As the economy starts to turn around, how good will the recovery be? Most large companies will see the most gains in customers and revenue. Many CIO's at large companies will see their budgets increase in the next 6 months and hiring will increase. Executives at large companies are confident that business will improve dramatically.
Along with increase budgets companies are spending money on upgrading network and server platforms especially in relation to virtualization. At smaller companies, budgets are increasing but at a slower pace. Typically 50% of small business plan on spending on information technology projects and hiring will increase at a slower rate than their large counter parts.
As economic condition improve, depending on your sector, positioning yourself to take advantage of increase budgets and new projects can help improve your upward mobility.
Information technology, IT Consulting, the world through my eyes and other insightful commentary!
Thursday, April 29, 2010
Monday, April 19, 2010
Google -- America's best company
Google search and documents has revolutionized the internet. Most people use Google search to find any thing and every thing on the internet. The search engine has lead to greater profits and higher stock prices for Google. Has innovation made Google America's best company?
In many ways Google business approach is less is more has been very effective. The Google home page is very simple and loads fast, prompting users to make Google their default home page. This switch helped introduce iGoogle personalized home page and eventually Gmail. Gmail itself became a game changer because user received 1GB mailbox t no additional change and the competition has to follow suit
Google innovation has continued to lead the way with Google Apps such as: Google talk, Adsense, Wave, Earth, Android, and Google 411 which has evolved into the Google cloud. Google is betting a higher number of users will do business and work in the Google cloud as oppose to on their own desk top.
As more businesses move toward a collaboration platform, Google is updating Docs to be a all-in one cloud based collaboration. Google Docs is being designed to take Microsoft office documents and convert them into Google Docs with out losing Office formatting. Supposedly, two or more people can be editing various documents with very little delay time, enhancing real time collaboration
Google Apps have proven to be stable enough for business to move their entire email systems to Google's enterprise email solution. Google email is $50 per user a year, and Docs are included. Google Apps included email, word processing, spreadsheet, and presentation suite.
Innovation and good applications and services has made Google a success. I am currently testing Google suite of applications and will review.
In many ways Google business approach is less is more has been very effective. The Google home page is very simple and loads fast, prompting users to make Google their default home page. This switch helped introduce iGoogle personalized home page and eventually Gmail. Gmail itself became a game changer because user received 1GB mailbox t no additional change and the competition has to follow suit
Google innovation has continued to lead the way with Google Apps such as: Google talk, Adsense, Wave, Earth, Android, and Google 411 which has evolved into the Google cloud. Google is betting a higher number of users will do business and work in the Google cloud as oppose to on their own desk top.
As more businesses move toward a collaboration platform, Google is updating Docs to be a all-in one cloud based collaboration. Google Docs is being designed to take Microsoft office documents and convert them into Google Docs with out losing Office formatting. Supposedly, two or more people can be editing various documents with very little delay time, enhancing real time collaboration
Google Apps have proven to be stable enough for business to move their entire email systems to Google's enterprise email solution. Google email is $50 per user a year, and Docs are included. Google Apps included email, word processing, spreadsheet, and presentation suite.
Innovation and good applications and services has made Google a success. I am currently testing Google suite of applications and will review.
Monday, April 5, 2010
How good is the IPad, really cool or just hype?
The IPad is a pretty cool device for causal browsing, responding to emails, watching Videos, but very limited if you actually want to get some work done. I would consider buying and IPad for entertainment purposes only.
The things I like about the IPad:
Overall, nice product and good design.
The things I like about the IPad:
- Great screen which is high definition and how thin the device is, "remarkable".
- Touch screen capability is very similar to the Ipad-Touch which is cool
- I was concerned about the virtual key board, but it seems to work perfectly
- Great convience
- The screen is overly glossy and is difficult to view in sun light and certain lighting situations
- Lack of storage space of documents
- Limited USB support.
Overall, nice product and good design.
Friday, April 2, 2010
How good is your credit and is your data safe?
Having good credit along with the gold plated credit card has been a good thing. The gold card gets you privileges and access to the goods things in life, "I really have arrived"! Assuming your credit is good and has not been affected by the recession, how safe is your credit card # and data?
Based on various large security breaches, such as the infamous Heartland breach, it time to improve credit card security.
To improve the safety of consumer credit card data, Ma has implemented The Massachusetts Data Protection Law which required companies to take additional steps to secure data. These measure help in Ma, but does not solve the problem of credit card theft.
After the Heartland security breach, the House introduced the Data Breach Notification Act. The law requires persons engaged in interstate commerce and in possession of sensitive data to disclose breach of such information.
