Sunday, June 01, 2008

ASE: Inducts ITIL process in an orderly way, do not attempt complete the wholes set immediately.

Home Source: http://www.ithome.com.tw/itadm/article.php?c=43812

The reporter Whiffen Yang reported after the speech by ASE group information Vice-president Mincheng Sheng.

After ITIL becomes international standard ISO 20000 officially, more and more enterprises improve their IT service management with ITIL methodology gradually. This ASE example shares their ITIL induction information with public.

The ASE inducts is also quite complete, a key point must be mentioned is whether Acer or ASE inducts the ITIL processes, both has adopted with the same pattern which proceeds in an orderly way.

ASE group information Vice-president Mincheng Sheng shares ASE’s experience on ITIL induction by itSMF Taiwan branch's invitation. “The enterprise inducts ITIL framework which should better be adopts the processes on proceeding in an orderly way, do not attempt to complete ITIL framework immediately, the reason is setting the scope is too big at the beginning, the cost on investment must be increasing naturally. The disagreement will be prompted on the boss side easily. Therefore enterprise should start from the point which has highest benefit and the smallest impulse.” he said.

By the ASE's experience, we starts from Service Level Management on the entrance of ITIL project induction before more than two years ago, then progresses gradually to the Change Management, as well as Incident Management and Problem Management and such. Mincheng Sheng said that besides both ASE and Acer starts to invest ITIL is also adopts the process on expand the scope with gradual growth way. ASE faces to the configuration management information database (CMDB) and the Change Management slowly extended recently.

Many people thought that inducts ITIL is must spend a lot of money, parts on buying many tools. Then can complete the IT service management truly, but as ASE inducts ITIL not to spend many money. Mincheng Sheng said. Take the example on the establishment on CMDB, ASE implement CMDB with their own method, has not invested too many money on tool purchasing. Because of CMDB is the key mainly, don’t matter the tool itself, just keep going on the flow improvement and the management. In term of the CMDB part, actually there does not have any information service provider to be possible to provide suggestion to the enterprise explicitly, how can the enterprise measure the achievement to be able to have the help to the IT management.

According to the ASE's procedure is caring the most important system. Mincheng Sheng explained that ITIL is talking about the flow management actually. However, in all the practice operation, each flow has the different priority, enterprise should take care their important software and hardware system, for example: ERP, the server or the storage. And also carry on the strict management, which can probably fit IT service requirement about 95%~98%.

In the past, the role of IT just focuses on solving problems. That idea was not make sense. After inducting ITIL, IT department may along to the SLA agreement to provide IT the service which matches the request initiatively.

Mincheng Sheng suggested that each enterprise should induct ITIL, because inducts ITIL really has the advantage; it will let IT changed differently compare to the former. After inducting ITIL, might reduce IT the Operation Cost effectively. In term of ASE’s experience, in the past wanted we need about 250 did a matter personally, so long as now the same matter only 70 people can complete it. Moreover, enterprise might control all the events and the processing status by the daily report. Do more with few resources this benefit should have the opportunity in each enterprise.

In my opinion, each enterprise wants to use a limit cost to have more benefits under high competition environment. This idea also can be seen on the ASE case as well. With some one’s story illustrate their reaping, we can not feeling truly, only if we confirms the advantage on IT government personally.

Saturday, May 31, 2008

IBM: ITIL is not only the IT service management Bible

Home Source: http://www.zdnet.com.tw/news/software/0,2000085678,20121784,00.htm

After the ITIL version 3 has been published at the middle of 2007, ITIL becomes a hot topic which has been discussed between the manufacturer and enterprise. IBM believed that ITIL become a hot topic, it is no doubt to be helpful to the market introduction. Enterprise must complete the consummation the IT service management, no just only ITIL, another standard as CMMI, COBIT, also enters the consideration.

Michael Shallcross, IBM construction service and the IT strategy Executive Consultant to indicate this enterprise should evaluate the present IT service management which parts needs to be improve, and then chooses the suitable standard to follow. Which standard should be use to improve the IT service management, the decision should consider the requirement from the user side.

Michael expand, If enterprise IT services focus on the business operational, that is suitable play attention on ITIL. But if the enterprise’s IT department focuses on the development, they should pick CMMI (Capability Maturity Model- Integrated) framework. If enterprise focuses on the government or planning, they should pick COBIT (Control Objectives for Information and related Technology) standard.

IBM global IT service department Consultant Manager Junchang, Chen said. “ITIL is parts of ITSM, enterprise may take many standards to match their development situation and demand.

