Thursday, October 27, 2005

Out Now in Your Online Bookstore

CPA Australia has just released for purchase the IT & Management CoE's publication, IT Governance: A Practical Guide for Company Directors and Corporate Executives. The co-authors were Chris Gillies and Marianne Broadbent of Gartner. I was a member of the steering committee for this publication, and it is in the end a document that we are all proud of.

In particular, Jan Barned - an unheralded contributor but the policy advisor for the IT & M Centre of Excellence - did a good job of keeping us all on track and making sure that it hit the deadlines on time. A mammoth effort to get it there and some very good lessons learned by Jan and for CPA Australia.

The publication is an excellent result, and of course you can buy it here for $A55 (and I know how much effort and time went into it, and it's cheap at twice the price).

Wednesday, October 19, 2005

Chief Information Officers - The Glue That Binds

ZDNet have an article by Steve Ranger called 'CIOs must bridge gap between business and tech'. The essential point of the article is that the role of CIO is not technical, it is about business strategy and implementing that in the technical sphere.

The CIO is responsible for the stewardship of technological resources within a defined architectural framework - and then implementing strategic direction (not technical implementation!) to achieve technological goals.

This echoes the discussion CPA Australia was having recently regarding information technology governance. Keep it simple for the board, and break up the tasks in terms a layman can understand: Keeping It Running, Plan It, Manage It, and Build it. At the end of the day, that's all that's involved in IT (it's a lot more complex than that, technically, but business-wise - that's all that matters.

Wednesday, October 12, 2005

Business Blogging InTheBlack

This week's CPA journal has an article in it - "It's time to Enter the Blogosphere" - in which your humble correspondent is quoted. The article came about partly because of a discussion our Centre of Excellence had regarding blogs and wikis and such like, and our biggest booster Jan Barned suggested the topic to the editor of InTheBlack. And then the genie is let out of the bottle!

The article is also reproduced at Ed Charles' own blog. Another "avid blogger" quoted in the article is Trevor Cook of the PR firm Jackson Wells Morris.

Good to see I'm not the only one out there blogging away to an unconfirmed audience. Corporate blogging on the rise. I am particularly interested in exploring the ideas of using the internal blog for more effective project coordination.

Viva la ITIL Revolution!

Australia's CIO Magazine has recently (well, yesterday) published an article entitled "ITIL Power" by Ben Worthen. This article is a relatively practical and in-depth review of the capabilities of ITIL (Information Technology Infrastructure Library) and when (and when not) to use it.

It's worth comparing and contrasting this perspective with the view from Technology Executive Club in an article by Alcyone Consulting regarding the synergies between CObIT and ITIL.

As I say, ITIL and CObIT are good ways of making information technology "boring", which is a good thing for business!

Tuesday, October 11, 2005

All About Information Taxonomies - Yet Another Blog

Further to the Ark Group presentation on information taxonomies on Wednesday, Ark Group have put forward a moderated forum for the further discussion and comment on Information Taxonomies.

You can click here for further information.

The welcome message is reproduced below:

"Welcome to the Ark Group Taxonomy Forum. Following on from Designing a Business Focused Taxonomy, we felt that it would be useful to start a discussion forum. The way that the discussion and topics progress is entirely up to you - the members.

Ideally, all discussions should be targeted towards particular business issues that you face with your taxonomy project. Please feel free to introduce yourself and organisation and your particular area of interest."

Thursday, October 06, 2005

To make omelettes, you have to break eggs - but do it very, very carefully!

Last week I presented to Ark Group's Business Information Taxonomies Conference on the topic "Understanding the Purpose of Your Taxonomy and Ensuring Business Adoption" at the Avillion Hotel.

My uploaded presentation can be found here.

In case you are wondering, a (very loose) definition of information taxonomy is a way of classifying and categorising the creation of unstructured information in a way that lets you more easily identify what is contained in the document, and how it relates to areas of your organisation. Although this helps with the search process (you can determine at a glance what a document is about rather than full-text searching for it).

One of the interesting things I discovered at the conference was the presentation by Verity on their tools, one of which (Verity Profiler) claims to be able to automatically classify a document into a taxonomy with about 85% accuracy.

The underlying theme of my presentation, however, was that generally people in business are very good at presenting the benefits of an information taxonomy, but are rarely able to really articulate a low-risk methodological approach to actually implementing the information taxonomy (or business classification scheme) in a way that actually has people use it.

So the benefits are fairly clear, but our ability to state how it is to be done, and to convince business management that it will actually achieve real outcomes, is often less clear.

So as I say, to make omelettes, you have to break eggs - but do it very, very carefully in case you break the business too!

Tuesday, October 04, 2005

OpenDocument Standards

ZDNet is reporting on the new OpenDocument standard (approved by OASIS) that may "turn the world inside out" (which, frankly, is one of those phrases to use when hyperbole just isn't enough). It does promise great things, as the promise of sharing documents independently of the application that created them may finally become a reality (although, predictably, Microsoft advises it refuses to support an inferior standard and will accordingly go its own way).

