As most of my followers (all 9 of you), may know our most recent subject in class dealt with organizational security. Protecting business from internal and external threats. Our two speakers represented the same organization from two different areas of IT security. Our first speaker was responsible for tackling issues related to Internet fraud, sensitive corporate information being shared, unintentionally or intentionally, and intellectual property issues. The other guest speaker from Legg Mason was charged with the IT infrastructure security - ensuring that IT property and corporate systems are well protected from intrusions, theft and other security issues. Both representing necessary roles within a firm to ensure that the customers, corporate IT systems and the company image are protected.
I found our first speakers role as extremely challenging and difficult for such a small team monitoring such a large spectrum (the World Wide Web) and tackling issues of fraud and blackmail while handling the various language barriers with a small team of virtual novices in a poorly defined role. Their ability to build relationships with the various local, federal and international law enforcement agencies to handle the relatively new frontier of Intellectual Property on the Internet is amazing. She describe how they have to use cleverly designed web crawlers that perform intensive web searches for certain key words that may signal an issue requiring her teams legal expertise to resolve. Additionally, her team seems poised to newly define the role of IT Intellectual Property - the team seems to find new ways to investigate possible leads .. they have no formal training or professional investigators but her team finds a way to discover who is infringing, stealing or blackmailing them while attempting to remain anonymous.. They don't just use the Internet either.. they make phone calls and perform investigative type activities to discover the criminals. Sounded really cool.
The second speaker spoke to us about the need bridge the gap between leadership and the employees and that the ability to understand the real meaning of corporate strategic direction and apply this to your projects and activities. Seems like it's always about bridging the divide between business and IT, right? He also reveled some valuable insight into how organization protect their IT resources, and why. He brought the issue of protecting corporate systems through encryption of virtually every facet of Legg Mason IT: files, external drives, hardware and intranets and corporate websites. He explained that that the security modus operandi of locking down all IT and then requiring employee justification for exceptions isn't based on malice but rather is the more sound approach to ensuring that no IT resource is left vulnerable due to an oversight. Examining each individual port request, website, media accessory and access to file system ensures that risks have been weighed and activity can be tracked. Tracking playing and important part in possible legal issues and allowing firms to accurately assess the extent of a security breach that may result in loss of data or exposure of client information.
Sunday, March 7, 2010
The world according to the customer... and of course their always right. Right?
I've recently found myself presented with a new job opportunity - one with great challenges and possibly great rewards. Unfortunately these challenges involve a difficult customer who has ran off three previous occupants of this position. This is a customer who eagerly seeks confrontation and is prone to engineering flights of fancy - i.e. changing already poorly defined requirements for the architected systems at a moments notice or delaying critical design decisions until the last minute.
This customer is of course only one customer on a larger team my organization supports. Customer colleagues have noticed the rapid flight of the best engineers from the project due to the toxic relationship between the development team and, well let's call him Mr. X, yet they are seemingly powerless to remove him because of his position within his organization and because our firm refuse to expose the turmoil within the team because of the fear of reprisal in either the form of this customer simply moving to another position where he can influence decisions regarding contracts or if the customer organization decides to retain this individual in his current position. So now the customer team is attempting to stem the tide of exiting engineers by providing generous incentives to ensure the remaining team stays put. The customer team is rightly concerned that if team members continue to exit that continuity and the current delivery schedule will suffer. I'm sure bribing our developers and engineers is the appropriate way to ensure team cohesion and productivity.
Well of course I'm tickled pink that the team lead has selected me to help rebuild the developer customer relationship - of course the big hurdle can't be tackled directly (Mr. X) and thus I have to figure a way to maneuver around him and still meet the software delivery schedule. Your guess is as good as mine. This brings to light the issues with organizations who feel certain individuals have some inalienable right to employment; they have the right to manipulate, distract, delay, and generally annoy with impunity. Why do organizations tolerate this, why is management so fearful of direct confrontation - I mean.. we all don't work for the Postal Dept. right? There's a culture of tolerance (which is normally great...unless your talking about tolerating bad behavior), which creates these tense moments during technical meetings and project reviews where you wait to see who the next engineer is who breaks down and decides to seek better opportunities.. I hope I have the ability to negotiate and broker the deals necessary for the team to advance and continue to be productive.... but hey If I do decide to quit I may receive a generous bribe to stick around... Win/Win!