IDC enterprise applied research Manager Yonghui,Cao indicate that ITIL is one of achievement on ITSM ways, but it is not for all. He also believed that although ITIL is the Best Practice which provides the criterion to enterprise face on ITSM, but no more than two enterprises have the same way to fulfill the ITSM. If enterprise just follow the single standard, they might take the ITIL framework as the foundation, develops their own IT service management flow.

Other entrepreneurs approve this ITIL is not the only one, but it is a very good reference to carry on the ITSM. CA senior technical adviser Zhenyi-Jiang indicated that achieve all the requirement base on ITSM, ITIL is not the only way certainly. Regarding to the enterprise did not have the resources develop their self management flow; it is quite easy to create the management flow base on the existing standard.

According to the professional’s opinion, that has been published early. I can see this strategy. The goal on IT service quality improvement, everybody is consistent. But the experiences, the time and the procedures could be different because of enterprise's nature are different. Meets enterprise's needs first then faces to the global standard later. This strategy is the best way to reach the coveted benefits.

Friday, May 30, 2008

ITIL or not ITIL? That is not the question

Home Source:
http://www.zdnet.com.tw/enterprise/technology/0,2000085680,20123187-2,00.htm

Brian Johnson emphasis this is not necessary each enterprise needs ITIL, but which ITIL version should enterprise chooses, it depend on enterprise’s business demand. The final answer on which edition should be taken to use? That must clear understanding is ITIL suit to be used in the organization. ITIL framework covers the area broad and depth, the implementation cost is huge money which is oversized. Whether needs to induct the ITIL framework in the enterprise or organization, making the decision after the appraisement voluntarily.

Johnson also pointed out clearly that ITIL is one kind of directive, is not the law. ITIL even requests the enterprise have to confirm their demand before starting, while the enterprise knows which part should be improved, then can discover the suitable products and solution, also consider which ITIL version should be chosen to implement if it should be is required.

If enterprise knew clearly what they needs, perhaps they don’t need ITIL. As ASE CIO Mincheng,Sheng reported, ASE has not obtained the ITIL authentication, also did not want to facing the ISO authentication, he believed that so long as all the processes can guarantee the practical execution by the internal management, ASE does not need the certification.

Whether Enterprise general manager or CIO, the main point is: taking ITIL for improving IT service, But not for ITIL. IDC Research Manager Yonghui, Cao has a similar idea, he indicate whatever is ITIL perhaps COBIT, or BS7799, these are the external models, it may not suits the enterprise completely, the external consultant also may not necessarily can tell enterprises are they suit it. All must return to the physical demand. “The most understands the demand and the work, is the internal IT department.” he said.

In summary, what I can see is the change is eternal, ITIL is not exceptional. The main point on ITIL framework is "provides the information service management framework which the enterprise needs", but the enterprise does not need to follow all the material. There are different requirement along the industrial characteristic, enterprise culture and the market strategy, different enterprise pays attention on the information service also difference. Which way can let business running smoothly, that way is we need.

Thursday, May 29, 2008

ASL ITIL for Enhanced Application Management

Home Source:
http://ezinearticles.com/?ASL-ITIL-for-Enhanced-Application-Management&id=168396

Patrick Moore is an independent consultant and technology writer residing in Los Angeles, CA, USA. The following information comes from his writing.

The Applications Services Library (ASL) was developed specifically for the application management domain. ASL is increasingly being used for application management improvement to complement ITIL.

In ASL domain it serves to ensure the prudent management of application software, databases and the relevant documentation throughout the useful life of the relevant business processes that are supported by the application. ASL describes the implementation of service management processes in the application management domain. ASL also includes best practices for the implementation of the various processes. It devotes significantly more attention than ITIL to the strategic processes as part of the future of an ICT portfolio; which supports a business process. The processes concerning enhancement and renovation of applications are considered as an enrichment of ITIL. The ASL processes complement those of ITIL.

ASL is based on the processes and service concepts of ITIL framework. The two frameworks differ in their approach to controlling and supporting the technical infrastructure. In effect, ASL more explicitly outlines the process interdependencies between the infrastructure, applications and the business. ASL stresses different functional competencies and introduces additional processes that support the Application Management framework, in addition to providing more detail surrounding the ongoing management and support of business systems and services. ASL also adds some practical guidance for management of the lifecycle through its recognition of a paradigm shift in focus from application development to software maintenance.

