable sources.
Finally, your technology has to be flexible, so you can readjust your priorities according to changing threats, threat levels and resources.
Accuracy involves many factors. And, it’s a moving target. Because of the evolving nature of threats, we must keep working at this – we must keep pushing the envelope.
“Good enough” just doesn’t work any more. As soon as we can do more, we have to do more. And we have to keep pushing for greater accuracy and a greater ability to connect the dots. Our national security is at stake.
The flood of digital information increases the need for accuracy -- including knowing which data to leave out. Scott Schumacher, Ph.D., a government security and technology expert with Initiate, an IBM Company, explains:
Remember when we used to ride around in our cars and listen to AM radio? Maybe you’re not quite old enough to remember, but there was a time when AM radio was all we had – and that was fine. There also used to be only a handful of television channels, which we had to get up out of our chairs to change. That was fine, too.
I don’t remember longing for a wider variety of music on the radio, or more channels to watch on TV. We had what we had, and it was all fine – it was all “good enough.”
There was also a time when the level of accuracy that our intelligence and law-enforcement systems offered was “fine.” We connected the dots well enough to eliminate the greatest threats.
Not any more.
Today, there is an intense push for accuracy in our data and, particularly, in our ability to accurately “connect the dots.” Why now? What’s changed? What’s pushing the accuracy button more than it’s been pushed before?
Turn off the radio, put down the remote, and I’ll explain.
What is accuracy?
I’m a mathematician. When I think of accuracy I think of numbers and percentages, of false-negatives and false-positives. But for law enforcement or intelligence officials, accuracy means tracking down and mitigating a potential risk before it happens.
Both perspectives are critical in understanding what accuracy is and how to improve your results.
Mathematically, accuracy is a pair of numbers. Accuracy compares the number of times you “miss” (present a false negative) and the number of times you incorrectly “hit” (present a false positive). Accuracy measures how well your process makes a decision – how well it can find a “true-positive” result amid the false negatives and false positives.
When you hear a phrase like, “our system is 95 percent accurate,” it usually refers to the false-negative rate – or the connections it missed. To gauge the true accuracy of that system, you also need to know the false-positive rate. If the system floods you with false positives, and touts a 95 percent accuracy rate (focusing on the things it missed), that’s not going to get you very far. You’re going to be spending all your time chasing false threats.
From an intelligence perspective, accuracy is just as much about keeping data apart as it is putting it together. If there were a security threat in a particular airport at a particular time, a less-than-accurate system might flag every person who was in the airport at that time as a suspect. A highly accurate system would be able to parse through the vast numbers of individuals in the airport at that time, “connect the dots” between those people and other data points within other records, and present a highly targeted list of suspects.
Accuracy is being able to make the best use of all the information you have – putting data together where necessary, and keeping it apart where necessary, to create a highly targeted list of “true-positive” results.
Why now?
The description of accuracy hasn’t changed since the time of AM-only radio, but the need has changed – because our circumstances have changed. Two primary factors are driving the push for greater accuracy:
• More information. Today’s law enforcement officials have to deal with millions of terabytes more data than they have ever had to work with in the past. Not only are there more records about more people – a simple function of our digital times – there is significantly more travel (international travel in particular), more people traveling on visas, more types of communication and a wider variety of threats.
• More fragmentation. As the amount of information grows, so do the different locations and different types of information. From local police records to state databases to federal watch lists – and all the different types of entities (people, phone numbers, weapons) that reside in each – intelligence and law enforcement officials are faced with a daunting task of connecting dots between and among all this information. Their job is akin to finding a needle in a haystack.
Adding to the challenge, the risks are greater for missing important connections – or, not connecting the dots between data that already exists. Being marginally accurate is no longer good enough.
Finding the right technology
Finding the right solution is all about understanding what accuracy is and what you should expect from a highly accurate system. The most effective technology will let you look at the right 10,000 things, not just the top 10,000 things. The right technology will help you reduce the noise, particularly the signal-to-noise ratio.
The most effective technology also will have a level of intelligence. Technology that produces the most accurate results will be able to account for errors and other misspellings – or purposeful deception, a practice common among persons of interest trying to avoid detection. That technology also will have the ability to recognize and account for cultural anomalies and unique factors in different languages.
The technology you use also has to be adaptable; it has to be able to allow you to introduce new information and new agents, as well as securely exchange information between – and allow appropriate access from – other reliable sources.
Finally, your technology has to be flexible, so you can readjust your priorities according to changing threats, threat levels and resources.
