Wednesday, January 04, 2006

10 New Year's resolutions for net admins

By Rick Vanover

As 2005 rolls to a close, many IT professionals are deciding what to make a priority in 2006—as well as what to relegate to another burner because the back burner is still full.

Develop security strategies for enterprise wireless networking

Our reluctance to embrace WLANs isn't going to make the issue go away. Now's the time to develop the protections at software and authentication levels, treating the office wireless network like the Internet from the security point of view.
IT professionals, users, and everyone in between can benefit from the wireless workplace. However, we need to accept that yes, our office now extends to Panera Bread. Our task is what can we do to make it secure?


Put a moratorium on buzzwords and phrases


I dread hearing buzzwords and overused phrases as much as any of you. Here are my top three:

What can we do to move forward? How many times have you had meetings that involved too many nontechnical people and that concluded with this statement, which lead to another meeting, which lead to the same conclusion… but yet brought no results?

We don’t have the bandwidth for … Sorry to hear that. I guess this isn’t us asking for such resources, but us telling you that we need such bandwidth. Whether it be staff resources, computing horsepower, or a fat pipe on the LAN, if the case and need are presented well, we need that bandwidth.

There needs to be some accountability… This is the worst. What's funny is that the people (management) who use this term don’t really exact any accountability. It’s a word that's more visible in the early stages of a project. However, it mysteriously stops popping up later on—even when results warrant some accountability!

Make a decision on leasing vs. purchasing IT equipment

Many organizations have blanket rules to lease or purchase IT equipment. A better approach may be a standard set of criteria that's applied to systems during planning to determine their scenario. Consider making a provisioning chart that will help determine whether a system is a candidate for leasing or direct purchase. This will lay forth specific criteria that, depending on your IT climate, will more clearly identify candidates for leasing. Here's a sample system provisioning chart to determine whether a lease is appropriate:

Of course, there are always many factors (like price and money!) that will influence how assets are procured. But a planned implementation with the end in mind (such as a lease return) can simplify the ongoing support of systems, especially as they become more complex.


Avoid 5eCuR1TY & P@sSW0rD Ov3Rk1!!


What's worse than working with your own security requirements? Easy: It's dealing with another party that has security requirements at your level or higher. Sure we’ve got to be secure, but how many times has security locked out an authorized party? I’ve had it happen to mission-critical systems for silly things like a MAC address not authorized to participate on a network (in the case where a secondary system has a different MAC address).

Or how about this complex password requirement: 10 characters, including five special characters and mixed case for the remnants, and use of numbers. The password is: 8$4rR#Z@! . Don’t bother counting, it is that way by design. (Yes, there is a space at the end of the password.) That was fun to troubleshoot after it was assigned.
Really, wouldn’t investments in brute force detection, lowered bad password thresholds, and automated password reset utilities be worthwhile?

Take a stand against the off-brand!

How much time have you spent working with inferior equipment? It can be viewed as pennywise and pound foolish to skimp on the equipment dollars. Using top-tier quality, branded equipment provides a superior support channel for drivers, issues, and spare parts. This applies to servers, networking equipment, PDAs, mobile phones, and even cables and tools.

Great efficiencies can be made by consolidating vendors of equipment (more on that later) as well as gaining a professional appearance by having the equipment represent an extension of the service provided by the technology. Besides, if the equipment fails, this is too easy a point to get burned on.

Make sure you know what you're getting for the money

Price is always important, but remember to consider what you get. For example, on the server platform, analyze items like standard warranties as well as price-per-Gigahertz or -Gigabyte. Of course, we are all dealing with shrinking budgets as well as increased service responsibilities, so price is definitely a factor that will not go away. Sure, an easy solution is to buy up and overprovision systems at the start—but that goes too far. A delicate balance needs to be met.

Recognize that it's time to retire NT

You would be surprised how many installations still have Windows NT Server 4.0 systems running vendor -provided mission-critical applications, legacy Windows domain controllers, and government systems. Some organizations still have it as the standard.
Core support for NT has stopped, and driver support is soon to follow on server-class systems. You can live without service packs—but not drivers.

Reap the benefits of platform standardization

Let’s all take a page from the Southwest Airlines playbook as a good example of how to keep overhead low. By having all equipment, operating systems, and software versions standardized, you'll realize savings. For example, consider the small to midsize enterprise that has a single server platform. This greatly enhances the internal support options. With a single server platform, you can:
• More quickly build a server (standardized process)
• Maintain fewer spare parts or systems (less unused inventory)
• Reduce staff training knowledge requirements (less training expenses)
• Build a higher competency on the standardized platform (better service)
• Manage fewer baseline images, if used (less storage requirements)

For software title and version standardization, a big expense in compatibility testing is reduced to a single instance. Having lower overhead without compromising the result of the IT server is achievable for many organizations. It may be difficult to migrate to a standardized environment across the board (notebook, desktop, server, operating system, productivity suite, etc.), but the long-term benefits are habits of successful organizations. Even if a system is "over-provisioned" to meet the standard, that may be better than an array of oddball systems in the enterprise.

Just say No!

Is it that tough? Well, sometimes it is. The common plight of the IT professional: Here is the functionality, now make it happen. And of course you don’t get any more resources (money).

When using the No! card, be sure to cite business rules, fundamental standards, resource requirements, or other major obstacles to substantiate your decisions. It's difficult to judge when to pull the No! card. IT should use it if they simply can’t do what's requested. The easy answer is to outsource it or contract some help for the task, but even that can warrant the No! card. There's no “Easy Button” in IT, but the No! card can be fun.

Address ownership roles

One of the biggest issues that arises in IT is ownership, specifically for an entire system that has shared use with vendors and many internal departments. For example, take a vendor-provided system that interfaces with operations and IT. Does the vendor own it? Does operations? Does IT? It is mission critical, but no one wants to touch it—at least not when there is an issue.

When systems are incepted, there should be a clear chain of command. IT doesn’t generally want to deal with operational topics, operations doesn’t want to (and usually can’t) deal with IT topics, and the vendor gets frustrated with all the IT groups and operational differences for a system. It's a good investment to get premium support from vendor-provided systems. This keeps IT groups in the best position by having their infrastructure and security topics met, operations dealing with the vendor for support, and the vendor having ultimate ownership of the system—especially if there is an issue! One less fire to deal with.

3 comments:

Anonymous said...

Thank you!
[url=http://txyschcv.com/pait/hzvr.html]My homepage[/url] | [url=http://slmddqru.com/nxpv/jlmp.html]Cool site[/url]

Anonymous said...

Nice site!
My homepage | Please visit

Anonymous said...

Nice site!
http://txyschcv.com/pait/hzvr.html | http://xjxgcnqq.com/dawt/jgvv.html