You've noticed it seeping into the IT workday. An end user calls the support desk for help connecting a new iPod to the desktop. Another asks how to add Skype capability to the desktop. Consumer IT-technology and devices initially designed and marketed for use in the consumer space-has infiltrated the workplace.
CIOs overseeing the invasion of consumer technology know it's not enough to simply write a management policy, post it on the intranet and then revisit it a few years down the road. "Stagnant policies and procedures just aren't practical for these types of technology," says Rob Israel, vice president and CIO at US$400 million John C. Lincoln Health Network . Policies need to be revised on a regular basis, according to user needs and organizational security concerns; Israel revisits his every four to six months. And for any policy to work, CIOs need to have a strong communication strategy, involve users in policy creation, build in security and find a balance between restriction and freedom of use.
Communicate Existing Policies
"I know some CIOs who have 150 or 200 security policies. That's just way too many," says Israel. His consumer IT-related policies total 30. The limited number makes it easier to communicate the policies and their updates. When Israel's team makes a policy addition or change, they explain the rationale to users with straightforward language. "We'll say, 'Do you know why we encrypt e-mail?' Then, we'll explain why we do it in three or four sentences," says Israel.
Involve the End-User Community
Jay Dominick, formerly CTO at Wake Forest University and now CIO at the University of North Carolina, sees more consumer technologies being introduced every day. Most come from students, who tend to have both disposable income and time on their hands.
"Our policy-making process involves multiple layers of faculty, staff, student input and the legal office," says Dominick. "So it can take six months or a year to reach consensus." In 2000, when Napster hit university networks, Dominick says "it took almost two years before there was a response from universities as to how to manage it."
That was then. Students now have input in forming the policy, so the specifics get socialized among the user community before the policy debuts. This way, there are no surprises.
"A policy that is a surprise won't get followed," says Dominick.
Balance Policy Strictness
Given the confidentiality restrictions around patients' medical data at John C. Lincoln Health Network, Israel employs a high level of strictness in his usage policies for consumer IT. At Kennametal, a US$2 billion industrial manufacturer, there's more leeway. IT works closely with end users to find suitable workarounds to its strict policies, says Raj Datt, VP and CIO of Global Information Technology. An example is a request for YouTube functionality by the sales staff. "Our sales team came to us asking for functionality so they could show potential clients current pricing and inventory products from a video perspective. We responded by enabling BlackBerry access to our ERP system for real-time customer data," says Datt. Working with users to create a viable alternative has helped change their view of Kennametal IT from that of a cost center to a value-driven organization. "If we don't give them an alternative, then they would just bypass IT," Datt says.
- White PaperWhat you don’t know can destroy your business. It’s hard to imagine modern business without the internet but in the last few years it has become fraught with danger. Read on to discover how internet security can give your business a competitive advantage.
- White PaperJoin industry expert Martin Tuip to discover best practice strategy for the archival and removal of .PST files using email archiving. Learn how to ensure long-term email records are there when needed, and reduce the risk to your business and clients.
- White PaperJoin industry expert Bob Spurzem and Chuck Arconi of Fox Hollow to discover how to reduce Exchange total storage and keep it at a manageable level. Learn how Exchange storage growth can be contained without sacrificing security and accessibility.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
Chris Hoff on Virtualization and Cloud Computing 20 November, 2008 10:55:00
Chris Hoff, chief security architect for the systems and technology division at Unisys and an advisor on the Skybox Security customer advisory board, is one of the biggest critics of virtualization security out there. Not because it isn't important - but rather because it is vital and needs to mature rapidly. - +
Cybersecurity is focus of new start-up incubator 20 November, 2008 07:19:00
Texas uni announces the Institute for Cyber Security.The University of Texas at San Antonio Tuesday announced a technology incubator aimed at fostering IT security-based start-ups within the state. - +
Dilip Sarangan on Physical Security M&A 20 November, 2008 11:18:00
Dilip Sarangan tracks physical security companies for Frost & Sullivan. He expects the industry's "need to have" products to weather the economic storm well, with the big players (now including IBM and Cisco) looking for value-priced acquisitions. - +
International Challenges in PCI Security 20 November, 2008 09:15:00
In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective. - +
PCI council sharpens oversight of security auditors 19 November, 2008 10:53:00
Quality assurance plan targets security assessors and scanning vendorsThe PCI Security Standards Council Monday unveiled a plan to sharpen oversight of the hundreds of security-service providers now authorized to evaluate merchant networks under the organization's Payment Card Industry data standards.
Vignette Announces 2008 Excellence Awards 21 November, 2008 10:50:00
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 20 November, 2008 17:34:00
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 20 November, 2008 12:06:00
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 20 November, 2008 12:04:00
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 20 November, 2008 12:02:00
|
||
|
||
|
|
||
|
Know thy self: Reduce costs, secure data and ensure compliance with identity management
Midsize businesses cannot operate effectively without the ability to control access to their networks and business systems. A strong identity management platform can play the role of gatekeeper and guardian of business intelligence and information. Read on to discover how you can create a strong identity management plan to protect your business.














