Showing posts with label CoBIT. Show all posts
Showing posts with label CoBIT. Show all posts

Thursday, June 9, 2011

Startups vs.best practices... can't we all just get along?

Transitioning from CIO to CEO has been an interesting move for me.  This is not my first time as a CEO, but my role as CEO of Vigilant was short, and Vigilant was an IT services company, so it was still chief of IT services.  However, as much as I dog on ITIL, CObIT and other industry frameworks for being too esoteric and vague, I always have appreciated and applauded the principles and intents.  As SMAK has launched from thought to design to code to hardware, my experiences and training in lifecycly management has served me well.   Our Strategy phase quickly incorporated what our resources and capabilities could be, would be, and should be.  Since I have the unique opportunity to start this IT operations from scratch, I wanted to get our LifeCycle management clear and correct from the start.

Just because we are a lean startup doesn't mean we need to run in chaos.  I certainly am not going to cast all hard lessons learned in the trash.  I know that if a disparate development team is not given a solid and stable platform for code migration, our IT ops will be a mess.  My ITIL students and past clients have heard this expression a million times from me.  If you want to cleanse the pond, you must clean the streams that feed it.  In other words, if you want a clean IT operations platform, you must have solids standards and architectures in place for all involved to work from.  Breaking down the DEV/QA/UAT/Prod barriers is a challenge.  Typically it is based on rights and security.  Access control can be a nightmare and causes much of this angst.  By setting up boundaries and protocols up-front, the streams will stay clean and the pond will be a source of value.

So here is my strategy straight out of SMAKs operation guide on how I plan to allow autonomy and control co-exist.

User Setup and Configuration:

To secure the environment we will utilize a strategy of layered access to systems. Each environment will utilize the same set of layers with a name denoting their environment.

To gain physical access to systems (keyboard, SSH, Remote windows) there will be a user created.
Once physical access is gained you will need to change user or run-as a user with rights to access either system settings / application data (php, xml files / database settings / database information.
Access controls are organized in to functional groups based on assetts. Asset types fall into 5 categories:
Production – Production environment with real users and customers. Needs to exhibit high service warranty.
Demo – Production+ build version of our site with fake data that we will use for demonstration at events, webinars, and other marketing events. (Production+ means at least production vesion with potentially new features to demonstrate functionality)
UAT – User Acceptance Testing Environment– QA Build version signed off on by production release team for Security; Availability; Performance testing. Now awaiting user interaction; regression; usability and design; product marketing sign off.
QA – Quality Assurance Environment – Build version that has been signed off by development team and gone through integration testing. Testing in this environment will focus on Functionality; Security; Performance; Availability; Installation; Recovery. Training to production release team will happen at this build stage. Sign off by Product Management.
Dev – Development Environment – Dynamic build versions be created in this environment with 2 core focus areas

  1. InnoDev - New product development focused on publishing new feature sets and requirements from Product Marketing team.
  2. ProbDev – Problem Management environment focused on production snapshots for replicating issues found in production.

The following table lists the usernames:  {obviously cleansed and changed for security purposes}  Key here is to create naming conventions that make it ease for each lifcycle to be identified and controlled.  This will make it a lot easier with building RACI models in your CMS map.
User Type Production User Name Demo User Name UAT User Name QA User Name Dev User Name
Group Name




Enterprise Cloud Administration




Access User




System Admin




Application Administration




Database Administration






Data Access User
(can see datapoint for customer information)





Customer Service Access
(access to configuration and registration info)





Monday, June 14, 2010

ITSM Weekly the Podcast (Week19) Guest: Robert Stroud

Very exciting week for me on ITSM Weekly the Podcast, our special guest was Robert Stroud.

In 2007 when I was working for a CA partner I had the opportunity to meet an individual that really impressed me with his vision of the ITSM market.  I've since seen Robert speak several times and had a chance to have a conversation over lunch at the 2009 ITSMF Academic summit.  He has a great passion for the industry, and does  lot for the community through the membership organizations.
He is also one that has crossed over from technology to marketing, which is my own personal career path.
Please enjoy as I did this weeks podcast with Robert and definitely check out the show notes from ServiceSpehere:
http://www.servicesphere.com/blog/2010/6/13/itsm-weekly-the-podcast-week-19.html

ITSM Weekly The Podcast (Week 19) from ServiceSphere on Vimeo.