Accuracy involves many factors. And, it’s a moving target. Because of the evolving nature of threats, we must keep working at this – we must keep pushing the envelope.
“Good enough” just doesn’t work any more. As soon as we can do more, we have to do more. And we have to keep pushing for greater accuracy and a greater ability to connect the dots. Our national security is at stake.
Tuesday, March 10, 2009
Business Intelligence Trends for 2009
By Mark Brousseau
Even in a weak economy, demand continues for enterprise business intelligence, Vickie Farrell (vickie.farrell@hp.com), manager, Neoview market strategy & development, software division, at HP said today during a presentation at the Gartner Business Intelligence Summit 2009 in Washington, D.C.
“IT spending has dropped precipitously in this economy,” Farrell noted. “But studies show business intelligence should grow by 7 percent this year, off from 8.6 percent growth in 2008. Business intelligence remains strong.”
Farrell thinks businesses will be well served by their business intelligence investments. “Businesses that maintain and build analytic capability will survive and thrive when the economy improves,” she said.
Farrell made her comments during an afternoon presentation in the HP Solutions Theater on the emerging macro and business intelligence trends for 2009. Among the trends she presented:
… The consumerization of IT. IT technology innovation is shifting from the enterprise and the military to consumer technology, spawning a new wave of IT adoption, Farrell said. The impact on business intelligence is increased visualization, greater collaboration, and new sources of data. Farrell believes that social networking will increasingly dictate information delivery and use.
… Business intelligence is increasing in importance. Farrell cited a Computerworld survey finding that 42 percent of respondents expected overall expenditures for business intelligence tools and solutions to increase from 2008 to 2009. And the economic crisis may actually drive some of this growth as more organizations realize that analyzing data can help them better deal with new government regulations, understand and manage their business, decrease their risks, and enhance their ability to compete.
… Business intelligence buyers are much more scrutinizing. Farrell said organizations are dealing with stricter requirements for clearly-defined business objectives and quantified value. Farrell also is seeing requirements for shorter payback periods and self-funding business intelligence initiatives.
… The market is demanding lower business intelligence complexity.
… Analytics are moving to the front office. Advanced analytics are top initiatives at many companies, Farrell said, noting that organizations with a culture and infrastructure for analytics and fact-based decision-making are better poised to compete and grow.
… Data integration is gaining momentum. Surveys show this to be a top business intelligence project challenge and key IT initiative, Farrell said. “As enterprises recognize data as a corporate asset, data management becomes a strategy corporate capability,” she explained.
… Structured and unstructured data are converging. “Integration of unstructured data increases the accuracy of business intelligence analysis,” Farrell said, noting that recent technology advances enable text mining and queries.
What do you think? Post your comments below.
Even in a weak economy, demand continues for enterprise business intelligence, Vickie Farrell (vickie.farrell@hp.com), manager, Neoview market strategy & development, software division, at HP said today during a presentation at the Gartner Business Intelligence Summit 2009 in Washington, D.C.
“IT spending has dropped precipitously in this economy,” Farrell noted. “But studies show business intelligence should grow by 7 percent this year, off from 8.6 percent growth in 2008. Business intelligence remains strong.”
Farrell thinks businesses will be well served by their business intelligence investments. “Businesses that maintain and build analytic capability will survive and thrive when the economy improves,” she said.
Farrell made her comments during an afternoon presentation in the HP Solutions Theater on the emerging macro and business intelligence trends for 2009. Among the trends she presented:
… The consumerization of IT. IT technology innovation is shifting from the enterprise and the military to consumer technology, spawning a new wave of IT adoption, Farrell said. The impact on business intelligence is increased visualization, greater collaboration, and new sources of data. Farrell believes that social networking will increasingly dictate information delivery and use.
… Business intelligence is increasing in importance. Farrell cited a Computerworld survey finding that 42 percent of respondents expected overall expenditures for business intelligence tools and solutions to increase from 2008 to 2009. And the economic crisis may actually drive some of this growth as more organizations realize that analyzing data can help them better deal with new government regulations, understand and manage their business, decrease their risks, and enhance their ability to compete.
… Business intelligence buyers are much more scrutinizing. Farrell said organizations are dealing with stricter requirements for clearly-defined business objectives and quantified value. Farrell also is seeing requirements for shorter payback periods and self-funding business intelligence initiatives.
… The market is demanding lower business intelligence complexity.
