Friday, March 19, 2010
Asking the right questions
A great example is from today at work. BuCorps is being audited. From my standpoint, that means applications and servers I host are getting scanned for security vulnerabilities. I fully support this effort and want to ensure that our servers are as robust as they need to be to thwart attacks. Today were several meetings with the group doing the audit. I've never been involved in an audit of this nature before, so I was pretty interested in how it would progress. I prepared for all the questions I envisioned would be asked so I didn't come across as unqualified.
The first meeting was about backup and recovery. Notebook in hand full of information about our backup, disaster recovery, and continuity of operations plans I was prepared. Imagine my disappointment when all I was asked was for a screen shot that demonstrated that the databases were scheduled to be backed up nightly. I was in shock. I wasn't asked about the percentage of the time the backups were successful. I wasn't asked if the backups were moved to another location. I wasn't asked about restoring from backup. I wasn't asked about what happens if the building is blown up and we lose servers. All the auditors wanted to see was that the backups were scheduled. Had they asked the right questions, they possibly could have gotten some pretty juicy information for their audit. But, alas, all they wanted to know about were the scheduled jobs.
My second meeting was about security patches. The auditors wanted to see what operating system security patches had been installed in the last 6 months. I asked them what I needed to show them to satisfy their requirements. They didn't know. I asked them what servers they were interested in. Again, they had no specifics. They ended up getting screen shots of the add/remove program wizard. I hope it works.
My third meeting was about security scanning. The first thing that irked me was when the auditors showed up late. Everyone else made it on time, they were late. But, I'll forgive that. It gave everyone else an opportunity to prepare for their arrival. Having heard stories of past audits crippling hardware because an improper button was selected, I had several topics to discuss. The most hilarious was trying to get the idea across that running security scans on a production server in the middle of the day was not a good idea. They just didn't understand the repercussions. In fact, the importance of the servers seemed to slip their mind. The servers they wanted to scan are used by more than 40,000 employees every day. The servers interact with terabytes of data each day. It just didn't click.
The audits will continue next week so I'm sure the hilarity will continue. I guess today just reinforced the importance of understanding what you're working on. A finance major will have difficulty doing a GOOD audit of a computer infrastructure because they don't know what everything is, the same way a computer expert couldn't do a home inspection. When eliciting information, leading questions certainly have their place, but so do open ended questions. Good open ended questions allow much more knowledge to be gained than a simple leading question. Most importantly, to quote the movie Finding Forrester, "You gotta know the rules if you wanna play the game."
Saturday, October 24, 2009
Let's all hate IT
When I got involved with the meeting I was pretty amazed at how quickly things turned into "It's the IT department, screwing us again." It was only the second time I'd interacted with a customer not from within IT and this idea was a shock. I never really considered that people didn't like the IT department. I know the stigma associated with them, I just thought that BuCorps was different.
Once I got back in the office I talked to my boss about the perception of the department from the outside and why people don't like us. He said that most peoples' perceptions of the department are from the help desk. This is an interesting problem for BuCorps especially. Most people that work in the Help Desk aren't employees coming in for life. They use the job to get their foot in the door then move on. Turn over at the help desk is high which means that it's difficult to get people with real knowledge in there. Since they are the face of IT to the field, having less than knowledgeable people answering the phones isn't helpful. It's also not good if they answer the phone and you can just hear that they hate their jobs. But, this is the case a BuCorps.
I don't know how to rectify this except through a vigorous marketing campaign. The IT department should focus more on interacting with the customers we serve and ensuring that we are meeting their needs. That involves a huge change from the past methods of doing things. The separation of the IT department from the field has been crippling. It results in inefficiency through usage of manpower and wasted money by purchasing equipment and software that isn't fully utilized. Making the changes will be an incredibly hard process. It needs to start with communication and end with creating tools which meet the needs of the people who use them.
Saturday, September 26, 2009
Corporate E-Mail
I've never been a huge fan of that little button that looks so inviting. It seems like a great idea: allow e-mail to facilitate a discussion among multiple people by keeping everyone on the same page. This is a great and powerful tool. Like anything powerful, it's just waiting to be misused. And I'd call it the most frequently abused aspect of e-mail communication.
My first exposure to this abuse came from being on several listserves in college. It wasn't uncommon for people to hold private discussions via an entire listserve thanks to that dreadful little button. They, of course, wouldn't figure out the error of their ways until I knew far too much about their weekend plans or relationships.
