Jumat, 10 April 2009
Industry Analysts and Federated Identity
I was thinking that I haven't worked with any industry analyst firm in a long term in terms of allowing them to create a case study on things we do well. I wonder if there is interest in learning about what me and my employer are up to in the world of federated identity?

Explaining Security to Business People
The vast majority of IT security professionals in large enterprises don't usually interact with the business community and therefore don't know how to convince them that well-established encryption algorithms, well-established key exchange protocols, etc, will be much better than whatever homebrew scheme they cook up themselves in a couple of meetings...

Not invented here is a common attitude in many enterprises when it comes to many things but security is even more challenging in that it requires others to acknowledge that their thinking is incomplete and adhoc schemes are not enough before they are willing to spend time and effort to quantify additional requirements.
Security is a business issue and many decisions should be made by business people, however there is no framework that helps business people who generally aren't as passionate as IT in seeking enlightenment to participate and make informed decisions. Imagine what would happen if business customers came up with their own scheme to implement either disaster recovery and/or high availability? They will probably come up with ways that are either expensive and ineffective, or simple and ineffective. There are many ways to handle HA/DR requirements but usually you have to specify the need before you can decide how to do it.
So, what are security professionals not doing that HA/DR types have figured out? Maybe this can be a conversation at an upcoming OWASP conference?

Not invented here is a common attitude in many enterprises when it comes to many things but security is even more challenging in that it requires others to acknowledge that their thinking is incomplete and adhoc schemes are not enough before they are willing to spend time and effort to quantify additional requirements.
Security is a business issue and many decisions should be made by business people, however there is no framework that helps business people who generally aren't as passionate as IT in seeking enlightenment to participate and make informed decisions. Imagine what would happen if business customers came up with their own scheme to implement either disaster recovery and/or high availability? They will probably come up with ways that are either expensive and ineffective, or simple and ineffective. There are many ways to handle HA/DR requirements but usually you have to specify the need before you can decide how to do it.
So, what are security professionals not doing that HA/DR types have figured out? Maybe this can be a conversation at an upcoming OWASP conference?
Kamis, 09 April 2009
Are you married to Enterprise Architecture?
If you really love someone, then you'll stick around and take advantage of the ways they're wonderful, and you'll try to ignore, improve, or mitigate the ways they're awful. But if your husband starts slapping you around, it's time to leave. Too many folks let themselves be slapped around...

You have a certain realtionship with your employer. You also have a relationship with your lover, your children, and your future. When the interests of these parties conflict, this may manifest itself as dissent within one or several of your relationships. Sometimes we are all consumers of a slow poison that is toxic to everything we do.
So, if enterprise architecture is about people, processes then tools, in that order then how do we determine when we should marry things together and when things should be separated. So, if we were to focus on the people aspects then it would probably mean that we need to focus on poor people management which spreads without conscious effort and can slowly poison others.
Poor managers are poor managers for a reason: fear, distrust, ignorance, etc. Over time, they will actually make decisions that increase these qualities in other people they deal with. This is apparent in most interactions with coworkers, but is exceptionally apparent in personnel decisions, with poor managers hiring, promoting, and otherwise rewarding subordinates with dysfunctions that complement their own. The classic example is trusting only a "yes-man", who will agree with every decision you make regardless of the quality of the decision itself.
In addition to rewarding and spreading mismanagement, this will also drive out motivated, conscientious intelligent workers, who will at some point realize it makes more sense to focus on organizational change management over committing to other business-oriented strategies. Through this phenomena, an organization can actually get less competent over time, even with other inputs (size, revenue, business climate, etc.) remaining constant.
Mismanagement can destroy an entire organization, but it can happen so slowly that the managers might not notice it or are likely to misunderstand why the organization is failing. So the feedback loop is not very tight, and they can either avert their gaze from the growing problem or they can find scape goats.

You have a certain realtionship with your employer. You also have a relationship with your lover, your children, and your future. When the interests of these parties conflict, this may manifest itself as dissent within one or several of your relationships. Sometimes we are all consumers of a slow poison that is toxic to everything we do.
So, if enterprise architecture is about people, processes then tools, in that order then how do we determine when we should marry things together and when things should be separated. So, if we were to focus on the people aspects then it would probably mean that we need to focus on poor people management which spreads without conscious effort and can slowly poison others.
Poor managers are poor managers for a reason: fear, distrust, ignorance, etc. Over time, they will actually make decisions that increase these qualities in other people they deal with. This is apparent in most interactions with coworkers, but is exceptionally apparent in personnel decisions, with poor managers hiring, promoting, and otherwise rewarding subordinates with dysfunctions that complement their own. The classic example is trusting only a "yes-man", who will agree with every decision you make regardless of the quality of the decision itself.
In addition to rewarding and spreading mismanagement, this will also drive out motivated, conscientious intelligent workers, who will at some point realize it makes more sense to focus on organizational change management over committing to other business-oriented strategies. Through this phenomena, an organization can actually get less competent over time, even with other inputs (size, revenue, business climate, etc.) remaining constant.
Mismanagement can destroy an entire organization, but it can happen so slowly that the managers might not notice it or are likely to misunderstand why the organization is failing. So the feedback loop is not very tight, and they can either avert their gaze from the growing problem or they can find scape goats.
Langganan:
Postingan (Atom)