… Analytics are moving to the front office. Advanced analytics are top initiatives at many companies, Farrell said, noting that organizations with a culture and infrastructure for analytics and fact-based decision-making are better poised to compete and grow.
… Data integration is gaining momentum. Surveys show this to be a top business intelligence project challenge and key IT initiative, Farrell said. “As enterprises recognize data as a corporate asset, data management becomes a strategy corporate capability,” she explained.
… Structured and unstructured data are converging. “Integration of unstructured data increases the accuracy of business intelligence analysis,” Farrell said, noting that recent technology advances enable text mining and queries.
What do you think? Post your comments below.
Monday, March 9, 2009
Mastering Data Management
Posted by Mark Brousseau
An interesting article from SearchSAP.com on successful master data management:
Successful MDM strategy starts with finding broken processes, not technology
By Courtney Bjorlin, News Editor
24 Feb 2009 | SearchSAP.com
Developing a successful master data management (MDM) strategy starts with identifying broken business processes that can be fixed with improved data management, according to analysts.
MDM tends to come across like an infrastructure project or middleware -- something that IT would sponsor, according to Dan Power, president of Hub Solution Designs Inc., an MDM consulting firm. But placing sponsorship with IT misses the point, he said.
The line of business needs to sponsor the project because it can identify the business value the data holds and how a single view of that data can affect the bottom line.
"IT should be involved, but it shouldn't drive this," Power said. "It's really a business paradigm -- changing the way the business thinks about data."
Master data is all the data elements that are broadly used and shared across departmental boundaries. MDM is the discipline for ensuring the consistency of an organization's data, enabling a single view of product or customer data.
"For us, it is definitely not a piece of software," said Ted Friedman, vice president, distinguished analyst with Stamford, Conn.-based Gartner Inc. "It is a holistic discipline -- process, architecture and people."
In contrast, an ERP system isn't designed to master data -- it's designed to fulfill processes, according to Rob Karel, principal analyst with Cambridge, Mass.-based Forrester Research.
Also, different SAP applications have their own set of data models, and ways of managing customers, according to Ravi Shankar, senior director of product marketing for Siperian, an MDM software vendor. In turn, data warehouses are used more for reporting purposes, Shankar said.
Finding the people whose jobs are affected by the data is the best way to identify those broken processes and thus get started with an MDM project.
"Find the business pain, and find out what their problems are, and what better, more accessible, more secure customer information and product information would do for them," Power said.
He added that organizations should start building the MDM business case with involvement from the three different levels of the organization -- the C-suite, the business owners (such as the vice president of marketing), and the line-of-business people.
Ideally, companies should try to recruit people who have a good balance of the process and data views, Friedman said. Those individuals should be high enough in the organization to have the ability to make changes, yet low enough to be intimately familiar with the problems that poor master data can cause in the organization, he added.
If the company has already invested in a data governance organization -- people from business and IT who represent the business needs and the technology that supports organizational data -- use those stewards to do the analysis, Karel said. Ask such questions as: What are the processes most in need of the data? What are the systems providing that data? Does assessment of the quality of that data improve consistency?
If the company doesn't have a formal data governance organization -- for instance, if a project manager or enterprise architect is trying to evangelize the project -- it should start by defining the priorities. If a line of business can't articulate a negative business impact around the data, Karel said, there probably isn't a reason to pursue MDM there.
"MDM is a great place where the squeaky wheel should really get the grease," he said.
In reality, what people want is a single view of the data, and that can't be completed until there is a strong foundation of clean, accurate data, according to Power. Getting different parts of the business to agree on definitions of the data can be one of the hardest parts of the project.
Because it's unlikely that a company will ever get the entire business to agree on such a broad question as what a customer is, a better strategy is to put out a definition and have people respond with those aspects that work for them and those that don't.
The scope of the project -- which master data domains a company will tackle -- is one of the most important pieces to start with, Friedman said.
Instead of looking at MDM as a holistic, cross-enterprise strategy, look at it from the bottom up and take a multi-step, multi-phased approach, Karel said. Identify specific business processes and functions for the most-improved opportunities around data management, he advised, and quantify or qualify the value of improving that particular process.
Fulfilling compliance initiatives, as well as reducing costs, is a common business driver for MDM projects. For instance, rectifying duplicate customer data can reduce the amount of money spent on mailings.
The company also gets a true understanding of lifetime customer value, according to Aaron Zornes, founder and chief research officer of the MDM Institute. For example, an insurance company could have three different stores of customer information, depending on what the customer purchased. MDM can increase cross-sell opportunities.