I often wonder, from a quantitative perspective how much time and resources have been spent to simply mitigate and lessen the impact this individual has had on this project? All of which could have been avoided by his management simply having a talk with this person, providing a warning or even providing some guidance on how to behave? Can you imagine what this individuals direct reports have to tolerate on a regular basis - why haven't they spoken up? According to the an article regarding bad behavior that managers who are held accountable for the behavior "tend to more actively promote fairness within their organizations", and "when organizations make managers accountable for promoting fairness they stop enabling individuals who confuse power with effectiveness or pursue financial ends at any all costs"... wow that pretty much sums up what I feel in this scenario. Organizations really think that avoiding these difficult subjects and issues will make it go away... really ..really? In denial much.
This customer is of course only one customer on a larger team my organization supports. Customer colleagues have noticed the rapid flight of the best engineers from the project due to the toxic relationship between the development team and, well let's call him Mr. X, yet they are seemingly powerless to remove him because of his position within his organization and because our firm refuse to expose the turmoil within the team because of the fear of reprisal in either the form of this customer simply moving to another position where he can influence decisions regarding contracts or if the customer organization decides to retain this individual in his current position. So now the customer team is attempting to stem the tide of exiting engineers by providing generous incentives to ensure the remaining team stays put. The customer team is rightly concerned that if team members continue to exit that continuity and the current delivery schedule will suffer. I'm sure bribing our developers and engineers is the appropriate way to ensure team cohesion and productivity.
Well of course I'm tickled pink that the team lead has selected me to help rebuild the developer customer relationship - of course the big hurdle can't be tackled directly (Mr. X) and thus I have to figure a way to maneuver around him and still meet the software delivery schedule. Your guess is as good as mine. This brings to light the issues with organizations who feel certain individuals have some inalienable right to employment; they have the right to manipulate, distract, delay, and generally annoy with impunity. Why do organizations tolerate this, why is management so fearful of direct confrontation - I mean.. we all don't work for the Postal Dept. right? There's a culture of tolerance (which is normally great...unless your talking about tolerating bad behavior), which creates these tense moments during technical meetings and project reviews where you wait to see who the next engineer is who breaks down and decides to seek better opportunities.. I hope I have the ability to negotiate and broker the deals necessary for the team to advance and continue to be productive.... but hey If I do decide to quit I may receive a generous bribe to stick around... Win/Win!
I often wonder, from a quantitative perspective how much time and resources have been spent to simply mitigate and lessen the impact this individual has had on this project? All of which could have been avoided by his management simply having a talk with this person, providing a warning or even providing some guidance on how to behave? Can you imagine what this individuals direct reports have to tolerate on a regular basis - why haven't they spoken up? According to the an article regarding bad behavior that managers who are held accountable for the behavior "tend to more actively promote fairness within their organizations", and "when organizations make managers accountable for promoting fairness they stop enabling individuals who confuse power with effectiveness or pursue financial ends at any all costs"... wow that pretty much sums up what I feel in this scenario. Organizations really think that avoiding these difficult subjects and issues will make it go away... really ..really? In denial much.
Sunday, February 21, 2010
Death of the written word
Hello my digital followers...
