Written by Tsvetanka Stoyanova
Metrics and the other ways to measure performance are very popular among technical people. Almost every aspect of a computer’s performance can be and is measured, however when it comes to service metrics for IT personnel and organizations this is one area that companies should pay close attention to.
Computers or machines are easier to measure because there are little to no subjective factors. But with organizations, and especially with people, the subjective factor becomes more and more important and frequently, even if the best methodology is used, the results obtained from metrics are, to put in mildly, questionable.
Who Needs IT Service Management Metrics
Metrics are used in management because they are useful. Metrics are not applied just out of curiosity but because investors, managers and clients need the data.
There is no doubt that metrics are useful only when they are true. I guess you have heard Mark Twain's quote about “lies, damned lies, and statistics” (or in this case – metrics). True metrics are achieved via using reliable methodologies. It is useless just to accumulate data and show it in a pretty graph or in animated slideshow. This might be visually attractive but the practical value of such data is null.
However, even when the best IT Service Management metrics methodology is used, deviations are inevitable. Therefore, one should know how to read the data obtained from metrics. It is also true that metrics, including IT Service Management metrics, can be used in a manipulative way, so one should be really cautious when he or she reads metrics and above all – when making decisions based on these metrics.
Where to Look for IT Service Management Metrics
There are several metric methodologies in use for IT Service Management, so you can't complain about the lack of choice. Some of these IT Service Management metrics methodologies have been borrowed (with or without adaptation) from other industries, while others have been specifically designed for IT Service Management.
Many organizations, including ITIL and ITSM regularly publish books and reports on IT Service Management and even though these are not the only organizations, which define the de-facto standards for IT Service Management metrics, there books and reports are among the top authorities in the field. A short abstract from the “Metrics for IT Service Management” book by Peter Brooks can be found here: The sample shows the TOC and includes the first couple of chapters, so if you have the time to read it, it should give you a more in-depth idea of what IT Service Management metrics are and how to use them.
In addition to the general metrics for IT Service Management, there are sets of metrics for the different areas of IT Service, such as configuration management, change management, etc. Therefore, if you are interested in measuring only a particular subarea of your IT services, you don't have to go through the whole set of IT metrics just to get the information for the area in question. Many IT consulting companies have also developed benchmarking and other methodologies that measure IT Service Management and these documents are also useful.
In addition to ITIL, ITSM, and the various consulting companies, another place where you can get IT Service Management metrics ideas from are the sites and the marketing materials (i.e. white papers) of vendors of software products for IT Service Management. Some of these vendors implement the metrics of other organizations. This is why IT Service Management metrics are often similar and sometimes they are just the same set but from a different angle, which of course can lead to different results.
There are many vendors that you can access by conducting a search on your search engine. Whenever possible get a trial version (if the vendor offers one), give it a test run and decide for yourself if what you got is what you need. As I already mentioned, IT Service Management Metrics are only useful when true. That is why you will hardly want to waste your (and your employees') time and money on a set of IT Service Management metrics, which are not applicable in your situation.
With so many metrics that lead to so many different results in the same situation, one sometimes wonders if IT Service Management metrics do actually measure one and the same thing and if they are of any good, Yes, IT Service Management metrics are useful but only when used properly.
Wednesday, March 25, 2009
IT Service Management - Metrics
Posted by Roy Zafar at 6:07 AM 0 comments
Labels: Data Center, Tech and Trends
Tuesday, March 3, 2009
The Latest on Power Usage Effectiveness (PUE)
Written by Rakesh Dogra
The technical language related to any field including IT is full of acronyms most of which are quite handy. For many of us in the data center world we are now aware of the latest acronym; PUE. If you don’t let me tell you that it stands for Power Usage Effectiveness. In this article we will discuss about this term and the latest buzz in the PUE arena.
Data centers are energy hungry monsters and their need for energy keeps rising continuously. It reminds of a mythical monster in the Oriental philosophy that was named Sursa whose mouth increased in size in proportion to the prey that had to be devoured.
Attempts are being made to tame the data center monster so that they perform to their maximum possible ability while consuming the least possible amount of power by having the maximum possible energy efficiency. But then there needs to be certain parameters which define the efficiency and give a standard way to measure it.
The Green Grid which is a non-profit organization of IT professionals came out with two metrics known as PUE and DCiE which are mathematically reciprocal of each other, though the former has got a wider acceptance in the industry.
Mathematically the Power Usage Effectiveness is defined as the ratio of the total power consumed by the data center to the power consumed by the IT equipment.
PUE basically gives you an idea about the total power being consumed and the amount going towards actual computing purposes. The total power includes the power supplied to cooling equipment, chillers, lighting, storage nodes etc in addition to the IT power which counts the power delivered for servers, workstations, switches and so forth that are directly involved in the information processing going on in the data center.
This means that the PUE of an ideal data center would be one while on the upper limit it could go anywhere upto infinity. Of course the value of 1 is just a utopian idea and I don’t think there will be every a data center with such a value at least not with the current technology.