Depending on the scope of the project, an organization can derive benefits in as little as six months, Friedman said.
Organizations should not assume going in that the right answer is going to be consolidating all master data into a single repository at one end of the spectrum, Friedman said. There are other ways to integrate and synchronize data.
In turn, because MDM is a cross-organizational effort, there has to be some funding model associated with it that engages the different parts of the organization and makes them feel that they have some skin in the game, he said. Make sure one individual doesn't hold much more political clout or power in the initiative than any other individual.
Above all, remember, don't lead with the technology.
"There's some great technology out there that can really help support and deliver," Karel said. "But it's not going to be the main [catalyst] of MDM."
An interesting article from SearchSAP.com on successful master data management:
Successful MDM strategy starts with finding broken processes, not technology
By Courtney Bjorlin, News Editor
24 Feb 2009 | SearchSAP.com
Developing a successful master data management (MDM) strategy starts with identifying broken business processes that can be fixed with improved data management, according to analysts.
MDM tends to come across like an infrastructure project or middleware -- something that IT would sponsor, according to Dan Power, president of Hub Solution Designs Inc., an MDM consulting firm. But placing sponsorship with IT misses the point, he said.
The line of business needs to sponsor the project because it can identify the business value the data holds and how a single view of that data can affect the bottom line.
"IT should be involved, but it shouldn't drive this," Power said. "It's really a business paradigm -- changing the way the business thinks about data."
Master data is all the data elements that are broadly used and shared across departmental boundaries. MDM is the discipline for ensuring the consistency of an organization's data, enabling a single view of product or customer data.
"For us, it is definitely not a piece of software," said Ted Friedman, vice president, distinguished analyst with Stamford, Conn.-based Gartner Inc. "It is a holistic discipline -- process, architecture and people."
In contrast, an ERP system isn't designed to master data -- it's designed to fulfill processes, according to Rob Karel, principal analyst with Cambridge, Mass.-based Forrester Research.
Also, different SAP applications have their own set of data models, and ways of managing customers, according to Ravi Shankar, senior director of product marketing for Siperian, an MDM software vendor. In turn, data warehouses are used more for reporting purposes, Shankar said.
Finding the people whose jobs are affected by the data is the best way to identify those broken processes and thus get started with an MDM project.
"Find the business pain, and find out what their problems are, and what better, more accessible, more secure customer information and product information would do for them," Power said.
He added that organizations should start building the MDM business case with involvement from the three different levels of the organization -- the C-suite, the business owners (such as the vice president of marketing), and the line-of-business people.
Ideally, companies should try to recruit people who have a good balance of the process and data views, Friedman said. Those individuals should be high enough in the organization to have the ability to make changes, yet low enough to be intimately familiar with the problems that poor master data can cause in the organization, he added.
If the company has already invested in a data governance organization -- people from business and IT who represent the business needs and the technology that supports organizational data -- use those stewards to do the analysis, Karel said. Ask such questions as: What are the processes most in need of the data? What are the systems providing that data? Does assessment of the quality of that data improve consistency?
If the company doesn't have a formal data governance organization -- for instance, if a project manager or enterprise architect is trying to evangelize the project -- it should start by defining the priorities. If a line of business can't articulate a negative business impact around the data, Karel said, there probably isn't a reason to pursue MDM there.
"MDM is a great place where the squeaky wheel should really get the grease," he said.
In reality, what people want is a single view of the data, and that can't be completed until there is a strong foundation of clean, accurate data, according to Power. Getting different parts of the business to agree on definitions of the data can be one of the hardest parts of the project.
Because it's unlikely that a company will ever get the entire business to agree on such a broad question as what a customer is, a better strategy is to put out a definition and have people respond with those aspects that work for them and those that don't.
The scope of the project -- which master data domains a company will tackle -- is one of the most important pieces to start with, Friedman said.
Instead of looking at MDM as a holistic, cross-enterprise strategy, look at it from the bottom up and take a multi-step, multi-phased approach, Karel said. Identify specific business processes and functions for the most-improved opportunities around data management, he advised, and quantify or qualify the value of improving that particular process.
Fulfilling compliance initiatives, as well as reducing costs, is a common business driver for MDM projects. For instance, rectifying duplicate customer data can reduce the amount of money spent on mailings.
The company also gets a true understanding of lifetime customer value, according to Aaron Zornes, founder and chief research officer of the MDM Institute. For example, an insurance company could have three different stores of customer information, depending on what the customer purchased. MDM can increase cross-sell opportunities.