Have you all heard that ink/pencil to paper is an outmoded means of communication? I mean look at where I'm entering this information... this used to be the equivalent of the personal diary. Now I type away and if popular my personal feelings regarding any subject can be shared with millions. I read an article in Fortune magazine recently that declared the future of reading is in the digital form. It extolled the virtues of digital media and its ability to be portable, shareable and easily accessible, but how do you sell it? Not just from a journalistic subscription standpoint - I mean can you imagine people paying $0.25 for access to the Washington Post for 2-3 hours? Ok, let's move beyond that aspect and get back to the comfort people have with the tangible qualities of pen to paper. Would you feel comfortable having all legal documents signed via a digital PKI certificate... I think there's a certain uneasiness with this thought, but people are becoming comfortable with wireless banking transactions - avoiding paper money entirely, so why not get rid of all forms of the written word and save some trees right? Certain banks have already begun to scan all paper checks deposited and then retain the digital copies which they send to customer via email (PDF.. got to love it). The funny part is that the entire burgeoning growth of free digital media and digital content was being pushed forward on the wings of promotional marketing (on-line ads). Well the interesting thing is that marketing research has shown that printed ads actually results in greater revenue because it sticks with readers longer - the blitz of media sponsored digital content has overwhelmed readers and become background clutter, white noise so to speak. People like the flexibility/portability of digital media but they trust paper and ink. Is this some innate personal connection from childhood or does this rest with some type of intrinsic human need to believe in what we can feel, touch and interact with - including information.
According to the Fortune article this doesn't necessarily mean that people don't want to read or access information online, but they just don't want lots of it (long-form journalism is considered impossible for some writers), readers seem to prefer short summarized articles and even in the business circles financial investors worry that financial media journals like The Wall Street Journal and The Financial Times will fall apart and the critical and in-depth pieces of journalism that allow investors to draw conclusions about the information may disappear to be replaced by the Equivalent of financial Tweets. I mean can you imagine the end result: "Like I heard a wicked rumor that J&J will not meet financial earnings..LOL" follow me on Flitter for more info in 200 characters or less... The article suggests that the savior for news and information could actually be... well a digital one. The digital readers which spend a considerable amount of time attempting to resemble paper in its original form ... a simple direct approach that allows you to do something that yes ... could possibly be free if you find your article online or your book at a peer-to-peer site, but is it convenient and direct. No. People are lazy and if you offer them a cheaper, at least from a time perspective, way to receive their information they will pay for it. Something that may be challenging to receive free (think of all the registrations you have to go through to read an article.. the ads that interrupt your reading or the inability to trust the excerpts from a third-party provider). Still there are those who love the feel of a page of paper and revel in the gloss of a photo spread, but can't this too be replicated to some extent digitally?
In business it's already become a thing of the past for someone to write down notes or send inter-office memos and even the bulletin boards in the break room have been replaced with dynamically updated information on HD TV monitors (at least where I work). Oddly enough the only group not comfortable with the thought of replacing the written word are those involved with contracts and other legal issues in business. The thought that making your X could be done with a trusted key seems to really unnerve folks (well at least my Dad who thinks that cybercriminals are specifically targeting his personal stash of can't fail investment strategies and Grandmas ultimate brownie recipe). Security seems to be the final hurdle that needs to be overcome prior to regulatory and legal approval of digital forms of contracts and other legal documents because truth be told the cost benefit analysis has been done and the cost-savings of eliminating stack and stacks of paper is there in some would say "black and white".
Have you all heard that ink/pencil to paper is an outmoded means of communication? I mean look at where I'm entering this information... this used to be the equivalent of the personal diary. Now I type away and if popular my personal feelings regarding any subject can be shared with millions. I read an article in Fortune magazine recently that declared the future of reading is in the digital form. It extolled the virtues of digital media and its ability to be portable, shareable and easily accessible, but how do you sell it? Not just from a journalistic subscription standpoint - I mean can you imagine people paying $0.25 for access to the Washington Post for 2-3 hours? Ok, let's move beyond that aspect and get back to the comfort people have with the tangible qualities of pen to paper. Would you feel comfortable having all legal documents signed via a digital PKI certificate... I think there's a certain uneasiness with this thought, but people are becoming comfortable with wireless banking transactions - avoiding paper money entirely, so why not get rid of all forms of the written word and save some trees right? Certain banks have already begun to scan all paper checks deposited and then retain the digital copies which they send to customer via email (PDF.. got to love it). The funny part is that the entire burgeoning growth of free digital media and digital content was being pushed forward on the wings of promotional marketing (on-line ads). Well the interesting thing is that marketing research has shown that printed ads actually results in greater revenue because it sticks with readers longer - the blitz of media sponsored digital content has overwhelmed readers and become background clutter, white noise so to speak. People like the flexibility/portability of digital media but they trust paper and ink. Is this some innate personal connection from childhood or does this rest with some type of intrinsic human need to believe in what we can feel, touch and interact with - including information.