Regarding the actual value of PUE in the industry leading companies such as Google and Microsoft which have some of the largest data centers are really very efficient. A recent report published by Google stated that the efficiency of their data centers is in the region of 1.21 while Microsoft also expects their new data centers to have a value in the similar range of about 1.22.
However not all enterprise data centers have that value of PUE but lie somewhere in the region of 2.0. This effectively means that for every one unit of power which goes into their servers and other IT equipment, one extra unit of power is required for other purposes such as cooling equipment. A data center with a value of PUE above 3.0 is considered really poor in terms of its energy efficiency.
The increasing attention being given to data centers by the new US President may push the PUE metric forward. If the recommendation provided by IBM’s CEO comes to fruition then we will see Federal data centers more efficient in 3 years. To achieve this goal will require a measurement that may include PUE or some other metric. If a energy efficient measurement is adopted in Federal data centers it may not be long before it is adopted in data center throughout the US.
Reports and surveys have indicated that IT departments are less concerned about the energy efficiency of their facility and more concerned on the immediate cost savings. This frame of mind will need to change if energy efficiency in the data center is to have traction. It just may require penalties in the form of a tax from the Federal government or utility companies to change the attitude toward energy efficiency.
The adoption of such standards and metrics will also encourage manufacturers of IT equipment to produce more energy efficient products. The requirement will expand to other equipment such as mechanical and electrical systems and so forth.
Lastly it can be said that despite the slow adoption, PUE has become one of the most talked about metrics in the data center industry. For PUE to take shape as a green standard for measuring energy efficiency will require the convincing or pushing of CIO’s and the remainder of the C suite.
The true problem with PUE is not everyone is convinced that it is the most accurate measurement for energy efficiency in the data center. In addition, many believe that most data centers do not have the capability to properly measure and document such information.
At the moment the Federal government has not made any announcements regarding a mandate to make Federal data centers energy efficient. It is likely because Federal agencies like the Environmental Protection Agency, Department of Energy and research groups they sponsor have not come to a clear consensus on how to properly measure energy efficiency.
Other measurements such as Site infrastructure energy efficiency ratio (SI-EER) as defined by The Uptime Institute is essentially the same metric as PUE.
Measuring data center energy efficiency will grow in importance as energy costs escalate and the demand for powering IT equipment pushes the data center envelope.
Despite the lack of adoption, many including the originators of the Green Grid’s metric have been encouraging IT departments to monitor and document your data centers power and IT trends. The information may not provide an immediate insight, but it will give you a head start on tracking your data center against a mature metric along with provide a fingerprint of your data center energy consumption all of which most never had before.
Posted by Roy Zafar at 7:47 AM 0 comments
Labels: Data Center, Tech and Trends
Monday, March 2, 2009
Absence of Evidence Does Not Equal Innocence
Written by Paul Thackeray
Imagine, for a moment, that the delete button on the email client of all of your employees was permanently disabled. This would mean that your email users would be forced to save and organize their email into various folders within the email client, and then when their email file reached quota, your IT team would have to move all the old email into large PST files or other forms of backup.
This now means that you have email scattered all over the network in any number of stores. Now imagine that your organization is implicated in a lawsuit and the attorneys for the plaintiff have issued subpoenas for all of your electronic records, including email, related to the lawsuit. How do you access those emails?
Well the good news in this scenario is that you at least have all of the email. Often businesses operate under the assumption that if there is no record of the topic in question, then they cannot be held responsible. This is simply not true. Businesses that delete email, even as part of its standard business practice, but have no way of retrieving it in the future, can still be held liable for the information contained within the deleted email. Simply having all of the email, however, is only half the battle. Companies must also have mechanisms in place to quickly search and retrieve the emails in question.
While the suggestion that a disabled delete key may seem like an extreme scenario, the concept behind it is important: Business email should not be deleted until the organization has some way to archive and, more importantly, retrieve email.
Archiving for the rest of us
Organizations in heavily regulated industries, such as the financial, government and healthcare industries were among the first to put policies and solutions in place in order to satisfy regulatory standards for their specific markets. But all organizations, no matter what vertical, need to very carefully assess what risks they face by not saving email.
It is an unfortunate fact that most organizations will at some point in the course of normal operations be implicated in lawsuits. Litigation discovery, or e-discovery, involves all parties in a lawsuit and requires that all data or information relevant to the lawsuit be provided as requested by the court of law. The cost of finding and producing such information can often outweigh the actual damages claimed in the lawsuit itself. This is most often the case for companies that are not using an email archiving solution.
Key features to look for
Message archiving solutions should have the ability to full index all email to enable simple search and retrieval of emails containing specific key words in an e-discovery request as well as for corporate policy control. Retention policies are also a key factor when determining which solution fits the needs of the organization; archiving solutions should have the storage capacity to keep email records for long periods of time in order to satisfy regulatory compliance standards. All functionality should be organized via a simple user interface that is easy for the administrator to use, but that also captures a high-level glimpse into the performance of the message archiving solution that can be easily demonstrated to management or legal counsel.
