An aggressive bank vice-president commissions an outside company to develop a PC banking application. The renegade programmers create a snazzy interface, terrific functionality and a security hole a mile wide. One morning, the CEO picks up the newspaper and reads that his bank's records have been hacked. His first call? To the CIO's office -- "You're fired!" The CIO protests: "I didn't even know this project was under way!" But it doesn't matter, does it? The CIO is liable for every use of technology at the bank.
IS organisations are losing control of information technology because technology is no longer just a way to automate back-office processes or collect data; it has become part of every company's product, from the initial design stage to customer service. The Internet and its corporate cousin, the intranet, put meaningful technology power directly in the hands of employees, customers and business partners.
CIOs cannot and should not try to prevent the move to wider access and the Internet. Locking up corporate data and thereby letting critical business projects languish in an endlessly growing queue won't be tolerated. So how can companies balance technology innovation and manage business risks?Forrester Research says large companies must establish a "technology democracy", a change through which IS will guide technology use but business managers will have strategic control. In some companies, the magnitude of that change will be akin to a totalitarian dictatorship becoming a modern 20th century democracy: government guides, but the citizens have ultimate control.
The key to creating a successful technology democracy is an open partnership between IS and senior management.
Partners in governance
Together, the CIO and CEO will agree to pass laws, protect the national interest and engage in public works to promote the general welfare. Those three mandates will take different forms depending on whether IS is empowering company employees or helping business managers connect with external parties -- customers, partners and technology vendors.
Only rule of law can set broad guidelines that identify the IS group's responsibility and where the business units have discretion. Business managers and IS policy makers must define clearly a set of boundaries within which corporate citizens -- that is, users -- have freedom to experiment.
National security is everyone's concern. The CIO cannot be 100 per cent responsible for security; data belongs to the business, and managers must have the freedom to use it within the range of tolerable business risks. Even so, IS must provide clear procedures for limiting security exposure when using the Internet and solid recovery mechanisms when intranet data is lost or systems are overwhelmed.
As far as public works, for companies to take advantage of the Internet, managers must supply specific infrastructure and services, including a Web-based information backbone, useful tools and a distributed security architecture. The availability of such a self-service environment means IS must also take on a greater role as teacher and consultant to the rest of the enterprise.
IT freedoms
In a technology democracy, the contract between a governing IS department and its citizens is based on providing employees with IT to tackle new opportunities and solve business problems on their own. That philosophy shifts the role of governance from control to facilitation.
For example, IS cannot test every intranet application and edit every Web page -- nor should it. So business managers must take on the responsibility of making sure their employees use the intranet in a professional manner, not posting highly sensitive, inappropriate or lewd content. The freedoms of democracy require a responsible, educated citizenry. IS can help executives encourage user creativity while limiting potential risks by establishing ground rules to govern intranet behaviour, putting some safeguards in place and providing some end-user training. An example of each of those roles follows:LAW Obey software-licensing laws.
The Internet is full of tempting, free applications, but many of them require users to click on a licensing agreement page. In a technology democracy, employees must take responsibility for complying with copyright and distribution regulations.
PROTECTION Provide an escape hatch. Inevitably, users will disable desktops with Internet downloads or kill hard drives with megabytes of multimedia content. They will try tools like CyberMedia's Oil Change and Tune Up.com's PC TuneUp, that find new drivers and updated software versions on the Internet and upgrade desktops automatically, thus mucking about with their PCs' configurations. IS should offer users a panic button -- a set of network scripts that flush corrupted hard drives and restore PCs to the standard corporate configuration.
EDUCATION Create an Internet community college. To use the new technology effectively, staff and managers alike will need help. IS should staff a learning centre that offers a curriculum for workgroup Webmasters and classes for administrative assistants. IS-trained product managers from the Internet college can act as consultants to help executives plan, budget, staff, implement and support complex intranetsystems.
Good neighbours
To encourage creativity, internal systems need to be as open as possible; but when dealing with the outside world, the technology democracy must maximise the value of external connections while minimising business risk.
Smart technology governance will accomplish that with strategies such as business contracts, technology tools and support specialists. For example, if intranet information about inventory levels was to appear suddenly on the Internet, there would be only limited damage to the business. But if business partners' pre-patent designs appeared, there would be legal repercussions.
Because IS cannot be held responsible for security breaches beyond its own corporate walls, the best safeguards to protect shared intellectual property are contractual.