What can be done to improve credit card security? Many other countries outside the US have implemented smart card technology. The US government must at some point, mandate credit card companies to implement smart cards. Smart card technology could have helped prevent the Heartland breach, where intruders hacked into systems used to process millions of card transactions affecting 100,000 of merchants. To prevent the data from being compromised, smart cards generate one time response to financial transaction requests from banks, so the data stream is good for one transaction.
Implementing smart cards is a must, and transferring the liability to credit card issuers from merchants can discourage or prevent fraud. Culpability for fraud should be determine by the courts thus giving credit card companies the incentive to implement smart cards and chip and pin technologies.
Consumers need to be responsible consumers, keep your computer security up to date, and check for virus / malware on a regular basis. Checking your credit card statements and credit reports is advisable. Enjoy your well earned privileges, live large.
Based on various large security breaches, such as the infamous Heartland breach, it time to improve credit card security.
To improve the safety of consumer credit card data, Ma has implemented The Massachusetts Data Protection Law which required companies to take additional steps to secure data. These measure help in Ma, but does not solve the problem of credit card theft.
After the Heartland security breach, the House introduced the Data Breach Notification Act. The law requires persons engaged in interstate commerce and in possession of sensitive data to disclose breach of such information.
What can be done to improve credit card security? Many other countries outside the US have implemented smart card technology. The US government must at some point, mandate credit card companies to implement smart cards. Smart card technology could have helped prevent the Heartland breach, where intruders hacked into systems used to process millions of card transactions affecting 100,000 of merchants. To prevent the data from being compromised, smart cards generate one time response to financial transaction requests from banks, so the data stream is good for one transaction.
Implementing smart cards is a must, and transferring the liability to credit card issuers from merchants can discourage or prevent fraud. Culpability for fraud should be determine by the courts thus giving credit card companies the incentive to implement smart cards and chip and pin technologies.
Consumers need to be responsible consumers, keep your computer security up to date, and check for virus / malware on a regular basis. Checking your credit card statements and credit reports is advisable. Enjoy your well earned privileges, live large.
Wednesday, March 31, 2010
Virtualization and Storage
My storage
As I go through the process of building my virtualized environment, one of my key considerations is storage. We are leaning towards a terabyte SAN storage device to improve the speed of back ups and virtual machines (VMS) can be moved faster. The ability to quickly deploy VMS is the key to quick disaster recovery.
As I go through the process of building my virtualized environment, one of my key considerations is storage. We are leaning towards a terabyte SAN storage device to improve the speed of back ups and virtual machines (VMS) can be moved faster. The ability to quickly deploy VMS is the key to quick disaster recovery.
System Management
To ease the management of VMS you should create VMS IDs. The use of VMS IDs allows for control of mobility from server to server and enforce policies automatically. The management tool for Vmware VMS is hypervisor. Management tools become critical because VMS are moved to different servers and taken off line which makes management tricky.
In addition to managing VMS, you must successfully manage all of your licensing. Licensing has been traditionally been tied to per user or per CPU based pricing, but this model does not work with virtual machines. Many vendors must update their licensing models to account for VMS. VMS builds must be accurately tracked to control additional licensing cost associated with OS instances and applications.
Security in a virtual environment is key as the challenges and stakes are high. Any management tools such as hypervisor must be secured properly to protect VMS that ride below. Additionally all your SAN builds become critical as the house all VMS.
Once you have your virtual environment up and running you can decommission servers that have been replaced with VMS. This ultimately saves on power, cooling, and management costs. If you were ever to decommission a virtual server, you would have to find it; and justify the reasoning.
As Virtualization becomes a reality, the key components that need to be monitored are: application availability, resource utilization and allocation, security, storage, and redundancy. The journey has began and is well worth it.
Monday, March 29, 2010
Virtualization Planning -- disaster recovery and power
I have been reviewing a Virtualization plan for the last 12 - 18 months and I getting close to implementation. The key goals of the Virtualization plan are: consolidation of servers, disaster recovery, reduced power consumption, and fault tolerance.
Virtualization is attractive because it reduces sprawl. The key component of Virtualization is the deployment of virtual machines. Licensing of software running on each virtual machine must be managed and in compliance.As all o the corporate servers become virtualized, down time and disaster recovery become more efficient and cost effective.
Lines of management of virtual servers can become blurred as far as who CIO, CTO, data center, systems manager takes ownership. It seems to be dependent on who is making the decisions regarding deployment.
My current Virtualization plan is as follows: assessment of current resource utilization patterns, security implications, internal and external service requirements, and business disaster recovery plans.
I am in the process of testing Virtualization and determine which technology to use base on cost effectiveness (VMS or Hyper V). Since VMS is the most mature product and easily deployed, I probably will start on this track. When VMware and virtual machines where first deployed there were basic issues with vendors related to licensing, compliance, reliability and performance. During the testing and deployment phase, each of these aspects must be reviewed and responsibility for virtual machines (VMS) must be determined. In some organizations the responsibility for VMS does not fall under I.T., but business managers or some other non-technical discipline. I am in the process of deploying a test virtual server in my environment. Stay tuned as I update my progress!