The bottom line: there is no single reason for implementing an archiving solution. But one thing is for certain, email must be retained by every organization that relies upon it as one of its main business communication channels. Deploying an easy-to-use solution will save a lot of time and resources for the organization in the long run. Further, it is a much simpler and more practical solution than disabling the delete key on the email client.
Posted by Roy Zafar at 7:43 AM 2 comments
Labels: Data Center, Tech and Trends
Thursday, February 26, 2009
Native PCI Express I/O Virtualization in the Data Center
Written by Marek Piekarski
I/O virtualization based on PCI Express® – the standard I/O interconnect in servers today – is an emerging technology that has the capability to address the key issues which limit the growth of the data center today: power and manageability.
Data Centers and Commodity Servers
Over the last decade the demands for increased performance have been answered by simply providing more and more hardware, but now this trend is proving to no longer be sustainable. In particular, power and management have become the dominant costs of the data center. More hardware is no longer the solution that is needed for growth.
Server architecture – what is I/O?
I/O can be defined as all the components and capabilities which provide the CPU – and ultimately the business application – with data from the outside world, and allow it to communicate with other computers, storage and clients.
The I/O in a typical server consists of the Ethernet network adaptors (NICs), which allow it to communicate with clients and other computers – networked storage adaptors (HBAs), which provide connectivity into shared storage pools, – and local disk storage (DAS) for non-volatile storage of local data, operating systems (OSs) and server “state”. I/O also includes all the cables and networking infrastructure required to interconnect the many servers in a typical data center. Each server has its own private set of I/O components. I/O today can account for as much as half the cost of the server hardware.
Fig 1: Server I/O
I/O Virtualization
Data centers in recent years have been turning to a variety of “virtualization” technologies to ensure that their capital assets are used efficiently. Virtualization is the concept of separating a “function” from the underlying physical hardware. This allows the physical hardware to be pooled and shared across multiple applications, increasing its utilization and its capital efficiency, while maintaining the standard execution model for applications.
Virtualization consists of three distinct steps: Separation of resources – providing management independence; Consolidation into pools – increasing the utilization, saving cost, power and space; Virtualization – emulating the original functions as “virtual” functions to minimize software disruption;
I/O Virtualization (IOV) follows the same concept. Instead of providing each server with dedicated adaptors, cables, network ports and disks, IOV separates the physical I/O from the servers, leaving them as highly compact and space efficient pure compute resources such as 1U servers or server blades.
Fig 2: CPU-I/O Separation
The physical I/O from multiple servers can now be consolidated into an “IOV Appliance”.
Because the I/O components are now shared across many servers, they can be better utilized, and the number of components is significantly reduced when compared to a non-virtualized system. The system becomes more cost, space and power efficient, more reliable, and easier to manage.
Fig 3: I/O Consolidation
The final step is to create “virtual” I/O devices in the servers which look to the server software exactly the same as the original physical I/O devices. This functional transparency preserves the end-users’ huge investment in software: applications, OSs, drivers and management tools.
Fig 4: I/O Virtualization
I/O Virtualization Approaches for Commodity Servers
I/O Virtualization is not new. Like many technologies new to the PC and volume server, it has been in mainframes and high-end servers for many years. Its values are well understood. The challenge has been to bring those values to the high-volume, low-cost commodity server market at an appropriate price point, while not requiring major disruption to end users’ software, processes and infrastructure.
A number of companies have, over recent years, introduced products delivering I/O virtualization based on Infiniband. Although they have delivered many of the advantages of IOV – particularly in data centers which already use Infiniband – their use of Infiniband has limited their attractiveness to the broader market. The cost, complexity, and disruption of introducing new Infiniband software, networks and processes have negated the value of IOV.
The default I/O interconnect in volume servers is PCI Express. The PCI-SIG has recently defined a number of extensions to PCI Express to support I/O virtualization capabilities both within a single server (SingleRoot-IOV) and across multiple servers (MultiRoot-IOV). However, these extensions are not fully transparent with respect to standard PCI Express and require new modified I/O devices and drivers. The requirement for an “ecosystem of components” means that it is likely to be some years before we see MR-IOV, in particular, as a standard capability in a significant range of I/O devices.
Another approach is to virtualize standard PCI Express I/O devices and drivers available in volume today by adding the virtualization capability into the PCI Express fabric rather than into the devices. This has the advantage of exploiting the existing standard hardware and software and being extremely transparent and non-disruptive. Because the virtualization capability is contained in the PCI Express fabric, neither the I/O device nor any of the servers’ software, firmware or hardware needs to change. VirtenSys calls this new approach “Native PCIe Virtualization”.
Fig 5: Comparison of Infiniband IOV, PCI MR-IOV and Native PCIe IOV
Key Features and Benefits of Native PCIe IOV
Hardware cost reduction through consolidation IOV reduces hardware cost by improving on the poor utilization of I/O in most servers today. Native PCIe Virtualization contributes to this cost saving by reusing the existing high volume, low cost PCIe components and by adding very little in the way of new components.
Power reduction Increasing the I/O utilization through consolidation not only minimizes acquisition cost, but also the amount of I/O hardware required and hence the power dissipation of the data center.