According to the Fortune article this doesn't necessarily mean that people don't want to read or access information online, but they just don't want lots of it (long-form journalism is considered impossible for some writers), readers seem to prefer short summarized articles and even in the business circles financial investors worry that financial media journals like The Wall Street Journal and The Financial Times will fall apart and the critical and in-depth pieces of journalism that allow investors to draw conclusions about the information may disappear to be replaced by the Equivalent of financial Tweets. I mean can you imagine the end result: "Like I heard a wicked rumor that J&J will not meet financial earnings..LOL" follow me on Flitter for more info in 200 characters or less... The article suggests that the savior for news and information could actually be... well a digital one. The digital readers which spend a considerable amount of time attempting to resemble paper in its original form ... a simple direct approach that allows you to do something that yes ... could possibly be free if you find your article online or your book at a peer-to-peer site, but is it convenient and direct. No. People are lazy and if you offer them a cheaper, at least from a time perspective, way to receive their information they will pay for it. Something that may be challenging to receive free (think of all the registrations you have to go through to read an article.. the ads that interrupt your reading or the inability to trust the excerpts from a third-party provider). Still there are those who love the feel of a page of paper and revel in the gloss of a photo spread, but can't this too be replicated to some extent digitally?
In business it's already become a thing of the past for someone to write down notes or send inter-office memos and even the bulletin boards in the break room have been replaced with dynamically updated information on HD TV monitors (at least where I work). Oddly enough the only group not comfortable with the thought of replacing the written word are those involved with contracts and other legal issues in business. The thought that making your X could be done with a trusted key seems to really unnerve folks (well at least my Dad who thinks that cybercriminals are specifically targeting his personal stash of can't fail investment strategies and Grandmas ultimate brownie recipe). Security seems to be the final hurdle that needs to be overcome prior to regulatory and legal approval of digital forms of contracts and other legal documents because truth be told the cost benefit analysis has been done and the cost-savings of eliminating stack and stacks of paper is there in some would say "black and white".
Sunday, February 14, 2010
Social Networking and it's potential for disruption
Does anyone remember the beginning's of the Internet era and the old electronic Bulletin Boards where people would post messages to topics and threads for other users to comment and share. These legacy (Well, GeoCities, Tripod) sites were the forerunners of current social networking sites and were mainly a mechanism for personal communications and were devoid of media, and robust linking technologies that allowed people to connect easier. Social Networking tools have now become a way of life for virtually all individuals who use the Internet - even if they aren't aware of it. Many sites that are used for simply sharing photos (like Flickr) are considered social networking tools due to their ability to link profiles and tag photos that allow users to reach other people and photos that have similar characteristics. If you like photos of ducks you can search for other duck photos and find users who take photos of ducks and post your duck photos you want to share... crazy duck people. Certain sites like Classmates.com have a large and diverse user base of people simply looking to connect with old school chum via the sharing of email addresses have been around for years and have recently begun to expand their capabilities to shift to a more traditional social site by allowing personalized pages and linking to blogs, websites and allowing customization of a user page. I know my dad uses classmates but if made the link between Facebook and Classmates he would scoff and assert there is a distinction, but is their really?
