How to Address Data Center Operations Challenges - PowerPoint PPT Presentation

1 / 19
About This Presentation
Title:

How to Address Data Center Operations Challenges

Description:

Principal, Hype-Free. June 4, 2003. Hosted by ... Source: Hype-Free Consulting. Security Technology. Security Operations. Staff decisions ... – PowerPoint PPT presentation

Number of Views:26
Avg rating:3.0/5.0

less

Transcript and Presenter's Notes

Title: How to Address Data Center Operations Challenges


1
How to Address Data Center Operations Challenges
  • Jon Oltsik
  • Principal, Hype-Free
  • June 4, 2003

2
How many industry analysts does it take to change
a light bulb?
  • Answer This may seem like a simple question but
    it has extensive ramifications. Therefore,
    answers are best handled on a firm-by-firm basis.

3
Industry Analyst Responses
  • IDC 7 billion light bulbs worldwide, CAGR 4
  • Meta Define light bulb transformation business
    process
  • Forrester The Holistic Internet Illumination
    Voyage (Giga will cover IT impact)
  • Gartner
  • New nanotechnologies will make light bulbs
    obsolete by 2028 (0.8 Probability)

4
Data Center Futures
5
Data Center Management Operations
Billy Gates, Manager, Data Center Operations
Scotty McNealy, Manager, Security Operations
6
Billys Challenges
  • People
  • IT organized around technology not business
  • In constant fire-fighting mode
  • Process
  • Lack of defined policies
  • Too many manual processes
  • Technology
  • 37 annual device growth
  • Too many point tools

7
Scottys Challenges
  • People
  • Limited security group
  • Limited security knowledge and training
  • Process
  • Lack of enterprise security policies
  • Limited security preparation
  • Technology
  • Too many point tools
  • No end-to-end security picture

8
Addressing The Issues
  • IT Governance
  • Organizational Model
  • Data Center Operations
  • Security

Common
9
IT Governance
  • Definition
  • A standard set of policies and procedures for all
    IT operations activities
  • Models
  • IT Infrastructure Library (ITIL). Developed in
    UK.
  • Defines best practices in 24 IT disciplines.
  • Control Objective for Information and Related
    Technology (CobiT).
  • Four domains, planning and organization,
    acquisition and implementation, delivery and
    support, and monitoring
  • Caveats
  • Phased approach
  • Must be supported by Business Governance

10
Success Stories
  • Global adoption of ITIL, 1997
  • Savings of over 500 million in first 4 years
  • 6 to 8 cut in operating costs
  • 15 to 20 reduction in technology staff
  • When IT processes are done by 5,000 people
    consistently across one company, service
    management can deliver tremendous savings.
    Morton Cohen, Manager, Global Service Management

11
IT Organization
  • Issues
  • Hierarchy of services
  • Staffing
  • Accountability
  • Compensation
  • Communications
  • Wells Fargo Bank
  • Internet Banking

12
Improving Billys World
  • Rely on IT Governance to cope with scale
  • Support with tools as necessary
  • Provide a solid baseline
  • Service chain
  • Set standards Thresholds, data. . .
  • Build management into applications
  • Measure and communicate

13
Scottys World
900M
120,000
World-wide Attacks
800M
Blended Threats (CodeRed, Nimda, Slammer)
100,000
  • SQL Slammer, 1/24/2003
  • Effected over 200k servers
  • Infected servers doubled
  • every 8.5 seconds
  • BOA, Continental Airlines,
  • Microsoft, City of Seattle
  • Over 1 billion in damages

700M
600M
80,000
Denial of Service (Yahoo!, eBay)
500M
Infection Attempts
60,000
Network Intrusion Attempts
Mass Mailer Viruses (Love Letter/Melissa)
400M
Malicious Code
Infection Attempts
300M
40,000
Zombies
200M
Network Intrusion Attempts
20,000
Polymorphic Viruses (Tequila)
100M
0
0
Analysis by Symantec Security Response using
data from Symantec, IDC ICSA 2002 estimated
Source CERT
14
Typical Response
15
Improving Scottys World
  • Appoint CSO
  • Reports to CEO
  • Combine security groups
  • Physical and Infosec
  • Training
  • Employees
  • IT
  • Communications

16
Improving Scottys World
World-class Security Organization
Phased approach through facilitated workshops
Direction
Company-specific requirements
Industry-specific requirements
  • GLBA
  • HIPAA
  • ISO 17799
  • CISSP CBK
  • NIST 800-37

Security Policies and Procedures
  • ITIL
  • ITSM
  • CobiT

IT Governance
Source Hype-Free Consulting Treadstone71
17
Improving Scottys World
  • Defense-in-depth
  • Understand security service chain
  • Review constantly
  • Designate a response plan and team
  • IT business team
  • Design acceptable plan by service
  • Practice, practice, practice

18
Summary
  • Big issues with
  • IT Operations
  • Security
  • Fix processes with strong IT governance
  • Fix organization to bridge the business and IT
  • Address technology issues last

19
Thank You
  • Jon Oltsik
  • Principal, Hype-Free
  • 978.263.6974
  • joltsik_at_hype-free.com
Write a Comment
User Comments (0)
About PowerShow.com