Management simplification I/O virtualization changes server configuration from a hands-on, lights-on manual operation involving installation of adaptors, cables and switches to a software operation suitable for remote or automated management. By removing humans from the data center and providing automated validation of configuration changes, data center availability is enhanced. It is estimated that 40 percent of data center outages are due to “human error”.
Dynamic configuration – agility Businesses today need to adapt quickly to change if they wish to prosper. Their IT infrastructure also needs to be agile to support rapidly changing workloads and new applications. I/O virtualization allows servers to be dynamically configured to meet the processing, storage and I/O requirements of new applications in seconds rather than days.
Ease of deployment and non-disruptive integration
Native PCIe IOV technology has been designed specifically to avoid any disruption of existing software, hardware or operational models in data centers. Native PCIe IOV works with – and is invisible to – existing volume servers, I/O adaptors, management tools, OSs and drivers, making its deployment in the data center extremely straightforward.
Rapid and cost effective adoption of new CPU and I/O technologies CPU and I/O technologies have been evolving at different rates. New, more powerful and cost/power effective CPUs typically appear every nine months while new I/O technology generations come only every three – five years. In particular the “performance-per-watt” of new CPUs is significantly higher than those of a few years ago. The separation of I/O from the compute resources in servers (CPU and memory) allows new power efficient CPUs to be introduced quickly without disrupting the I/O subsystems. Similarly, new I/O technologies can be introduced as soon as they are available. Since these new high-cost and high-performance I/O adaptors are shared across multiple servers, their introduction cost can be significantly smoothed when compared with today’s deployment model.
Summary
I/O virtualization is an innovation that allows I/O to be separated, consolidated and virtualized away from the physical confines of a server enclosure.
Of the various approaches described, Infiniband-based IOV is most suitable for installations which already have an Infiniband infrastructure and whose servers already use Infiniband software. For the majority of data centers without Infiniband, IOV based in the standard I/O interconnect, PCI Express, provides a much more acceptable, low- power, low-cost solution. In particular, Native PCIe Virtualization provides today all the benefits of IOV without requiring new I/O devices, drivers, server hardware and software.
VirtenSys I/O Virtualization Switches improve I/O utilization to greater than 80 percent, enhance throughput, and reduce I/O cost and power consumption by more than 60 percent. The products also enhance and simplify data center management by dynamically allocating, sharing, and migrating I/O resources among servers without physical re-configuration or human intervention, dramatically reducing Operational Expense (OpEx).
Posted by Roy Zafar at 7:58 AM 0 comments
Labels: Data Center, Tech and Trends
Saturday, January 31, 2009
IT Hiring Outlook - 2009
Job and Salary OutlookWith the US economy tanking, the question for IT professionals is this: Is my niche relatively safe?
According to many observers, there is good news for IT folks in a number of sectors, whether they’re veterans with decades of experience or recent graduates whose skills are untested in the marketplace: If you’ve got the right tech skills and can think like a line-of-business manager, you’ll be in demand. “For sure, there is still a shortage of IT skills,” says Jeanne Beliveau-Dunn, head of the certifications group at networking vendor Cisco Systems.
But with the economy likely to shrink for a good part of 2009, will employers be able to build their IT staffs, or at least fill vacant positions? Here’s what we’re hearing around the industry.
Will IT Head Count Rise, Fall or Go Flat in 2009?
The proportion of employers increasing their IT head count will edge up from 40 percent in 2008 to a projected 43 percent in 2009, according to a survey by the Society for Information Management (SIM) published in November 2008 using data collected in June.
Jerry Luftman says this number remains valid, even with the fiasco in the financial markets. “Information systems and business executives are not panicking,” says Luftman, SIM’s vice president for academic affairs. “In previous recessions, IT was the place to cut, cut, cut.” Why not this time? Because IT has become a champion of cost-cutting across the enterprise, Luftman says.
Offshoring may be more of a threat to American IT jobs in 2009 than it has been in recent years. After trending down slightly since 2006, IT budget allocations for offshore outsourcing will jump from 3.3 percent in 2008 to 5.6 percent in 2009, the SIM survey says. Why the increase? “The economy is in a downturn, and many organizations believe they can get IT staff at a much lower cost offshore,” Luftman says. IT executives may also feel financial pressure to try offshoring, even if they have concerns about quality, he says.
Financial IT Jobs Lost and Gained
Obviously, thousands of jobs in distressed banking and financial services firms will be lost to downsizing, mergers or bankruptcies. But for the companies left standing, “even in the worst crisis on Wall Street, networks still have to perform,” says Beliveau-Dunn. For that reason, mission-critical IT operations will carry on, while many growth-oriented IT projects may be suspended or sacked, industry sources say.
But just as the Sarbanes-Oxley accounting reforms created work for IT professionals in the wake of the early-2000s corporate scandals, the current financial crisis is driving up demand for financial IT talent in select niches.
“The government has enacted new securities regulations and modified existing ones” to mitigate the effects of the financial crisis, says Ari Packer, a financial software engineer with Galatea Associates LLC in Somerville, Massachusetts. As a result, Packer and his colleagues have been putting in extra-long hours for their clients – Wall Street broker-dealers – to rework software that must continue to function well in a rapidly changing regulatory environment.
