Thursday, April 23, 2015

Differences between Architecture Roles

Source : Click Here

People often confuse or don't find any difference between various Architect roles.However each role have their unique role to play in day to day work.In this article they have picked out the roles of Solution Architect,Technical Architect and Enterprise Architect.




There are three dimensions or axes that constitute the architecture roles:
1.Life cycle disciplines:Set of activities performed in a particular stage of project or program .
2.Level of details:Amount of specific details required to fulfill the objectives of the role.
3.Focus:A particular work stream where the above are relevant to.


Technical Architects:Main focus is on implementation technology.Works across projects and pays attention to the complete software lifecycle of the product.Requires hands-on knowledge on technology thereby specializing in a particular stream.
Solutions Architects:Overlooks the technical integrity and consistency of solutions in a project.The solution architect acts as a Project Manager for the project along with perceiving the technology related risks involved in the project.
Enterprise Architects:Concerned with the holistic view of the Information and technology within the enterprise.Responsible for whole set of life-cycle disciplines and prospective IT.


Technical Architect works within a solution,Solution Architect translates a problem to a solution and finally Enterprise Architect defines which problem need a solution.This articles gives a clear view of what each role comprises of.Informative for many who might not have direct experiences working with or for such roles.



Sunday, April 12, 2015

Business Architects:Do not start with strategy

Source: Click Here

 "Business architects start with the strategy of an organization.  They take that strategy and map it to the capabilities of the enterprise to clarify the capabilities that must be improved or matured in order to effectively execute."


This article ponders on how business  takes on working on strategy first which might not be fruitful.The best thing would be to have a business model in place and then work on building the strategy.The strategy is meaningful within context.Analyzing the organization's business model helps to determine what to expect and how to frame the needs of the business.This is where Strategy comes in role.The strategy directs the business model to help achieve the future business expectations.


     image

Strategy depicts one of the two possibilities:
  • Incremental improvements in the business model (cut costs a little more.  Improve customer satisfaction a little more.  etc), or
  • Adding a new business model to the organization.
I agree that understanding the value of business is important and to layout a model to be able to put in place a methodology to work it out.But at the same time it might not work for all organizations.A intuitive and calculated decision might help in determining whether strategy comes first or after adopting a business model.

Sunday, April 5, 2015

Launch of the Cybersecurity Framework

Source: Click Here

The Obama administration announced the launch of the cyber security framework.The framework is a key deliverable from the Executive Order on “Improving Critical Infrastructure Cybersecurity”  that President Obama announced in 2013.

The framework is said to provide existing global standards and practices to help organizations understand,communicate and manage their cyber risks.For the organizations that do not know where to start it serves as a roadmap.It also provides a better way to communicate with their CEO's and suppliers about cyber risks.

The framework components(the framework core,profiles and tiers) reinforces the connections between business drivers and cyber activities.The Framework Core is a set of activities and informative references-The activities are grouped into five segments:Identify,Protect,Detect,Respond,Recover.The Profiles can help organizations align cyber activities with business requirements,risk tolerances and resources.The Tiers provide a way to view their approach and processes for managing cyber security which range from Tier 1 Partial to Tier 4 Adaptive.

It is a good approach to help organizations build their security infrastructure.The Program is a voluntary one which helps organizations connect with companies and share experiences .The Critical Infrastructure Cyber Community (C3) Voluntary program will help increase awareness.It is interesting to find out how many organizations have got involved in this move and what effects it has brought to an organization.I will need to search more on this to see the effect.I am sure this is beneficial for many companies especially start-ups and small scaled to get support and build upon a framework for securing their environment.

Defining an Enterprise-wide Security Framework


Source: Click Here

This article defines the knowledge management system -the Enterprise  Security Architecture System  (ESAS) developed by PriceWaterhouseCoopers.The ESAS is primarily built upon the PPT(People,Policy & Technology).

What is PPT methodology?

PPT methodology can be depicted in the
form of the venn diagrams showing the 
controls as three core elements. If the issue is broken down into the three core elements, action items can be determined for each core element. In this manner, control coverage can be moved from one element to two, and ultimately to coverage by all of the elements.