So what in little baby Jesus name could the problem with the social sites? Well I guess the biggest challenge is ensuring that your information isn't used against you - either professionally or privately. There is a certain amount of misplaced trust people place in these sites because of the thought that only the information I share will be seen by only those people I designate. This could be true to some extent if your wise enough to take advantage of security that may built into a program but isn't activated by default - i.e. you have to consciously decide what additional security you want on any of the social websites. Most people just quickly zoom through the fine print and want to get to the fun - only to discover that they should have left off their social security number and bank account when they asked for money from their parents for an extended spring break in Cancun (i.e. bail money) via their Facebook or twitter account. Now they're back in the states and their family and friends are being hit up for emergency money again becuase they've been robbed while on vacation in London - never mind that they've been banned from the UK since that notorious incident at the Coldplay concert at Wembley Stadium - again apologies to the Queen and that poor security guard with the very large hat that may have been used as a lavatory (they courts will decide this one). Point being that the information posted innocently was surreptitiously used to try to defraud family and friends. So how much information is too much. Well obviously some common sense should be used - don't post sensitive information about your life, including your address, phone number, bank accounts haha and even innocuous things like high school attended or workplace on a public profile - heck you probably shouldn't do it on a private profile because you never know who your friends will show it to. I think the important thing to remember is that your posting your information on the Internet - yes all of the Internet as far as I'm concerned. Yes, you can place some protections in place against your average yahoo or clown from high school but those savvy Nigerian/Russian scammers with large uncollected sums of money in Swiss numbered accounts will still find a way.
This brings us to the second part to the privacy discussion - unintended disclosure of work-related information on these sites. Often people reveal information that typically is quickly forgotten or disregarded in casual conversation with friends and family but when posted to a site where potential adversaries or competitive rivals may use the information to glean valuable intelligence. "Hey honey I'm going to be late to dinner because the Johnson case is probably going to take longer than I anticipated", or "Hey guys I'm going to be late for drinks because we think we have another great idea for the Nike advertising account"...this information doesn't appear to be damaging but in the right light it could reveal critical information that could prove to be a real advantage to competitors or rivals?
So what in little baby Jesus name could the problem with the social sites? Well I guess the biggest challenge is ensuring that your information isn't used against you - either professionally or privately. There is a certain amount of misplaced trust people place in these sites because of the thought that only the information I share will be seen by only those people I designate. This could be true to some extent if your wise enough to take advantage of security that may built into a program but isn't activated by default - i.e. you have to consciously decide what additional security you want on any of the social websites. Most people just quickly zoom through the fine print and want to get to the fun - only to discover that they should have left off their social security number and bank account when they asked for money from their parents for an extended spring break in Cancun (i.e. bail money) via their Facebook or twitter account. Now they're back in the states and their family and friends are being hit up for emergency money again becuase they've been robbed while on vacation in London - never mind that they've been banned from the UK since that notorious incident at the Coldplay concert at Wembley Stadium - again apologies to the Queen and that poor security guard with the very large hat that may have been used as a lavatory (they courts will decide this one). Point being that the information posted innocently was surreptitiously used to try to defraud family and friends. So how much information is too much. Well obviously some common sense should be used - don't post sensitive information about your life, including your address, phone number, bank accounts haha and even innocuous things like high school attended or workplace on a public profile - heck you probably shouldn't do it on a private profile because you never know who your friends will show it to. I think the important thing to remember is that your posting your information on the Internet - yes all of the Internet as far as I'm concerned. Yes, you can place some protections in place against your average yahoo or clown from high school but those savvy Nigerian/Russian scammers with large uncollected sums of money in Swiss numbered accounts will still find a way.
This brings us to the second part to the privacy discussion - unintended disclosure of work-related information on these sites. Often people reveal information that typically is quickly forgotten or disregarded in casual conversation with friends and family but when posted to a site where potential adversaries or competitive rivals may use the information to glean valuable intelligence. "Hey honey I'm going to be late to dinner because the Johnson case is probably going to take longer than I anticipated", or "Hey guys I'm going to be late for drinks because we think we have another great idea for the Nike advertising account"...this information doesn't appear to be damaging but in the right light it could reveal critical information that could prove to be a real advantage to competitors or rivals?