However, the abuse isn't limited to college students. This week at work I was bombarded with my first corporate cluster-fudge E-Mail storm. I arrived at work and opened Outlook expecting nothing new. While BuCorp is an international company, I'm not typically subjected to the whims of the international facet of the operation. So, imagine my surprise when I had over 100 new messages... all with the same subject line. Not able to resist the urge, I had to read through them. Starting off innocently enough with an e-mail to the corporate policy office things quickly spun out of control. Interspersed with the typical "STOP HITTING REPLY ALL" and "OMG, why am I getting this e-mail?!?!" were a few winners. Personally, I really liked a reply from a sales rep that invited users to e-mail another sales rep to be removed from the e-mail chain. (Technical note: most people should have realized that there was no way this person could remove someone from the list.) About 45 minutes after that e-mail the sender sent out another informing everyone that his prior e-mail was joke. My hypothesis is that the subject of the joke suddenly became inundated with E-Mails asking to be removed from a list he had no knowledge of. I got a real kick out of this and thought the exchange was hilarious. Since the E-Mail administrators work in my area, I took a walk over to get their fix on the situation. They were irate. There were 8,000 employees on the distribution list accidentally included in the list. Most of the 8,000 employees work in BuCorp headquarters, and included in the list was the company CEO. After a rather strong e-mail about "reply all" E-Mails from the E-Mail administration group, the fun for the day ended and it was back to work for everyone. It was a great start to the day.
Saturday, September 19, 2009
Information Sharing
My first example of this came about when I met with the director of my branch’s HR department. I had been at work less than a month and was given a project which required I meet with various levels of management. I didn’t know what to expect going into that first meeting but was pleasantly surprised by how friendly and knowledgeable he was. His willingness to talk to me exceeded that which was required for my project and he came across as genuinely excited to have me on board with the company and excited to work with me. The conversation extended well beyond my project and he provided me lots of stories about his time with the company.
Another interaction I recently had is even more remarkable to me. I recently had the opportunity to travel to another office location to meet with one of my team’s remote employees. While there, my supervisor arranged for me to take a tour of another division that was located nearby. The other division wasn’t reportable in any way to my team yet they were very willing to show me around. I showed up expecting to be given a nickel tour by whoever was free. I was shocked when I was introduced to an assistant director of the division for an introduction to the division. He welcomed me into his office and we spent about an hour talking about the division and his time in BuCorp. It was a great opportunity for me to pick his brain for all sorts of information. He told me all about his career and offered plenty of relevant advice for navigating the BuCorp system. He also led me on a tour of his whole division and carefully explained everything they did. The tour was amazing and I could tell that he had a great handle on the divisions operations, challenges and opportunities. He is the type of person that people want to work for: on top of his game and with a strategy to win.
These interactions have reassured me that I made a good choice in working fro BuCorp. While it’s not a flawless company, the right people are on the bus to make the company great. These people, recognizing that they are only 5 or 10 years from retirement, seem genuinely excited to share their knowledge with the newcomers so we can carry the torch as high as they do after they leave. They each have a passion with what they do and are capable of explaining what they do in an articulate manner that makes you want to get involved. I’m amazed that management is willing to take time out of their schedules to talk to someone not reportable to them and who is so low on the totem pole. Rather than working in a basement for a major company, work feels much more like an extended family reunion.
Wednesday, February 11, 2009
Recent Adventures
In other news, on the job front, all is well. I went to Atlanta Tuesday for my "personnel security interview" on Wednesday. It was my first solo "business trip" and I had a good time. Tuesday night I got to see some Savannah folks which makes any trip to Atlanta infinitely better. This morning I had an 8:30 appointment to get my application rolling again. After a fingerprinting (which was a funny situation - ask me about it sometime) and an interview I got to take my first ever polygraph test. To say it was nerve wracking would be an understatement. Don't breathe too slow. Don't breathe too fast. Don't breathe too deeply. Or too shallow. And don't move. Not even a little bit. But, after questioning if my name really was what I thought it was, it ended pretty well. I might be called back up to Atlanta if they need me to repeat a part of it but otherwise I've been told that "no news is good news." So, here's hoping for no news - and a job!
Thursday, December 11, 2008
Things Fall Apart?
At Richmond's career fair in August the booths were bustling with students looking to be hired and professionals, looking to hire. As one of those wide-eyed students, I was pretty excited and felt good about my prospects. As the semester moved on and the Wall Street Journal's economic outlook got darker and darker, the light on my prospects also began to weaken. I came out of the career fair with two solid interviews. However, after an interview I was informed by the companies that they were no longer able to hire new employees due to the economy or that they were revising the roles of the employees they would hire. This was disappointing but if nothing else, I took away plenty of knowledge from the interviews I had - they were somewhat entertaining as well.