Understanding the Security Framework:

The Information security framework provides the overall model for developing comprehensive security programs.The framework illustrates an enterprise approach for security.
The key elements, also referred to as the "Four Pillars" to Information Security, include:
  • Solid Senior Management Commitment
  • An overall Security Vision and Strategy
  • A comprehensive Training and Awareness Program
  • A solid Information Security Management Structure including key skill sets and documented responsibilities
                     

This indeed serves as a good base to frame a security model for any organization.Keeping the phases as a guideline to incorporate the business functions and levels of security will serve to make a difference in protecting the organization's valuable assets and enable the security team to work on improving every bit of the model.                                                                                                                         
          

Sunday, March 15, 2015

Seven Data and Information Security Mistakes

Source: Click Here

In an IT organization security is the top priority and every organization is working towards building a 100% secure network.99.9999% still means the organization is not secure.This article talks about the common security mistakes seen in an organization.It is usually the common traps that can be easily avoided.

  1. Securing Only Networks:It is also important to secure the endpoints.
  2. Not aligning Security with Business Goals:Seccurity projects are just addressed as one among a workflow but not considered to be a revenue generating project so overlooked most of the times.
  3. Not changing passwords often : or Tracking Access:Passwords need to be changed especially when there is any change in the organization like when an employee leaves the company.
  4. Not knowing where the Data is:It is essential to know the data location to know what kind of threats can harm it.Also to know the security efforts put in.
  5. Not vetting encryption used by vendors:The U.S. Government requires FIP-140-2 encryption for data and validated.The government considers data encrypted by this method as plain text which can pose unnecessary risks.
  6. Neglecting Data Governance:Everyone needs to know who can access what data.Policies should be reviewed and followed on how to control the data.Also evaluate the entire process.
  7. Not Disclosing Data Breaches:It is very important to let everyone involved with the organization to know about such breaches.It enables everyone to be more cautious and work together to protect 
I think the main aspect of making sure to disable accounts from previous employees and make sure the applications passwords need to be changed.The company I worked previously never changed passwords and always wondered how this could not be a addressed in anyway.But once it got acquired to a bigger company they had password policies but still employees never got the concept of security is my feel.

Sunday, March 8, 2015

Data Virtualization

Source: Click Here

This article highlights the basics of data virtualization to somehow who wants to know about it and also mentions about the capabilities.Data virtualization is the process of handling data without diving into the technical aspects of it.The technical aspects of data include the location,storage structure,technology involved.It is used to describe any approach to data management that allows applications to retrieve and manipulate data.

Data Virtualization Illustrated to help visualize the actual process:

                         what_is_data_virtualization.png

Data virtualization uses the concept of data abstraction which is the process of reduction of characteristics to make it a simplified representation of the whole system.This methodology helps in helping make decisions faster,improves operational efficiency,quality,increases revenue and lowers cost.

Data Virtualization enables the technology with the following capabilities:
  1. Abstraction
  2. Virtualized Data Access
  3. Transformation/Integration
  4. Data Federation
  5. Flexible Data Delivery
Data virtualization also addresses requirements for data security,data quality,governance and optimization.I have worked on data from a technical support side and have seen the usage of data virtualization.We have applications like an administrative front end which enables us or the users to look at their managed data and make changes by simply clicking,modifying and importing data for updates similar to ETL functions.The back end is where data virtualization gets into effect by the developers handling the database design aspects.This is very helpful to customers and other people who want to have front end access but also be able to control data to some extent.I see this technology to be widely used in various forms across different organizations.


Reference:

Tuesday, March 3, 2015

Enterprise Resource Planning (ERP)

Source: Click Here

This article brings out the simple features of Enterprise Resource Planning( ERP) and how it can be visualized.In a nutshell ERP software tries to integrate all different departments and functions of an organization into a single computer system to serve the various needs of the departments.The purpose of this system being the free flow exchange of information across the various business functions within the organization and connects with outside stakeholders.It seems a herculean task to get all individual units on board on a system.But with the help of an integrated  approach this can be made feasible.
Below one can see the differences between a non-integrated system and an integrated one.


                                    Enterprise Resource Planning

ERP system is a complex one during the implementation phase but by spending quality time and investment it adds a lot of value to the business.ERP helps in accurate forecasting,integrating leading to effective communication and planning.ERP can be expensive initially but once the system is running can expect to minimize costs and be effective.However one needs to take precautions to make sure ERP is done the right way otherwise might cost a fortune.