Show Hosts:
Christopher Dancy
Matt Beran
Matthew Hooper .




Wednesday, June 9, 2010

ITSM Weekly the Podcast (Week18) Special Monday Edition

This week we spent some time talking about user groups.  HDI, ISACA, ITSMF and SIM (Society of Information Management)

Time is a precious commodity.  It's our single greatest limited resource, and thus we must find ways to make it as valuable to us as possible.  I try to find ways to spend my time so I can have more time.  User groups have been a great way for me to accomplish this.  By getting to know others talents, resources, needs, helps us see how we can accomplish outcomes by leverage.  Chris relates it as NFL , Networking Fun and Learning.

We recorded this weeks podcast on a Monday, and for some reason it caught us a lot more giddy with a little bit of a sensitive side.  Enjoy the podcast and as always tell me what you think we should be covering and how we can improve.

Note: our new podcast editor did not bleep this recording, so there are a few swears in it.

Show notes from www.servicesphere.com
http://www.servicesphere.com/blog/2010/6/8/itsm-weekly-the-podcast-week-18.html



ITSM Weekly The Podcast (Week 18) from ServiceSphere on Vimeo.

Show Hosts:
Christopher Dancy
Matt Beran
Matthew Hooper .



Week 18 Topics:  Episode 1982 (well episode 18)

Tuesday, February 16, 2010

ITSM Weekly The Podcast - (Week 2)


What happens when a CIO, a Service Desk Manager and an Industry Junkie Chat Weekly?!
Your Hosts:  Chris DancyMatthew Hooper and Matt Beran
Submit Questions:  Anonymously or Email or Call In: (765) 236-6383

For more info check out "http://www.servicesphere.com/blog/2010/2/15/itsm-weekly-the-podcast-week-2.html"  Otherwise enjoy:

ITSM Weekly The Podcast Week 2 from ServiceSphere on Vimeo.
Show Hosts:
Christopher Dancy
Matt Beran
Matthew Hooper .

Tuesday, July 8, 2008

Service Catalogs are the key to demonstrating Value

What is a Service Catalog? Simply put it is system or documentation that allows people to preview the services they can obtain from you and the expectation they can have of getting those services (time, cost, quality, etc...).
Do we need a Service Catalog? Do you need a resume to get a job? No, but if you want the right job, and want to get paid fairly for the abilities you can bring, and want to set the right expectation, then you will want to have a clearly articulated resume.
Same thing with the IT Service Catalog. If you want the business to appreciate the value IT brings to the organization, and you want to ensure that staff, suppliers, and costs are adequately budgeted for, then you must present to the business your capabilities. The Service Catalog is where you will publish and present what IT will do, and thus what they will not do. At face the business will not necessarily want IT to have this. If you do not currently have an IT Service Catalog, then currently the Business can ask you for whatever they want, and IT has to scramble to either try and justify why they can't do it, or figure it out. If there is no cost allocation in place for IT resources, then in the eye of the Business stake holder IT is a free resource, and we all know what the value of free - zero - free has no value.

Thus to really drive the value of IT services, IT must put in place a definitive "what we do, how we do it, and how much it costs" communication platform. More advanced organizations are using this information to build an on-line IT ordering site where people can order account setups, email boxes, new laptops, PDA's and Blackberries, and other enablement services. These sites will typically hang-off the Service Desk platform so that people can get services ordered without having to interact with a service request person. This can lead to tremendous cost savings and it also leaves the business in more control. So many organizations are finding the business more willing to fund the Service Catalog under the umbrella of Self-Service optimization and cost efficiency.

Next blog: "Is the customer always right?" I'll share some tech support stories to show the difference between a customer focused support person and a person who answers the phone and follows a script.