Thursday, June 9, 2011

Startups vs.best practices... can't we all just get along?

Transitioning from CIO to CEO has been an interesting move for me.  This is not my first time as a CEO, but my role as CEO of Vigilant was short, and Vigilant was an IT services company, so it was still chief of IT services.  However, as much as I dog on ITIL, CObIT and other industry frameworks for being too esoteric and vague, I always have appreciated and applauded the principles and intents.  As SMAK has launched from thought to design to code to hardware, my experiences and training in lifecycly management has served me well.   Our Strategy phase quickly incorporated what our resources and capabilities could be, would be, and should be.  Since I have the unique opportunity to start this IT operations from scratch, I wanted to get our LifeCycle management clear and correct from the start.

Just because we are a lean startup doesn't mean we need to run in chaos.  I certainly am not going to cast all hard lessons learned in the trash.  I know that if a disparate development team is not given a solid and stable platform for code migration, our IT ops will be a mess.  My ITIL students and past clients have heard this expression a million times from me.  If you want to cleanse the pond, you must clean the streams that feed it.  In other words, if you want a clean IT operations platform, you must have solids standards and architectures in place for all involved to work from.  Breaking down the DEV/QA/UAT/Prod barriers is a challenge.  Typically it is based on rights and security.  Access control can be a nightmare and causes much of this angst.  By setting up boundaries and protocols up-front, the streams will stay clean and the pond will be a source of value.

So here is my strategy straight out of SMAKs operation guide on how I plan to allow autonomy and control co-exist.

User Setup and Configuration:

To secure the environment we will utilize a strategy of layered access to systems. Each environment will utilize the same set of layers with a name denoting their environment.

To gain physical access to systems (keyboard, SSH, Remote windows) there will be a user created.
Once physical access is gained you will need to change user or run-as a user with rights to access either system settings / application data (php, xml files / database settings / database information.
Access controls are organized in to functional groups based on assetts. Asset types fall into 5 categories:
Production – Production environment with real users and customers. Needs to exhibit high service warranty.
Demo – Production+ build version of our site with fake data that we will use for demonstration at events, webinars, and other marketing events. (Production+ means at least production vesion with potentially new features to demonstrate functionality)
UAT – User Acceptance Testing Environment– QA Build version signed off on by production release team for Security; Availability; Performance testing. Now awaiting user interaction; regression; usability and design; product marketing sign off.
QA – Quality Assurance Environment – Build version that has been signed off by development team and gone through integration testing. Testing in this environment will focus on Functionality; Security; Performance; Availability; Installation; Recovery. Training to production release team will happen at this build stage. Sign off by Product Management.
Dev – Development Environment – Dynamic build versions be created in this environment with 2 core focus areas

  1. InnoDev - New product development focused on publishing new feature sets and requirements from Product Marketing team.
  2. ProbDev – Problem Management environment focused on production snapshots for replicating issues found in production.

The following table lists the usernames:  {obviously cleansed and changed for security purposes}  Key here is to create naming conventions that make it ease for each lifcycle to be identified and controlled.  This will make it a lot easier with building RACI models in your CMS map.
User Type Production User Name Demo User Name UAT User Name QA User Name Dev User Name
Group Name




Enterprise Cloud Administration




Access User




System Admin




Application Administration




Database Administration






Data Access User
(can see datapoint for customer information)





Customer Service Access
(access to configuration and registration info)





Wednesday, March 9, 2011

Turning the page...

What is up with Hooper?
After almost 20 years of fixing technology and relentlessly studying ways to optimize it's usage and the people who administrate it, I have finally come to the realization that we are at the tipping point of communication technologies current usefulness, email in particularly.  Technology as we know it is changing, the methods we use to share, collaborate, engineer, design, problem solve, and innovate are creating huge opportunities but also huge human inefficiencies.