Electronic Document retention
Well this particular topic has quite a bit of personal connection for me - electronic document retention and this impacts the IT departments in businesses. Several years ago a family member became involved in a legal dispute with their employer. The family formally filed a complaint and was thus legally protected at the time from retaliation, persecution and job termination; however after waiting several months they decided to terminate his position. Being keenly aware of the termination tactics employed by this organization (which were pretty slick actually). The organization would inform an employee that they would need to see an HR representative located in an adjacent building to their own (regardless of where their actual HR representative was located). I have a point, I swear. This ruse would provide the firms IT and security team the opportunity to inventory, scan and remove any items they determined were Intellectual Property or work product of the firm - this was often anything that could be construed to be potentially damaging to the firm: electronic documents, emails, chat records, paper documents and even sometimes personal documents in briefcases, backpacks and other items in employee offices. Having been tipped off by another sympathetic employee, this family member (will call him Mr. X) quietly excused himself from the HR rep sent to escort him by requesting some time to use the restroom. The HR rep provided him with directions to the room and then left - fully expecting him to proceed directly behind them. Instead Mr. X quickly gathered all of his personal items and documents and proceeded to his vehicle. Before being able to depart Mr. X was confronted by a member of the security team who attempted to remove his personal items from Mr. X. Mr. X stated the items were his personal belongings and that any attempt to remove them could be construed as assault. Security was not content with this rebuff (again I swear this all is relevant) and called in a code red to the local law enforcement - code red's are reserved for ... well you guessed it really bad and possibly violent confrontations (angry employees, gun-toting maniacs ..etc) not disagreements with employees over documents. As the officer who arrived on the scene stated "it's not like his carrying a computer out of here". The officer requested the organization identify what they considered to be work product or intellectual property - the security team couldn't positively state that any items belonged to the organization, then they were promptly chastised by the officer for calling in a code red and the officer asked Mr. X if he would like to file an assault charge against the security team for attempting to grab the personal items from him and preventing Mr. X from departing. The moral of the story was that the firm had no document retention policies that would've enabled them to accurately identify missing items in this type of situation, thus avoiding confrontation because there would've been copies and accurate accounting of items - electronic and paper.
By applying policies regarding where personal vs. organizational documents and emails are stored, either electronically or paper document storage , requiring documents, emails and chats be appropriately labeled will contribute to avoiding confusing circumstances regarding what is and isn't proprietary information. This particular case became even more complicated when during the legal negotiations (discovery process) the firm stated that personal notes and items being introduced during the meetings should be classified as proprietary or sensitive work product thus mitigating its ability to damage the defendant (them). In order to provide some level of legal guidance for organizations seeking to formulate or revise their policies the American Bar Association (ABA) has devised a sample policy. Although Mr. X's particular case did set some legal precedent I reference another case "Zubulake vs. UBS Warburg LLC" were Mrs. Zubulake who was filing a gender discrimination case was awarded 30 million after the courts found that UBS deleted emails and other communications from the organization that affirmed her claims, on the other side in Teague vs. Target, Target had the case dismissed because Mrs. Teague destroyed her personal computer she used for working from home prior to the defendant, Target, having the opportunity to seek material pertinent to their case (during discovery). If you take a look the ABA link I posted you'll see that it carefully describes what types of documents are considered be under subject to the retention and tracking guidelines and requires employees to acknowledge they understand and agree by signing. Also take the steps necessary to devise an auditing, acceptable use, destruction and classification of all Electronically Stored Information (ESI) - that's the official term for anything not printed or scribbled on paper. In the end the courts determined in Mr. X's case that unless the firm could identify how the documents in question were intellectual property or how their disclosure in court could impact the confidentiality of clients (work product) i.e. tell us why you think these emails and other electronic documentation is related directly to your firms business and is un-related to this case - which it wasn't. The firm settled out of court for an undisclosed amount (the details are sealed...).