From the ASL perspective, roughly 80% of Application Management efforts may lie in the maintenance of systems. While ASL does not replace the ITIL Application Management framework, it compliments the service manager through its broader perspective into the dependencies associated with the functional and technical aspects of optimized service provision. That being said, the evolution of ITIL and ASL as a partnership should continue, but the framework documentation itself could more collaborative, reduce redundancy and more clearly articulate Application Management best practices to the ITIL community.

In my view, in spite of ITIL is the best practice, cover a wide area on IT service improvement. Each area may have the specific standard or public domain framework involve deeply. ITIL is a collector collects all the area it needs then become a good one. That mean, holding the ITIL certification should easily to get the others. As certification of ISO-20000, ASL and such. Those certifications are to be related as closely on high quality services improvement.

Security emerging as ITIL adoption incentive

Home Source:
Http://computerworld.co.nz/news.nsf/mgmt/FA3EBCDB14ADC8E8CC2573D400029683

Here listed some figures that come from a survey reported By Denise Dubie Framingham.

A survey analysts and enterprise ITIL adopters discussed how process improvements are now providing security benefits. The result conducted by IDC in November 2007 of more than 300 companies revealed that security had surpassed improved availability and lowered costs as a main driver for adopting the best practices laid out in ITIL. ITIL best-practices framework not just reducing operating costs, it also helps mitigate enterprise risk. The ITIL adopters said.

Specifically, 56% of survey respondents indicated security as a motivation for ITIL, while close to 50% said they wanted to lower costs and about 47% thought ITIL would help improve availability at their organizations. More than 45% said problem-solving was a driver for rolling out process improvements, and nearly 45% indicated that reducing errors was a top driver for ITIL adoption. The survey response might indicate a growing need among organizations to better secure corporate data and information, considering processes around security information management have been incorporated into ITIL Version 3.

ITIL may not provide the external protections of a firewall, but it can go a long way towards securing internal resources and preventing data breaches. "Security can be the motivation for doing some of these processes, such as patch and change management, for instance, because improving processes will make security work better in situations such as access controls," said Tim Grieser, programme vice president of enterprise system management for IDC.

According to companies using ITIL, security and risk management could be an easier argument to make when trying to get executive buy-in for adopting ITIL. The ROI for process improvements can be ambiguous and not realised for quite some time, so putting an executive's mind at ease with talk of reduced risk may be the better way to go. Oryst Kunka the vice president of process design and architecture at The Bank of New York Mellon, said, "This change will result in a reduction of risk, and it will get management's attention. Sometimes it's hard to point out dollars with process improvements, but companies understand risk. At The Bank of New York, ITIL has become a business advantage.”

In conclusion, according to the survey’s result representing, I can see the security of the information within an organization is a very big issue in present technical day, security policies should been considered in the control, planning, implementation, and evaluation. More then 50% ITIL adopter also indicated solving security issues also a motivation for ITIL methodology become more and more popular.

How ITIL Can Improve Information Security

Home Source: http://www.securityfocus.com/infocus/1815

The author Steven Weil is senior security consultant with Seitel Leeds & Associates. Steven Weil provided the overview of the information security issues based on ITIL implementation. The coming section represented his idea.

ITIL stresses service quality and focuses on how IT services can be efficiently and cost-effectively provided and supported. ITIL defines the objectives, activities, inputs, and outputs of many of the processes found in an IT organization. It primarily focuses on what processes are needed to ensure high quality IT services; however, ITIL does not provide specific, detailed descriptions about how the processes should be implemented, as they will be different in each organization. In other words, ITIL tells an organization what to do, not how to do it.

ITIL seeks to ensure that effective information security measures are taken at strategic, tactical, and operational levels. Information security is considered an iterative process that must be controlled, planned, implemented, evaluated, and maintained.

ITIL breaks information security down into:
  • Policies - overall objectives an organization is attempting to achieve
  • Processes - what has to happen to achieve the objectives
    Procedures - who does what and when to achieve the objectives
  • Work instructions - instructions for taking specific actions
  • It defines information security as a complete cyclical process with continuous review and improvement

ITIL's Information Security Process can be described as a seven step process:

  1. Using risk analysis, IT customers identify their security requirements.
  2. The IT department determines the feasibility of the requirements and compares them to the organization's minimum information security baseline.
  3. The customer and IT organization negotiate and define a service level agreement (SLA) that includes definition of the information security requirements in measurable terms and specifies how they will be verifiably achieved.
  4. Operational level agreements (OLAs), which provide detailed descriptions of how information security services will be provided, are negotiated and defined within the IT organization.
  5. The SLA and OLAs are implemented and monitored.
  6. Customers receive regular reports about the effectiveness and status of provided information security services.
  7. The SLA and OLAs are modified as necessary.