Socialized problem solving is enabling creative resolutions to be found at an accelerated pace in some communities.  However for most people the over indulgence in information sharing and connections is causing a social reaction:  Social Stress is the name I am giving it.  It's the constant desire to be in touch, in the know, in the group.  To have connections with the right people, to get the inside information, to be available to all, all the time.

For years I and many colleagues have been suffering from  "Information Overload".  Well, the problem now is "Connection Overload".  Too many connections, too many ways to be connected, too many relationship management tools...  it's too much. What's worse is all these social media tools are inter-connecting, repopulating and regurgitating the noise you didn't want to hear in the first place.

So this is what I am going to try and do:  To ease Social Stress and fix the "Connection Problem".  My business partners and I have teamed up to develop a technology that will allow you to centrally configure your relationships and connections.  Our hope is that with the reduction of noise, applications will become more meaningful, relationships more meaningful, and life more meaningful.  The company is called SMAK - Secure Messaging Alerting and Knowledge

Over the next few months you will see a new website launched called http://www.getsmaked.com where will make available access to a technology that will filter and stream your emails, status updates and group your connections in a super easy and effective way.
Stay tuned...

Wednesday, February 23, 2011

Dazed and Confused - Pink11 revelation

It's 6am Vegas time, and my head is spinning.  I am coming up on day 3 for me of one of my favorite conference venues Pink Elephant IT Service Management.  After years of studying, implementing, consulting and leading ITSM intitiatives and projects I woke feeling like someone had picked my pocket.

WHY IN THE WORLD DO NON-IT COMPANIES HAVE IT SERVICES?
THEY DON'T NEED THEM!
There I said it.  (actually' I've already tweeted it).

Why would I say this?  Me, after standing on soapboxes for so many years.
I don't know if it's the past year of doing the ITSM Weekly Podcast and listening to guests.  Having some gut wrenching discussion internally at Inforonics about our corporate strategy.  Maybe it has been reading the Universal Service Management Body of Knowledge (after reading this post Ian offered users a $50 discount. use Discount code "VigilantGuy" tx Ian) and meeting its author this week Ian Clayton.  I'm sure it's a  bit of all that, but's it's definitely 2 distinct events that have happened in sessions here at Pink.  Which is why this contiues to be one of my favorite venues.

Event #1) After a 45 minute panel discussion on Service Catalog (of which I had the pleasure of being on) the last question of the day was by a women who was frustrated by the inability to have services defined and asked "Besides Email, what are some other IT services".  I then hear each panelist rattle off System after system,  network, storage, etc..   It was clear this panel of Service Catalog (where you write down what the services are for the business) couldn't agree on what a Service is.

Event #2) In a panel discussion moderated by Rob England (aka The IT Skeptic) the topic was the elusive CMDB.  A source of consternation, frustration, and confusion throughout the ITSM industry.  The major point hit again and again: It has to be Service Aligned....  But wait, we can't define what a service is.
As I sat there and listened to the extremely passionate arguments, emotional lessons learned, and even one person honeslty begging for help.

We are trying to put Round Pegs in Square holes.  We are making up a layer that does not need to be there.  The IT Service layer is fabricated to fill a misconceived whole.  Well there is no whole.

Business Models are supported by Operational Models that are managed through systems and processes.  Business Services are the only services a business needs.  These can be supported through systems layer that correlates and integrates assets (technical or not).

Yet, that is not how ITSM community speaks and talks. In the ITSM community if my Business Model is about Hospitality, we still create this thing called Storage Area Network Services.  When did SAN Services become something people buy to get a hotel room.  They Don't!

So if I follow the current thinking on ITSM, I am supposed build and define the SAN Service, put it in a catalog, map it to a CMDB, and present its value to my CEO and ask him for a seat at the table.

If you were CEO, would ask me to sit down?

I can tell you what Captain Arbrashoff would say: "Beat it buddy"

Please tell me your comments or send me a tweet @vigilantguy  I would love to hear your response and thoughts on this.
On to day 3.