Depending on the scope of the project, an organization can derive benefits in as little as six months, Friedman said.
Organizations should not assume going in that the right answer is going to be consolidating all master data into a single repository at one end of the spectrum, Friedman said. There are other ways to integrate and synchronize data.
In turn, because MDM is a cross-organizational effort, there has to be some funding model associated with it that engages the different parts of the organization and makes them feel that they have some skin in the game, he said. Make sure one individual doesn't hold much more political clout or power in the initiative than any other individual.
Above all, remember, don't lead with the technology.
"There's some great technology out there that can really help support and deliver," Karel said. "But it's not going to be the main [catalyst] of MDM."
Saturday, November 8, 2008
Texas-Sized Data Center Problem
Posted by Mark Brousseau
IBM Corp. has been given a month to fix service problems with a mammoth Texas state data center project or possibly have its $863 million contract terminated, according to an article in Friday's Austin American-Statesman.
The state notified IBM this week that the company has "breached its contractual duties and obligations to the State of Texas" and outlines specific issues with IBM's work.
"The current, unremediated situation is untenable for the State of Texas, as critical state data continues to be at risk," according to the notice written by Brian Rawson, executive director of the Department of Information Resources.
The Statesman says the most persistent problem involves the company's failure to back up data stored on agencies' servers as it consolidates 27 state agencies' data centers into two facilities in Austin and San Angelo. The objective is to streamline and modernize the agencies' technology operations while saving money.
But the company has been repeatedly warned by the state that it had fallen short on requirements in the contract and has been penalized $5.2 million, including almost $902,000 for the data backup problems. The company so far has been paid $175 million under the contract.
The notice, released Thursday, is the first required step to terminate the contract.
It is a serious move by the state, following Gov. Rick Perry's directive two weeks ago to stop work on the contract while a plan to fix the problems was developed. That plan is expected to be completed by Nov. 17.
"The governor expects the issue will be resolved to the full satisfaction of the state," said Allison Castle, the governor's spokeswoman, so that termination of the contract will not be necessary.
IBM spokesman Jeff Tieszen said the company has been working to address the data backup and recovery issues, and would respond accordingly to the state's letter.
"The state's data center infrastructure is more stable and secure now and we plan to work with (the Department of Information Resources) to continue to improve the system to better serve the state's citizens," Tieszen said in a statement.
Rawson wrote in a letter to Perry that he expects "IBM to have restored the confidence of the state leadership and the agencies upon implementation" of the governor's plan.
But Rawson said that the state must be prepared if the results are not satisfactory and said a contingency plan is being developed to ensure data center services without IBM.
IBM assumed responsibility for servers and mainframes at 1,300 locations across the state in April 2007 as it moves the work to the centralized facilities.
It must provide security, backup and disaster recovery at all of those locations. That is where many of the problems have developed.
This summer, the attorney general's office lost a significant amount of data in a server crash at its Medicaid fraud division in Tyler. IBM had failed to back up the data, as required by the contract.
Eight months of data files from the office's fraud investigations were initially lost because the office had stopped using its previous file backup software in November. Ninety percent of the data has since been recovered, but it is unclear whether all of that data is usable.
IBM Corp. has been given a month to fix service problems with a mammoth Texas state data center project or possibly have its $863 million contract terminated, according to an article in Friday's Austin American-Statesman.
The state notified IBM this week that the company has "breached its contractual duties and obligations to the State of Texas" and outlines specific issues with IBM's work.
"The current, unremediated situation is untenable for the State of Texas, as critical state data continues to be at risk," according to the notice written by Brian Rawson, executive director of the Department of Information Resources.
The Statesman says the most persistent problem involves the company's failure to back up data stored on agencies' servers as it consolidates 27 state agencies' data centers into two facilities in Austin and San Angelo. The objective is to streamline and modernize the agencies' technology operations while saving money.
But the company has been repeatedly warned by the state that it had fallen short on requirements in the contract and has been penalized $5.2 million, including almost $902,000 for the data backup problems. The company so far has been paid $175 million under the contract.
The notice, released Thursday, is the first required step to terminate the contract.
It is a serious move by the state, following Gov. Rick Perry's directive two weeks ago to stop work on the contract while a plan to fix the problems was developed. That plan is expected to be completed by Nov. 17.
"The governor expects the issue will be resolved to the full satisfaction of the state," said Allison Castle, the governor's spokeswoman, so that termination of the contract will not be necessary.