These IT Areas Are Likely to Remain in Demand
Broader areas in IT are likely to see relatively healthy employment in 2009. Through 2008, for example, “there’s been a lot of demand for people doing integration and IT people with a business background,” says Matt Colarusso, a branch manager with Sapphire National Recruiting in Woburn, Massachusetts, a unit of Sapphire Technologies.
Networking skills especially in demand for 2009 will be in three areas, according to Beliveau-Dunn: wireless communications, data center virtualization, and unified communications and collaboration. “Travel budgets have been cut tremendously, so you need to enhance your tools for [distance] collaboration,” she says.
But ultimately, negative growth will hurt IT employment across much of the economy. “To maintain a business of a certain size, you need an IT operation of a certain size,” Packer says. “If the business gets substantially smaller, so will IT.”
While IT salaries are expected to rise 3.7 percent in 2009, according to Robert Half Technology’s 2009 Salary Guide, 2009 clearly won’t be the best time to ask for a big raise. Still, certain specialists – even some new grads – may do relatively well. According to Robert Half, three examples of in-demand IT specialties and 2009 starting salary ranges are:
- Web developers, with starting salaries between $60,000 and $89,750.
- Programmer analysts with skills such as .Net, SharePoint, Java and PHP, who will command starting salaries of $60,000 to $100,750.
- Tier 2 help-desk workers, starting at $36,750 to $48,250.
Posted by Roy Zafar at 7:27 AM 0 comments
Labels: Job Hunting, Tech and Trends
Tuesday, January 20, 2009
The Latest Trends on Software as a Service
While there are still some people who consider SaaS a passing fad, the latest developments on the Software-as-a-Service (SaaS) front certainly proves that SaaS is here to stay with a growing future.
While there are people, who consider SaaS a passing fad, the latest developments on the Software-as-a-Service (SaaS) front certainly proves that SaaS is here to stay with a growing future.
The Role of SaaS Is Growing
I guess it is not a surprise for industry insiders that Gartner and many other research organizations are reporting that the use of SaaS is growing. When one thinks of all the advantages SaaS has in terms of costs, ease of use and overall efficiency, it is only logical that more and more organizations of all sizes are embracing it. Sure, there are cases, when using SaaS is not recommendable (i.e. for applications, which require heavy customization or when security and control are of paramount importance) and if anybody expects that 100% of all organizations will ever use SaaS, this might never happen but it is a fact that more and more companies (and organizations in general) of all sizes use SaaS in one form or another.
According to a research by AMI-Partners “21 percent of small businesses and 31 percent of mid-size enterprises use SaaS solutions today—double the percentage of just four years ago.” This is totally in line with Gartner's forecasts that “Worldwide software-as-a-service (SaaS) revenue in the enterprise application markets is on pace to surpass $6.4 billion in 2008, a 27 per cent increase from 2007 revenue of $5.1 billion”. It is obvious that this is a lucrative market any data center would like to enter (if they are not already there) or to expand their SaaS offerings in order to generate more revenue.
SaaS is a real cash cow for those data centers, which know how to use it. What is more, the upward trend in SaaS usage is expected to continue in the next few years as well and again as per Gartner's predictions, the use of SaaS will more than double by the year 2012. This is really an opportunity (stand-alone) data centers can't afford to miss!
Is the Economy Doing SaaS a Favor?
In addition to the undisputed advantages of the SaaS concept itself, there might be another very important factor for the increased adoption of SaaS in the recent years – the poor state of the economy.
When organizations are pressed to cut costs, it is easier to decide that renting software (i.e. using SaaS) is more feasible than paying hefty amounts of money to buy it. Since the economic outlook for 2009 (and some economist say that the recession could go into 2010 as well) is far from bright, it can be expected that the cost-cutting benefits of SaaS will be even more of a factor for companies to adopt SaaS or to expand their SaaS adoption even further. This is the best news about the economy I have heard in recent months!
More SaaS-friendly Products Are Being Released
Cost-savings might be a major reason for many companies to turn to SaaS or to increase its adoption but they are certainly not the only ones. SaaS offers are improving all the time and this makes them more attractive. There might be many growth-related mistakes by SaaS vendors but generally the SaaS industry is not that young anymore and many of the issues, which plagued its infancy, have already been sorted out.
One of the most significant improvements to the SaaS model is the fact that more and more SaaS-friendly applications are offered by vendors. Even if the applications are not principally new, their latest versions are more SaaS-friendly (I hope this is not accidentally) and this certainly helps to make SaaS more lucrative. It seems that software vendors are becoming aware of the potential benefits the SaaS model gives them and that is why they start to develop SaaS-friendlier applications.
SaaS can be used for all kinds of databases and database applications (which are a large portion of Web applications). For non-technical users this translates as CRM, HR, or ERP packages, which generally are neither cheap, not always straightforward to install but when used as SaaS, these technical intricacies are hidden for the user. Office suits are also another SaaS-friendly group of applications and there has been a significant increase is the SaaS-ability of office suits, mainly the Google offer. Maybe it is an exaggeration to say that SaaS applications will make desktop applications obsolete but it is a fact that the rise of SaaS office suits has increased dramatically over the last year or two.