Thankfully, I'm not in a position where once I graduate if I don't have a job I don't eat. This knowledge also hasn't helped my job searching as I've been a little less intense than I could have. But, I still worry about those who don't have a buffer they can work from until the economy switches back to hiring mode. More than one person has told me "it's a great time to go to graduate school" and that is what others graduating with me are looking to do. I just don't feel like I would be able to get the most out of grad school yet. I want to experience more before I spend more time in a class room. I want to solve real world problems, I want to work with people. I want to work from 8-5 (or whatever) regularly and see how well I adjust. I've done the academic learning thing for a while - I want to see what else is out there.
Don't fear though, all is not lost for me. Despite my lackadaisical job search I've found and interviewed for a position which I think would be both fascinating, fun, and a great experience and with a company that isn't as subject to the whims of the market as others. Here's hoping that works out!
Friday, September 5, 2008
Life During Hurricane Season
A perfect example of this is with hurricane Katrina in my sophomore year of college. As a freshman, campus was closed for hurricane Ivan the year before and the city only got a little windy. This allowed people to get lulled into a false sense of security. When the next year's devastation came through it was a wake-up call for the entire city. New Orleans is an interesting case though. As it is known today, most of the city is built on swamp. A map from 1901 of the city shows much of Uptown and the French Quarter but the rest of the city is listed as swamp land. The recovery of this swampland into livable areas is partly why the city has to pay so dearly each time a hurricane approaches.
New Orleans desperately needs help if it is to survive. It's not feasible for a city which is a major center of commerce to have a season where nothing is definite. Eventually, business leaders will tire of their constant evacuations and move their companies elsewhere. This will be catastrophic for the city and state economy. This means that the power company for the region (Entergy) needs to get their ducks in a row. Five days following hurricane Gustav customers in Metro New Orleans still don't have power, and the local paper tells them they might have to wait until the end of next week to see it. This is unacceptable. How are businesses expected to operate and be successful when the basic infrastructure can't keep up with their needs?
To remain successful, New Orleans needs reliable hurricane protection and companies managing the infrastructure that know what they're doing or it will sink into it's reputation of being a great party city and nothing else. And that would be tragic.
Saturday, April 19, 2008
Housing? What housing?
The more I hear through the media about the “housing bubble” the more frustrated I get. For me, the whole thing seems pretty easy. People bought what they couldn’t afford and now have to pay the consequence. Someone paid too much for a home which is now worth less than they still owe for it.
What’s the deal with this though? I blame two groups. The first and most responsible are the people who bought what was out of their league. I’ve always been taught that something that sounds too good to be true probably is. What makes people think anything different when it comes to getting a home mortgage? If you make $50,000 a year you can’t buy that $300,000 house. I’m sorry but it just doesn’t make sense. Yet, this is part of what puts us in our current predicament. Had these people read and understood what they were signing and thought about it we wouldn’t be in as deep as we are currently. Sure, there’s a lot of fine print and things like “interest only” loans sound like great things. But, failure to understand or ask questions about what you read creates huge problems. Of course, I also blame the American mentality of “Well, we’ll worry about that problem when we get to it” for interest only loans.
The second group responsible for a large part of the problem is the lenders. The same “too good to be true” policy still applies. What good does it do the company to lend to someone who can barely afford the mortgage? Sure, it is great to put someone in a home they “own” but if they can’t afford it the payments this puts a heavier burden on the family than the benefit from owning a home. Greed is a bad thing. That’s my personal motto. These companies gambled and lost due to their desire for more money.
But, now what do we do? While it would be GREAT to be able to say “Well
All the while, the people at these lending companies are still making their salaries despite the trouble they have caused. The vice-presidents and CEOs of these companies have lost little compared with the people they targeted for lending and will probably get severance packages as they are fired for ruining not only the company but contributing to the downfall of an economy.
Meanwhile, people trying to retire are being hit hard. As the stock market dives investment portfolios tank in value. This is due in part due to a lack of diversification but also due to the general downfall of the
Monday, April 14, 2008
Residence Hall Access Security
There is an article in this week’s Maroon about dorm security. The article supplements a video made by the paper’s staff as they get in to the dorms at Loyola without the required identification and show that it’s not a difficult process. This wasn’t any real surprise of mine but it does expose a pretty important security issue.