By applying policies regarding where personal vs. organizational documents and emails are stored, either electronically or paper document storage , requiring documents, emails and chats be appropriately labeled will contribute to avoiding confusing circumstances regarding what is and isn't proprietary information. This particular case became even more complicated when during the legal negotiations (discovery process) the firm stated that personal notes and items being introduced during the meetings should be classified as proprietary or sensitive work product thus mitigating its ability to damage the defendant (them). In order to provide some level of legal guidance for organizations seeking to formulate or revise their policies the American Bar Association (ABA) has devised a sample policy. Although Mr. X's particular case did set some legal precedent I reference another case "Zubulake vs. UBS Warburg LLC" were Mrs. Zubulake who was filing a gender discrimination case was awarded 30 million after the courts found that UBS deleted emails and other communications from the organization that affirmed her claims, on the other side in Teague vs. Target, Target had the case dismissed because Mrs. Teague destroyed her personal computer she used for working from home prior to the defendant, Target, having the opportunity to seek material pertinent to their case (during discovery). If you take a look the ABA link I posted you'll see that it carefully describes what types of documents are considered be under subject to the retention and tracking guidelines and requires employees to acknowledge they understand and agree by signing. Also take the steps necessary to devise an auditing, acceptable use, destruction and classification of all Electronically Stored Information (ESI) - that's the official term for anything not printed or scribbled on paper. In the end the courts determined in Mr. X's case that unless the firm could identify how the documents in question were intellectual property or how their disclosure in court could impact the confidentiality of clients (work product) i.e. tell us why you think these emails and other electronic documentation is related directly to your firms business and is un-related to this case - which it wasn't. The firm settled out of court for an undisclosed amount (the details are sealed...).
Sunday, February 7, 2010
System Egineering challenges: I talk to the developers so the customers don't have to.
I find myself working between customers who are super intelligent mathematician's and super intelligent, very capable developers - so what's the problem you may ask, it's getting these two parties to understand basic Systems Engineering (SE) and development principles. I begin with the words "Requirements", "CM" or delivery schedules and it makes these two sides of the aisle cringe. They change the topic of conversation to when can we get the capability under development deployed within the larger corporate systems - "we'll never know what it can do until we have in the system". I've actually learned new terms that have been invented to circumvent traditional engineering processes. Terms like "toxicity testing", this basically means we'll test the product just enough to ensure it doesn't break the larger system or severely impact other components. My favorite is the colloquialism "Code and Pray" that implies that agile development can only be successful if you can view the initial operation and deployment of a product from a hardened bunker. I've never felt so inadequate in a work scenario - I spend most of my time trying to convince my organization about the value of what I bring and how process and planning are integral for long term sustainment of operational systems.
When I began to work in my current organization we were staffed with 14 SE's and about 100 Math/Computer Science engineers and nearly double that in developers. The organization had just sustained a massive systems failure to one of the core data warehouses due to years of patching and applying makeshift code to continue life support to a custom built, non-scalable, non-supportable (no interface documentation or consistent logistics support). Yet the recognized failures in SE practices did not dissuade them from shedding the repressive bonds of industry best practices and the cut our SE staff to 7 and boosted developers by and equal number. The theory being that now that the developers were not encumbered by all our restrictions, testing requirements and documentation generation rapid development would proceed. Wow... they just didn't get it. They spent months in Tiger Teams to analyze and document the circumstances surrounding the failure and although the recognition that certain CM and architecture level development and integration may have prevented this each organization just couldn't bring themselves to slow down and do the necessary pre-work to ensure long-term continuity of operations. Probably because my organization values actual delivery of new products and services and not how long they continue to run efficiently. Pretty hard to justify spending a year talking and writing I guess. I mean it's hard to try to convince management to just imagine how much we could save if the systems continued to operate with problems or delays - quantification of this benefit is challenging and without a strong champion I guess I'm out of luck. So I continue to try inject simple SE practices without actually labeling it as such. Everyone once in awhile during the infrequent meetings where no one takes notes or offers suggestions .. or heck has an agenda... I slip one in and get caught. Then there are the traditional jokes, scoffing and uncomfortable glances. I really would like someone in leadership to make it known that that SE and formal processes need to be taken seriously - We need a champion to carry the message and enforce the practices throughout each project before we experience another major systems failure.