To monitor Internet and intranet traffic, however, a technological strategy is available. IS should provide business units with toolkits, such as those from Sequel Systems or Network General, that identify visitors and flag unusual activity. Security Dynamics and VeriSign offer tools that allow users to issue tokens or certificates to validate a user's identity. IS needs to make sure business units know how to use those solutions.
A support organisation that maximises relationships with the outside world is the third pillar of the democratic technology's foreign policy. Partners and customers with questions about the Web request system or the intranet inventory link will call sales, manufacturing or customer service -- not IS. Service experts need to be able to forward technical queries to help desk gurus with the single push of a button.
No CIO can effect the transformation from IS department to technology democracy alone. Critical success factors from the business include corporate willingness to take on risk, a company-wide culture of professionalism and a commitment to technology skill building.
With a few successes driven by the new culture of facilitation under IS's belt, business managers with Internet and intranet requests, and wallets open wide, will come running to IS.
Who else can combine an understanding of the business with knowledge of available resources at a price no outsourcer can meet?Waverly Deutsch, a director at Forrester Research Inc, can be reached at wdeutsch@forrester.com. To read "The Technology Democracy," register on the Web at www.forrester.com/
- White PaperJoin industry expert Bob Spurzem and Chuck Arconi of Fox Hollow to discover how to reduce Exchange total storage and keep it at a manageable level. Learn how Exchange storage growth can be contained without sacrificing security and accessibility.
- White PaperYour organisation may well have devised and implemented an Acceptable Use Policy (AUP) some time ago in order to guard against the risks of inappropriate use of computer systems by your workers, but are you confident that your AUP remains 'fit for purpose'? Read on to discover how you can enhance the effectiveness of your AUP.
- White PaperLearn to tie virtualized computing to virtualized storage, to offer a dynamic set of capabilities within the data centre and create improved performance and system reliability. Discover how best to utilize EMC Celerra in a VMware ESX environment.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
TJX Maxx hacker banged up for 30 years 09 January, 2009 11:26:00
Key figure in the infamous TJX Maxx Wi-Fi hack of 2005 has been sentenced to 30-years in prison by a Turkish court.Maksym Yastremskiy, the Ukrainian accused of being a key figure in the infamous TJX Maxx Wi-Fi hack of 2005, has been sentenced to 30-years in prison by a Turkish court. - +
Data breaches rose sharply in 2008, says study 08 January, 2009 08:27:00
More than 35 million data records were breached in 2008, according to the Identity Theft Resource Center.More than 35 million data records were breached in 2008 in the U.S., a figure that underscores continuing difficulties in securing information, according to the Identity Theft Resource Center (ITRC). - +
Rogue SSL certificate exploit puts VeriSign on the spot 07 January, 2009 11:04:00
Wishes "white hat" researchers had notified VeriSign before public demo.Following the success of researchers last week in creating a false SSL certificate based on VeriSign's RapidSSL brand, the company is scrambling to explain how it happened, how it's preventing it from reoccurring, and whether its other SSL certificate-generation services are at risk. - +
With Gaza conflict, cyberattacks come too 05 January, 2009 08:03:00
Pro-Palestinian hackers have defaced thousands of sites following attacks in Gaza.The conflict raging in Gaza between Israel and Palestine has spilled over to the Internet. - +
5 ways to secure your Blackberry 18 December, 2008 12:58:00
What do Tom Cruise and the McCain campaign have in common? They have both been bitten by the loss of a Blackberry. Mobile expert Dan Hoffman gives advice on how to keep your cherished mobile device safe, even if it's out of your handsWhat do Tom Cruise and the McCain campaign have in common? They have both been bitten by the loss of a Blackberry. Mobile expert Dan Hoffman gives advice on how to keep your cherished mobile device safe, even if it's out of your hands.
IT industry veteran advises caution on outsourcing selection in light of Satyam problems 09 January, 2009 21:45:00
Research software developer appoints Susan Dart to new Business Development Director role 08 January, 2009 09:08:00
Research software developer appoints Susan Dart to new Business Development Director role 08 January, 2009 09:08:00
Anyware Introduce Two Powerful PCI TV Tuner Cards with S5 Power Up and Windows Media Center Remote 07 January, 2009 17:30:00
Fortinet Cures Mobile Phone “Curse of Silence/CurseSMS” Attack 07 January, 2009 16:30:00
|
||
|
||
|
|
||
|
Understanding Email Marketing: A Guide for SMBs
Email marketing is often viewed as a marketers silver bullet. If used effectively, email campaigns will provide strong results for a limited spend each and every time. Download this white paper to discover how email marketing can work for you and your business.