What can schools do to increase the safety of their dorms from an entry control stand point? I think the most important thing schools can do is create a single point of entry and exit to all their residence halls. This allows much more control from a physical point of view and also makes the dorms more social since people are forced to interact while approaching that central access point. This is one aspect of student housing that Loyola does an excellent job at.
After the buildings have a single way in and out the next important step is to staff that entrance with a well trained person all the time. Training should include proper procedure as well as the reasoning behind the procedures. Many problems encountered during my stint as an RA resulted from poorly trained work study students not doing their jobs properly. While at the desk a person’s responsibility becomes checking that each individual trying to enter the dorm is allowed to do so. This also involves monitoring visitor check-in and check-out as well as any other responsibilities (Tulane rents movies, Loyola checks out vacuums). As a part of this, residents of the dorms should each have something on their identification which makes it easy to detect whether they are in the right dorm or not at a glance. Loyola used “building stickers” for this purpose with each sticker being a different color. This allowed desk staff to glance at the ID and ensure the student was in the proper dorm.
Another side benefit of having the dorms staffed is that it provides a simple mechanism for problems. If someone crazy does enter the desk assistant can push the panic button. If something breaks the desk assistant can write up the work order. If a roommate is passed out in the hallway the desk assistant should be able to call for assistance. This requires the desk assistant to be given some level of control over their dorm. My biggest complaint while an RA at Loyola was that the dorms failed to empower the desk assistant.
For desk assistants to be able to perform their duties, they need to be able to control the entryway and lobby of the dorm. This means that beyond a certain point in the building, residents should have to walk around the desk through a single choke point that allows each person to be identified. Elevators and stairs to other parts of the building should be located only behind that point. This ensures that everyone going to the rooms has at least walked past the desk. Desks off to the side of a lobby allow ample room for people to sneak around the desk. When well placed desks are given good visibility of the lobby and entryway the likelihood that intruders could be easily detected greatly increases. Well placed desks also thwart potential intruders as they see a more difficult obstacle to gaining entry.
Tuesday, April 8, 2008
"Free" Software
- The right to run the program for any purpose
- The right to examine and/or change the source code for the program. (So, this requires access to the source code)
- The freedom to redistribute copies as desired.
- The freedom to modify the program and distribute that modification
Stallman is against any software that is not "open source" or, in his word, free.
This sounds pretty cool. We would have access to everything on our computers so that we could learn how everything works, add any features we desired or remove features we didn't like. We could then provide our changes to other people who might want a similar setup.
But, this would mean the end of companies which rely on proprietary software development for revenues. Because, if you want to sell someone software that you've written, but after the sale the code for the program ends up online no one else will buy it, they'll just get it off the Internet.
Despite this, "free" software seems like a pretty neat idea and it could change the way people use their computers. I don't think this is an economically do-able system though.
Some applications require proprietary software to be of any use. For example, if the government has software that can accurately track and shoot down missiles, that's not something we want China to have the code for. With the code, they could learn the software's limitations and exploit those problems before anyone else had discovered them (there is no such thing as an error free program). In a more applicable situation, imagine that you run a medium sized company in a highly competitive market. You are consistently trying to better manage your business to lower your costs and under price the competition. If in house programmers create an integrated management system for your company that you then use to run aspects of your business, it isn't something you'd want to publish the source code for. Publishing the source code would remove any competitive advantage you would have over your competitors that the software provided. Or, if your competitors wanted to they could examine the code and look for vulnerabilities. Finding even one problem with the code could be enough for them to access your system and ruin your business. These are two fundamental problems with open source software on a wide scale from a security stand point.
Another problem with Stallman's point of view is the money problem. In his talk, he spoke of a world where anyone could change the code and redistribute it, fixing problems with it, changing functionality, or whatever. Since all the software is open source, anyone could make these changes. To use an example of his, a high school student that was into coding could learn how to implement the changes in software and make them. The immediate problem I see with this would be the development of a price war. Much like the outsourcing of physical jobs, coding jobs would get delegated to the lowest bidder on a global scale. This would hurt countries with high cost of living as programmers need to make more money to sustain themselves. In another possibility, if a company needed some changes made to their software, what's to stop them from reaching an agreement with a local college to have a class rewrite the code for academic credit? As a company, wouldn't this be a good thing to do? You still get the software, it's probably going to be good since students are being graded on it and it's free.
The free software movement isn't all bad though. I think there are certain applications where open sourced software can be of great use. Open source software is great for basic applications that are common needs for everyone. These include e-mail, document creation, and internet browsers. However, as the software becomes more specialized than the generic variety it becomes more important to keep it in house to protect your business security and investments.