When I began to work in my current organization we were staffed with 14 SE's and about 100 Math/Computer Science engineers and nearly double that in developers. The organization had just sustained a massive systems failure to one of the core data warehouses due to years of patching and applying makeshift code to continue life support to a custom built, non-scalable, non-supportable (no interface documentation or consistent logistics support). Yet the recognized failures in SE practices did not dissuade them from shedding the repressive bonds of industry best practices and the cut our SE staff to 7 and boosted developers by and equal number. The theory being that now that the developers were not encumbered by all our restrictions, testing requirements and documentation generation rapid development would proceed. Wow... they just didn't get it. They spent months in Tiger Teams to analyze and document the circumstances surrounding the failure and although the recognition that certain CM and architecture level development and integration may have prevented this each organization just couldn't bring themselves to slow down and do the necessary pre-work to ensure long-term continuity of operations. Probably because my organization values actual delivery of new products and services and not how long they continue to run efficiently. Pretty hard to justify spending a year talking and writing I guess. I mean it's hard to try to convince management to just imagine how much we could save if the systems continued to operate with problems or delays - quantification of this benefit is challenging and without a strong champion I guess I'm out of luck. So I continue to try inject simple SE practices without actually labeling it as such. Everyone once in awhile during the infrequent meetings where no one takes notes or offers suggestions .. or heck has an agenda... I slip one in and get caught. Then there are the traditional jokes, scoffing and uncomfortable glances. I really would like someone in leadership to make it known that that SE and formal processes need to be taken seriously - We need a champion to carry the message and enforce the practices throughout each project before we experience another major systems failure.
Saturday, February 6, 2010
Theory Y vs. X
Fellow Bleary-eyed bloggers I'm back again, to kick some old-school science on the IT/Management subject and hopefully engage and entertain - folks please remember this is a blog not a forum for pieces of your life thesis - i.e free format characteristics are appreciated. I know we have a tendency in business school to write everything as if its being presented to a client. You can still write blog-style without appearing to be a high-functioning
Soooo we had a guest speaker this week in class - I love guest speakers BTW, its pretty cool to hear from different people about interesting aspects of their work lives - does that make me like a work-oriented voyeur? Probably not, because that would imply I sneak into other peoples classes to observe their guest speakers.. right? Sorry for the sidebar but I'm like puppy in that way.... All salivary glands... no focus. So our guest speakers topic was a subject near and dear to my heart - the stages of employee development and a a distinguished theory regarding the different types for management.
Basically there is this management theory developed by Douglas McGregor in his 1960 book "The Human Side of Enterprise" that says there are two types of managers in business - those who think everyone hates their job and needs motivation by reward and punishment and they only work fro money and job security i.e. your employees would rather be doing anything else besides working for you and first chance they get they'll shank you in the breakroom over the last Diet Coke in the vending machine (Theory X). On the opposite side of the fence McGregor states there are those managers who believe that work can be as fun as drinking with your frat brothers... Theory Y introduces the notion that if work is challenging and stimulating to the individual then they can align their goals with the organization and they won't require the old carrot/stick method to get work done.
Sioux (our guest speaker) made an interesting point when she stated that a lot of Theory Y goes back to something I covered in last weeks blog about Generation Y (not a coincidence I guess) - motivation in work and how managers can better achieve it. When we talked about the MBA graduates who stated they valued increased responsibility and self direction in their work over monetary compensation that jived directly with Theory Y. Sioux (like me) thinks that Theory Y involves engaging your employees and determining what type of work activities really get them motivated. Figure out if they're better suited to other positions our projects within your organization and make sure their personality gels with job - you might get more out of them and they may work harder and better because of their interest and appreciation.
Subscribe to:
Posts (Atom)