I suspect we shouldn't hold our breath in this regard. However, if there is enough momentum to using it, the potential for open source software applications to really become usable (e.g. OpenOffice) would become very high. I personally use OpenOffice at home and for almost everything I do it is perfectly OK. I do remain sceptical of the great and wonderful features that are packed into Office most of the time - I mean, seriously, does anyone ever use the Version Save feature of Word? And if you do, do you hope and pray it won't corrupt your document?

(PS in case you are wondering what the reason is for the gap in publishing my blogs, the gap is due to the birth of my baby daughter, Olivia Grace on 9th September. Parenthood - it's good for family life, bad for blogging).

Wednesday, September 07, 2005

Good Practice, Best Practice, Leading Methods

You say tomato, I say tomato (say, that doesn't work so well in print). A rose by any other name is just as thorny, that much is certain at least, and there are often objections to the term 'best practice'. Although it is meant to capture practices that are generally accepted by everyone else, and that the 'man on the Bondi tram' might adopt if he thought about it, there are some who consider that 'best practice' is code for 'doing what our competitors did five years ago'. And certainly there are some aspects of this - that 'best practice' is not necessarily 'best', it is just what everyone else is doing.

Still, it's a good place to start, surely, and if it isn't a place where competitive advantage can be gained (even unsustainable competitive advantage) for your business, why bother reinventing the wheel?

I note this recent article at NetworkWorld that discusses ITIL and COBIT, and discusses the two of them as being complementary, and in fact that they can result in more returns when coupled together. Certainly the news that 75% of IT Managers in the United States have plans to implement ITIL, or at least are thinking very strongly about it. When you check the fine print, of course, you realise that it isn't that scientific a study (all those attending a conference on IT Service Management) but it probably provides some interesting flavour of what's going on in the real world.

Tuesday, September 06, 2005

Disaster Recovery Planning Made Simple

Disaster recovery and contingency planning have been highlighted in the past week as the biggest issue since sliced bread started getting mouldy, as Hurricane Katrina hit NOLA hard and fast. In its wake was left the startling realisation that even the richest country in the world can have infrastructure devastated and destroyed by the forces of nature. The cost of the disaster is $US100 billion and climbing, with a significant part of that the IT Infrastructure.

And the week prior to that was the Zotob worm, which shut down Holden’s processing plants for a day (estimated costs: $A6,000,000 and yes, I checked the zeros).

In the IT context, both these events show that there is an increasing reliance upon information technology, and clearly business continuity plans are going to be top of the charts again for a while for our clients. This also comes back to IS Strategy and Governance procedures for clients. The facts bear out the old adage that luck is the residue of good planning – good IS Strategies and Business Continuity planning will help business A survive and business B not.

Probably a future cause celebre fot IT Disaster Planning - although some would perhaps suggest that it has worked too well - has been www.directnic.com, which is an ISP operating in a New Orleans downtown skyscraper that has maintained its connection to the internet throughout the disaster. Its biggest problem now is that it is getting many hits from around the world because people are blogging about it (just as I am now) which is causing some stress on their connectivity.

They have also maintained a blog about the disaster throughout, as reported by The Register and located at /mgno.com.

Interestingly, at least partly because of this blog, the ongoing debate about the issues related to blogs and their journalistic integrity has now tended to swung in favour of the humble blogger who, as johnny-on-the-spot in a time like this, tends to report what they see rather than filter it through the eyes of a journalist - which is both its strength and its weakness, clearly.

Monday, August 29, 2005

Life Is Tough, but it's Tougher when You're Stupid

On Friday I attended (with John Halliday, our Director of IS Audit, and several clients) a presentation by Internet Security Systems on "State of Security: An X-Force Briefing".

This was, to say the least, interesting, and it is fascinating to have a little chink of insight into the cloak-and-dagger side of information security. The presentation was somewhat American - if you are Australian you'll know what I mean, if you're American you'll wonder what the fuss is about. Suffice to say, the presentation was a little militaristic and "X-Files", but it works in getting the message across, and their deep and undying devotion for "moronic hackers" that are "dumb and stupid" is clear. The cloak-and-dagger effect is reinforced through their regular assessment of the internet's security condition: as of this writing we are at "AlertCon 1".

They are clearly doing some good work in the area of operation system vulnerability detection and prevention for their clients. You are rather left with the impression that the only good hacker is a hacker behind bars, but then if you are wanting someone on your side on issues relating to technical IT Security, I don't think you could ask for a better ally.

Quote of the day, reflecting a rather hard-nosed view of the world and a message to users that they need to be proactive in managing their information:

"Life is tough, but it's a whole lot tougher if you're stupid"

Kind of says it all, really.