IBM spokesman Jeff Tieszen said the company has been working to address the data backup and recovery issues, and would respond accordingly to the state's letter.
"The state's data center infrastructure is more stable and secure now and we plan to work with (the Department of Information Resources) to continue to improve the system to better serve the state's citizens," Tieszen said in a statement.
Rawson wrote in a letter to Perry that he expects "IBM to have restored the confidence of the state leadership and the agencies upon implementation" of the governor's plan.
But Rawson said that the state must be prepared if the results are not satisfactory and said a contingency plan is being developed to ensure data center services without IBM.
IBM assumed responsibility for servers and mainframes at 1,300 locations across the state in April 2007 as it moves the work to the centralized facilities.
It must provide security, backup and disaster recovery at all of those locations. That is where many of the problems have developed.
This summer, the attorney general's office lost a significant amount of data in a server crash at its Medicaid fraud division in Tyler. IBM had failed to back up the data, as required by the contract.
Eight months of data files from the office's fraud investigations were initially lost because the office had stopped using its previous file backup software in November. Ninety percent of the data has since been recovered, but it is unclear whether all of that data is usable.
Labels:
Brousseau,
data backup,
data center,
data management,
IBM,
outsourcing,
privacy,
TAWPI
IT Spending Getting Squeezed
Posted by Mark Brousseau
An article in yesterday's Austin American-Statesman says the fourth quarter could be even more disappointing than technology vendors already had expected. Businesses are cutting back spending by putting off equipment purchases and upgrades and laying off workers. Even software, considered a safer bet because it helps companies automate costly steps, is also likely to take a hit, the Statesman noted.
"It's inevitable that all technology companies, with varying degrees, will be running into the same thing," Stephen Minton, an analyst for research firm IDC, told the newspaper. "The reaction of businesses to the economic crisis is to stop spending money."
Technology makes up a big chunk of corporate spending. Of the total amount of money that U.S. businesses spend on fixed investments, which includes offices and factories, about 28 percent goes to computer and communications equipment and software, according to Commerce Department data analyzed by Bartels.
IDC expects very little growth in overall tech spending for the rest of the year and through most of 2009. Spending in the U.S. and Europe probably will be roughly flat, while emerging markets should continue to grow.
"One thing we learned in 2001, a lot of people in software said the recession won't have an effect," Minton told the newspaper. They were wrong. "What businesses do when a recession starts is they stop spending altogether."
The bright spots in the sector: Information-technology services and outsourcing — helping companies manage their computing — tend to be the least affected in a downturn, he added.
It is clear that a recession will hurt the tech sector, but things don't figure to be as bad as they were during the dot-com bust, which helped spark the last recession. This time around, there is no tech bubble to burst. So although corporate customers are temporarily putting projects on hold and delaying upgrades to weather the economic storm, Minton said that overall, "businesses are still optimistic about technology."
What do you think? Post your comments below.
An article in yesterday's Austin American-Statesman says the fourth quarter could be even more disappointing than technology vendors already had expected. Businesses are cutting back spending by putting off equipment purchases and upgrades and laying off workers. Even software, considered a safer bet because it helps companies automate costly steps, is also likely to take a hit, the Statesman noted.
"It's inevitable that all technology companies, with varying degrees, will be running into the same thing," Stephen Minton, an analyst for research firm IDC, told the newspaper. "The reaction of businesses to the economic crisis is to stop spending money."
Technology makes up a big chunk of corporate spending. Of the total amount of money that U.S. businesses spend on fixed investments, which includes offices and factories, about 28 percent goes to computer and communications equipment and software, according to Commerce Department data analyzed by Bartels.
IDC expects very little growth in overall tech spending for the rest of the year and through most of 2009. Spending in the U.S. and Europe probably will be roughly flat, while emerging markets should continue to grow.
"One thing we learned in 2001, a lot of people in software said the recession won't have an effect," Minton told the newspaper. They were wrong. "What businesses do when a recession starts is they stop spending altogether."
The bright spots in the sector: Information-technology services and outsourcing — helping companies manage their computing — tend to be the least affected in a downturn, he added.
It is clear that a recession will hurt the tech sector, but things don't figure to be as bad as they were during the dot-com bust, which helped spark the last recession. This time around, there is no tech bubble to burst. So although corporate customers are temporarily putting projects on hold and delaying upgrades to weather the economic storm, Minton said that overall, "businesses are still optimistic about technology."
What do you think? Post your comments below.
Subscribe to:
Posts (Atom)