Does Open Source Trigger the SaaS Expansion?
Open source is everywhere in the data center and SaaS is not an exception. The advantages of open source are well-known and it is logical that the use of open source for SaaS offerings is substantial. Due to the fact that most open source applications (operating systems, servers, databases, enterprise applications and end-user applications) are very reliable and free, open source has made its way into SaaS. And what is more – if there weren't so many and good open source applications then the adoption of SaaS would have been much slower. The prices for SaaS would have been higher and the reliability would not have been that good.
In fact, open source software has a dominating role in SaaS and its share will continue to increase. According to Gartner, “By 2010, 90 percent of software as a service (SaaS) providers will have some open-source component in their technology infrastructure stacks”. Open source has always been popular in most data centers and it is not surprising that its popularity spreads in the SaaS area as well.
If open source continues to provide the solid SaaS foundation, it can be expected that SaaS will soon become a dominating model for doing business. SaaS has a sound economic foundation and it offers many benefits to small and large companies, so SaaS is a safe bet for data centers. 2008 was a good year for SaaS and chances are that the positive developments will continue in the future as well.Posted by Roy Zafar at 9:29 AM 0 comments
Labels: Data Center, Tech and Trends
Monday, January 19, 2009
Meeting Business Expectations
IT Departments Pushed To The Limit
by Robyn Weisman
EVEN THOUGH ADDITIONAL FINANCIAL and human resources are limited, IT departments are being asked to develop, implement, and maintain new business initiatives. This theme isn’t a new one, says Gartner analyst Ken McGee, adding that the topic has become more pressing given the recession’s effect on the economy.
“Being outstripped in their ability to meet demand is not new. What is new is that CIOs for the first time are openly saying it out loud and freely,” McGee says.
Nevertheless, there is a big difference between talking about these issues and making changes so that your SME’s management no longer assumes you can meet whatever expectations they throw at you.
Are You Kidding Me?
“Since the credit crisis, we continue to ask clients, ‘How would you best describe the current level of activity among your developers? Are they not busy, busy, very busy?’ The overwhelming majority indicates they are very busy. That constitutes one hell of a recession,” says McGee.
The sheer volume of projects unfolding in the midst of a recession makes no sense whatsoever, McGee says. And much of that insanity lies at IT’s feet because IT has failed to communicate to management what the limits are. Because management is not being given enough information to help them make good decisions, they haven’t turned off the demand faucet, says McGee.
“The next time you swipe your credit card you do not first get, ‘Hold on a second; do you realize you’ve already spent $1,500 this month on your credit card?’ You don’t get that, and we don’t do that with our management requestors of new applications,” McGee says. “We are not being fair to managers because we are not saying to them what they are saying to their customers every day. ‘Oh, you want to buy X? Here’s how much it costs,’” McGee says.
Adds McGee: “You look at your kids after they find out that you’re laid off. If they say, ‘Can we still go to Disneyworld?’ [you’ll say,] ‘Are you kidding me?’ Yet that’s exactly what’s going on in business right now. ‘OK, times are tough. Our revenues are down. Can I still have that ERP project?’ Are you kidding me?”
Turn Off The Demand Faucet
Of course, determining which projects to keep and which to scrap isn’t easy even for IT, and many of McGee’s IT clients have said to him that they have saved as much money as they can find. But according to McGee, there is no way all the projects you have on the books constitute business imperatives. McGee recommends taking a zero-based budget approach to again justify all IT projects, a process he believes will reduce much of the demand in this economy.
“We do not depict the true genuine one-time costs or the recurring costs of an IT project before it’s done. In fairness to management, were we able to do that consistently, people would suffer from sticker shock, and perhaps then projects that they deemed so important would not actually be blessed,” McGee says.
Determine Which IT Projects Are Essential
Once you have determined how to stop the sheer volume of projects that are unfolding in the midst of a recession, as McGee has discussed, you then want to determine which of your remaining IT projects are essential to running your SME while the economy is in such a weak state.
For his part, CDW technologist Vic Berger recommends conducting a workflow prioritization plan. This is a process Berger believes all SMEs should do as part of a healthy business continuity and disaster recovery plan; however, this process becomes essential during these economically trying times.
First off, Berger recommends SMEs should examine their IT processes by outlining them and prioritizing the processes accordingly. What processes are most critical for business operations? What IT operations will save your organization money? And which ones are just nice to have but aren’t necessary?
“Draw a line separating mission-critical needs and non-essential IT functions. This line will fluctuate depending on cash flow. Once the performance-critical applications are sorted, wait until the market changes to purchase anything off of that top-line list,” Berger says. “Essentially, focus on the most basic business issues—most specifically, what IT applications do you truly need to run your business?”