Virtualization is attractive because it reduces sprawl. The key component of Virtualization is the deployment of virtual machines. Licensing of software running on each virtual machine must be managed and in compliance.As all o the corporate servers become virtualized, down time and disaster recovery become more efficient and cost effective.
Lines of management of virtual servers can become blurred as far as who CIO, CTO, data center, systems manager takes ownership. It seems to be dependent on who is making the decisions regarding deployment.
My current Virtualization plan is as follows: assessment of current resource utilization patterns, security implications, internal and external service requirements, and business disaster recovery plans.
I am in the process of testing Virtualization and determine which technology to use base on cost effectiveness (VMS or Hyper V). Since VMS is the most mature product and easily deployed, I probably will start on this track. When VMware and virtual machines where first deployed there were basic issues with vendors related to licensing, compliance, reliability and performance. During the testing and deployment phase, each of these aspects must be reviewed and responsibility for virtual machines (VMS) must be determined. In some organizations the responsibility for VMS does not fall under I.T., but business managers or some other non-technical discipline. I am in the process of deploying a test virtual server in my environment. Stay tuned as I update my progress!
Sunday, March 28, 2010
Digital Crime scene forensics and Computer espionage
Computer digital forensics is an emerging field of science to help track and capture cyber criminals. Now that social media sites and the web are a part of our daily life, protecting and securing cyberspace has taken on greater importance.
Computer forensics uses scientific methods to solve questions related to law and computer hacking and possible espionage. Since computer and technology evolves so quickly, it is very difficult for security experts and law enforcement to standarize digital forensic tools and procedures.
All of the computer data and various technologies flow over computer networks which requires network forensics. To improve network security and prevent cyber crime, data and evidence that passes over the network must be analyzed using network forensic tools and procedures.
In the years to come solving computer related crimes will require computer and network forensics and this data will be common component of trail cases. Developing techniques and standards to handle this data is vital to security and fairness of the judicial system.
Network security and cyber crime prevention is tied to collecting and analyzing network data. This is a difficult task as the data typically resides on internet service providers servers. In many case you need a sapena to get access to data. Many companies are implementing out bound content monitors so they can analyze data that is leaving their network.
In the legal system, the dilemmas revolves around who owns the data, which is considered evidence. Creating standards for network forensics and evidence gathering could solve wide ranging legal issues. Currently, security experts and developers are designing software and hardware solutions that will improve overall computer forensic sciences.
Even though a de-facto forensic standard has not been developed, there are some reasonably good data forensic best practices:
Best Practice Standardization issues
Computer forensics uses scientific methods to solve questions related to law and computer hacking and possible espionage. Since computer and technology evolves so quickly, it is very difficult for security experts and law enforcement to standarize digital forensic tools and procedures.
All of the computer data and various technologies flow over computer networks which requires network forensics. To improve network security and prevent cyber crime, data and evidence that passes over the network must be analyzed using network forensic tools and procedures.
In the years to come solving computer related crimes will require computer and network forensics and this data will be common component of trail cases. Developing techniques and standards to handle this data is vital to security and fairness of the judicial system.
Network security and cyber crime prevention is tied to collecting and analyzing network data. This is a difficult task as the data typically resides on internet service providers servers. In many case you need a sapena to get access to data. Many companies are implementing out bound content monitors so they can analyze data that is leaving their network.
In the legal system, the dilemmas revolves around who owns the data, which is considered evidence. Creating standards for network forensics and evidence gathering could solve wide ranging legal issues. Currently, security experts and developers are designing software and hardware solutions that will improve overall computer forensic sciences.
Even though a de-facto forensic standard has not been developed, there are some reasonably good data forensic best practices:
Best Practice Standardization issues
- Preservation How is the data preserved (media) and by who
- Identification What tools should be used to identify data (suspicion)
- Extraction How accurate is the data being extracted (purpose)
- Documentation How are finding documented and archived (quantity)
- Interpretation How is the data interpreted and by who (technology)
While researchers and developer create new software solutions, there are no concrete standard to test against. Typically the National Institute of Standards and Technology (NIST) creates standards to test tools used for network forensics, but there has been no clear definition of what forensic tools should do.
As new network forensic tools emerge (commercial and fee) manufacturers and developers should partner with standards organization such as (NIST), to create functional standards for network forensics. Standardized tools and methods will allow researches, security experts, legal professionals to use forensic tools prevent and monitor various security breaches and computer crimes.
Subscribe to:
Posts (Atom)