Ten ways ITIL can improve information security. There are a number of important ways that ITIL can improve how organizations implement and manage information security.

1. ITIL keeps information security business and service focused. Too often, information security is perceived as a "cost center" or "hindrance" to business functions. With ITIL, business process owners and IT negotiate information security services; this ensures that the services are aligned with the business' needs.
2. ITIL can enable organizations to develop and implement information security in a structured, clear way based on best practices. Information security staff can move from "fire fighting" mode to a more structured and planned approach.
3. With its requirement for continuous review, ITIL can help ensure that information security measures maintain their effectiveness as requirements, environments, and threats change.
4. ITIL establishes documented processes and standards (such as SLAs and OLAs) that can be audited and monitored. This can help an organization understand the effectiveness of its information security program and comply with regulatory requirements (for example, HIPAA or Sarbanes Oxley).
5. ITIL provides a foundation upon which information security can build. It requires a number of best practices - such as Change Management, Configuration Management, and Incident Management - that can significantly improve information security. For example, a considerable number of information security issues are caused by inadequate change management, such as misconfigured servers.
6. ITIL enables information security staff to discuss information security in terms other groups can understand and appreciate. Many managers can't "relate" to low-level details about encryption or firewall rules, but they are likely to understand and appreciate ITIL concepts such as incorporating information security into defined processes for handling problems, improving service, and maintaining SLAs. ITIL can help managers understand that information security is a key part of having a successful, well-run organization.
7. The organized ITIL framework prevents the rushed, disorganized implementation of information security measures. ITIL requires designing and building consistent, measurable information security measures into IT services rather than after-the-fact or after an incident. This ultimately saves time, money, and effort.
8. The reporting required by ITIL keeps an organization's management well informed about the effectiveness of their organization's information security measures. The reporting also allows management to make informed decisions about the risks their organization has.
9. ITIL defines roles and responsibilities for information security. During an incident, it's clear who will respond and how they will do so. ITIL establishes a common language for discussing information security. This can allow information security staff to communicate more effectively with internal and external business partners, such as an organization's outsourced security services.

The Conclusion for Steven Weil's idea, Information security measures are steadily increasing in scope, complexity, and importance. It is risky, expensive, and inefficient for organizations to have their information security depend on cobbled-together, homegrown processes. ITIL can enable these processes to be replaced with standardized, integrated processes based on best practices. Though some time and effort are required, ITIL can improve how organizations implement and manage information security.

In my view, majority of ITIL articles is talking about the implementation theory. Also the content just represented the benefits when audience jumps in the ITIL pool. No more authors or papers mention the information security issues in article, including the direction or processes. Fortunately, I found Steven Weil’s article. I understand more about the information security issues improvement based on ITIL framework form his article. Even that information I can’t practice, but least I know which area should be focus on the practical.

ITIL: the benefit difficultly to measure on introduction

Home Source: http://www.zdnet.com.tw/news/software/0,2000085678,20112824,00.htm

The following information come form the Reporter Cui Ling, Zhong.

ITIL induction cannot be equal to the traditional IT technical project induction. it also not to be possible similar with other IT system induction which can be deliver equally, or it can be measure the ROI obviously. If the senior management wants to see the benefit immediately, their expectation is to be disappointed.

The objective of ITIL methodology is the improvement on person and the related technical flow, the goal focus on IT capacity optimization. ITIL methodology view enterprise IT services as Service Company or user's department. ITIL framework provides a set of process to illustrate the better way of IT business operation in the enterprise.

After ITIL methodology inducts in the business, it has been integrated in the enterprise's daily business operation. ITIL implementation is not to be possible equal to other IT system induction, the implementing duration not just a half year or one year then can finish, obviously to get the ROI. ITIL project considered IT services is one kind of property investment or IT portfolio management; with it achieve the goal of business adaptively.

In other words, enterprise needs to understand what they want to be? Then clear to know which is their goal, otherwise very difficult to see any effect dependence on product induction or consultant involving. Although it is not getting the result immediately, also it does not unable to estimate. Enterprise should identify the approximate KPI, such as the system response time and the network disconnect time or the IT work load dropping because of automated and so on. Because ITIL processes are closely linked in the business operation flow, the enterprise should take a long time to feel the benefit from the change.

In my opinion, the changing can be seeing during the ITIL induction, and the conflicts could be found easily than the benefits. According to another case as Shell Oil, P&G, HSBC, they can get the obvious benefits after the ITIL induction four to 5 years probably. Enterprise must be patient on their business process improvement until feeling the benefits.