Posted by Roy Zafar at 12:00 AM 0 comments
Labels: Tech and Trends
Tuesday, January 13, 2009
Storage Interfaces
Sort Through The Options To Make The Right Choice
by George Crump
In 2009, the IT professional might feel like he is faced with many different interfaces to choose from for storage connectivity. On the storage infrastructure side, there is 4Gb Fibre Channel moving to 8Gb Fibre Channel, the option of FCoE (Fibre Channel over Ethernet), and 1Gb iSCSI moving to 10Gb iSCSI. On the storage component side, there is SAS, Fibre, SATA, and even SSD. Each of these options has a viable use in the data center, and working through the options is not as difficult as it appears.
Infrastructure
Paul Vogt, senior director of product management at Xyratex (www.xyratex.com), advises that once you decide you need a SAN or upgrade to a new one, don’t compare performance numbers of the different options: “The protocols are too different; you have to characterize the performance testing with your workload.”
“Also, don’t rule out Fibre Channel just because you have heard that iSCSI is easier,” says Brocade’s Mario Blandini, director of data center infrastructure product marketing (www.brocade.com). Blandini notes that the Fibre Channel of today is significantly easier than the Fibre Channel at the beginning of the decade and that it has become a much easier plug-and-play solution.
Vogt believes that 8Gb Fibre Channel is ready now for most customers, even first-time SAN buyers: “It is the natural upgrade for a current SAN, and the added bandwidth is ideal for IT staffs rolling out their server virtualization projects.” Brocade’s Blandini echoes that sentiment, saying, “Many customers are tempted to start with iSCSI because of perceived ease of use; the challenge is that in virtualized server environments, you quickly begin to push the limits of today’s iSCSI, and the steps needed to scale performance can make the implementation very complex. 8Gb Fibre Channel starts out with plenty of performance and adding to that performance is straightforward.”
FCoE is a 10GbE-based protocol and is positioned to take advantage of both Fibre and IP infrastructures. While FCoE is capturing a lot of attention right now and companies are shipping FCoE HBAs, Vogt believes that because the standard has not yet been ratified, most users will likely wait until mid-2010 before implementing the option. He notes, “Despite that, a Fibre Channel-based protocol, like 8Gb, will have a built-in migration path when FCoE use becomes more commonplace.”
Not to be forgotten is iSCSI. “iSCSI is an ideal protocol for the small to medium-sized enterprise, and now that 10Gb iSCSI is available, the usability is broadening to larger enterprises,” says Condre Senior Storage Engineer Harry Montanye (952/294-4900; www.condrestorage.com).
SCSI is viewed as the affordable alternative to Fibre Channel, and often, in reality, it is. With the improvements in Fibre Channel’s implementation and day-to-day operations, the iSCSI vs. Fibre Channel decision is no longer an issue of ease of use. The decision points now are cost, reliability, and scalability.
“Fibre Channel has proven itself to be more resilient and more scalable than iSCSI vs. iSCSI’s cost advantages, and as those environments begin to scale, much of the cost advantages go away,” concludes Blandini.
Storage Components
2009 will also see change at the storage component level, where the interface choice of Fibre Channel and SATA has been the standard for a few years. “2009 will be the year that we see a dramatic movement to SAS-based disk drives and a decrease in the use of Fibre Channel disk drives,” says Vogt. Montanye agrees, saying, “SAS drives will be the majority of drives used in new storage array purchases, and Fibre Channel drives will be primarily sold to existing users that are not ready to upgrade.”
Compared to SATA drives, SAS is a more enterprise-class drive with a deeper queue depth and the provision for dual-ported drives. The deeper queue depth will improve performance and reduce drive latency. Dual-ported drives will allow for two storage controllers to have direct access to the drives for better failover. In Montanye’s experience, “While SATA drives can simulate this by the use of a path multiplexer, the dollar cost in using a multiplexer can make SATA drives more expensive than the SAS drives, and [in] removing the multiplexer, you eliminate a point of failure.”
“Another advantage to SAS is that its drive connector is interchangeable with SATA,” says Vogt, which he says further lowers cost and system complexity. Vogt also believes that we will begin to see a more rapid transition from 3.5-inch to 2.5-inch drives, based on the new SAS II-based drives. He notes, “This will allow for greater density per cubic inch.”
Storage Decisions
Options are almost always good for the users. Options let users implement a solution based on what they need as opposed to settling for what is available. The problem with choices is that they have to be analyzed and decided upon. The interface decision is largely dependent on what is currently installed and what the IT staff is already comfortable with. If there is already a Fibre Channel SAN in place, staying on that path and migrating to 8Gb FC will likely have an immediate benefit. It would also position the company to take advantage of FCoE when the time comes (if it makes sense in the environment).
Similar is iSCSI: As more systems support iSCSI and provide tools to take advantage of the additional bandwidth, the obvious path of least resistance is to stay with it if it’s the current installation. That said, if there is a need to upgrade, especially if performance is a concern, Fibre Channel should be considered, as well.
The drive mechanisms will, for the most part, take care of themselves. The move to SAS will be part of the normal progression as new storage systems are purchased, and SATA will continue to be the option for the lower-cost tier of storage.
“Flexibility [is] a key feature when selecting your host bus adapter, storage infrastructure, and storage system vendor. Make sure that these providers have the ability to adapt to and interface with emerging standards as they come to market,” concludes Vogt.
It is difficult to know you are picking the right interface. Not only is market acceptance out of your control, but it is also hard to determine what will change internally in your business. The ability to adapt and be flexible is critical.
Posted by Roy Zafar at 9:00 AM 0 comments
Labels: Tech and Trends
Saturday, January 10, 2009
Security Trends during 2008 and 2009
Written by Zulfikar Ramzan Ph.D.
Thursday, 08 January 2009
As a new year approaches we must prepare for new Internet security threats. Every year, new and innovative ways of attacking computer users emerge and continue to increase in volume and severity. To know where we are going it is helpful to look at where we have been. Finding trends in Internet security has become a valuable, if not necessary, action for companies developing software to protect computer users.
Attacks have increased in sophistication and are often tailored to their specific victim. Trend tracking has shown that in 2008, the Web has become a primary conduit for attack activity. According to Symantec’s Top Internet Security Trends of 2008, attackers have become more difficult to track as they have shifted away from mass distribution of a small family of threats to micro distribution of large numbers of threats.
Security Trends of 2008
Spam and Phishing
This may be the most well known form of computer breaching, and yet it is still the healthiest and fastest growing of attacks. In 2004, Bill Gates predicted that spam would be resolved in another two years. In 2008, we were seeing spam levels at 76 percent until the McColo incident in November 2008, at which time spam levels dropped 65 percent. The battle with spammers has turned into an all out war and spammers are showing no sign of surrendering.
Spammers take advantage of current events, such as the presidential election, Chinese earthquake, Beijing Olympic Games and the economy. They use these widely socialized issues as headlines to lure people into clicking on a link to malware or sending money for unrealistic charitable campaigns. Social networks are only feeding the beast by making it easier for spam attacks to propagate quickly through a victim’s social network.
Phishing walks hand in hand with spam as it utilizes current events to make their bait more convincing. Another phishing tactic particularly recognized over the last year is by offering users a false sense of security by targeting .gov and .edu domains. Although cybercriminals cannot register domains under these domains, they find ways to compromise the Web servers to grant them control. Once control is gained, it becomes harder to fix because the domain cannot be simply deactivated. Lengthy measures are taken to have the company remove the compromised page from their website and secure their servers. The time it takes to make these changes allows the phished page to remain active and hit more victims.
Fake and Misleading Applications
Fake security and utility programs aka “scareware” promise to secure or clean up a user’s home computer. The applications produce false and often misleading results, and hold the affected PC hostage to the program until the user pays to remedy the pretend threats. Even worse, such scareware can be used as a conduit through which attackers install other malicious software onto the victim’s machine.
Data Breaches
In 2008, the Identity Theft Resource Center (ITRC) documented 548 breaches, exposing 30,430,988 records. The significance of this data is truly spotlighted after realizing that it only took nine months in 2008 to reach the 2007 total.
What is most interesting about data breaches is that most are not malicious in nature. In many cases, inadvertent employee mishandling of sensitive information and insecure business processes are the most common ways that data is exposed. This can be attributed to the increase of mergers, acquisitions and layoffs resulting from the thundering economic climate changes in 2008.
2009 Trends to Watch in 2009
Looking at attack trends and techniques malware creators favored in 2008 help us predict what to expect in 2009. Some of these new attacks are already starting to show up and users need to be aware so that they can stay safe online in 2009.
Social Networks
Social networks will enable highly targeted and personalized spam by phishing for username accounts and/or using social context as a way to increase the “success rate” of an online attack. In 2009, we expect an upgrade in spam to the use of proper names, sophisticatedly segmented according to demographic or market. The upgraded spam will resemble legitimate messages and special offers created from personal information pulled from social networks and may even appear to come from a social networking “friend.” Once a person is hit, the threat can easily be spread through their social network. Enterprise IT organizations need to be on the alert for these types of attacks because today’s workforce often accesses these tools using corporate resources.
Advanced Web Threats
The number of available Web services is increasing and browsers are continuing to converge on a uniform interpretation standard for scripting languages. Consequently, we expect the number of new Web-based threats to increase. User-created content can host a number of online threats from browser exploits, distribution of malware/spyware and links to malicious websites. The widespread use of mobile phones with access to the Web will make Web-based threats more lucrative. We have already seen attacks disguised as free application downloads and games targeting Smartphones. We expect to see more truly malicious mobile attacks in 2009.
Economic Crisis
As we have learned, current events are utilized as headliners to bait victims. In 2009, it is easily predicted that the economic crisis will be the basis of new attacks. We expect to see an increase in emails promising easy-to-get mortgages or work opportunities. Unfortunately, the people already being hit hard by the economy who have lost jobs and who have had homes foreclosed will also become the primary prey of scams.
The battle against Internet security threats will continue to rage on and tactics on both sides will become more sophisticated over time. Although no one can be certain of what the future holds, we can look back and learn from our past to identify trends that can help make educated predictions for where future attacks may be heading.
Posted by Roy Zafar at 4:28 PM 0 comments
Labels: Data Center, Tech and Trends