I'm planning on documenting a framework that we built for managing non-functional requirements. This is post #2 of the series. In Post #1, Last In - First Out: Building a Non-Functional Requirements Framework - Overview I outlined the template and definitions for our Non-Functional Requirements. We also had to address outstanding audit findings that pointed out the lack of enterprise-wide security…
I'm planning on documenting a framework that we built for managing non-functional requirements. This is post #1 of the series. A pain point for our infrastructure and security teams was a lack of usable, consistent availability and security requirements for our internally developed applications. The business analysts worked with the organization to create requirements for the functionality of the…
After I was sidelined (Part 10) we had another leadership turnover. This time the turnover was welcome. I ended up in a leadership position under a new CIO. This allowed me to take advantage of some topics that I studied while I was sidelined. My new team took on a couple of challenges. (1) Introducing cloud computing to the organization, and (2) attempting to add a bit of architectural discipline…
This post is the hardest one to write. I've been thinking about it for years without being able to put words to paper. With the COVID-19 stay-at-home directive, I can't procrastinate anymore, so here goes. As outlined in Part 9 , Fall 2011 was a tough period. To make it tougher, the CIO decided to hire two new leadership-level positions - a new CISO over the security group, and a new Associate…
The last half of 2011 was for me an my team a really, really tough time. As I hinted to in this post , by August 2011 we were buried in Oracle 11 & application performance problems. By the time we were back into a period of relative stability that December, we had: Six Oracle Sev 1's open at once, the longest open for months. The six incidents were updated a combined total of 800 times before they…
For historical reasons, we were a strong VMS shop. Before they imploded, Digital Equipment treated EDU's very kindly, offering extremely good pricing on software in exchange for hardware adoption. In essence, a college could get an unlimited right to use a whole suite of Digital Equipment software for a nominal annual fee, and Digital had a very complete software catalog. So starting in the early…
In the 2008-2009 period, we finally started to seriously address application layer security in our development group. By that time is was clear that the threat to hosted applications had moved up the stack , and that the center of gravity had shifted towards compromising the web applications rather that the hosting infrastructure. This meant that our applications, for which essentially no serious…
In the mid-2000's, our organization started to get serious about disaster recovery. By that time our core application was an e-learning application that was heavily used (a hundred thousand students on a typical day). That app became critical to our mission. To bootstrap a DR capability we paid consultants for what was at best a craptastic DR plan. The plan was not implementable under any…
As a side effect of building and running the backbone, I introduced UNIX systems into what was then a wholly VMS organization. We initially used Linux - roughly from 1994 - 1997, then over the next 20+ years, briefly migrated to Solaris x86, then to Solaris SPARC and back to Solaris x86/x64, and then back to Linux. Our CIO at the time recognized that a pure VMS/RDB shop was not a valid long-term…
As a natural fit with running the network my team took on the task of securing the campuses and data centers, starting with firewalling the data centers from the rest of the network. We started fairly simply by just segmenting enterprise-wide servers from networks with users and students and restricting unfettered access to enterprise servers, database and systems. This gave us the ability to…
Unfortunately nearly all the work we put into administrative and academic technology had to be abandoned. As a part of a larger initiative across the state, the various colleges and universities were being merged together into a single system that today is know as Minnesota State. In that process our college president retired, and the new college leadership de-emphasized the use of technology In…
At the college we were extremely fortunate to have a president who had a very forward looking view of technology. In the mid 1980s he was already using personal computers regularly and had written some of his own software. Sometime around 1988 or so he described what he thought would be appropriate use of technology in education. He wanted all student records and curriculum to be electronic, all…
As I've now ended 34+ years of public service, I'm going to burn a few posts on where I've been and what I've tried to accomplish. Like many people my age, my path toward a career in technology was non-linear. My first stop after a Baccalaureate in Physics was a move into teaching Machine Tool trades at a 2-year college. Make sense, right? Actually I had taken a few programming courses in college…
I’m looking at an old (early 20th century) hand-crank record player that was handed down to me from my great-grandmother. It’s a simple wooden box with a spring & flywheel mechanism that spins the turntable at a somewhat constant speed, a metal needle that rides in the grooves of a record disk and transmits the vibrations onto a small metal drum, and a big metal horn that focuses the sound from…
This blog has been idle since 2012. Does anyone care? Like many, I let this blog die. I think that’s happened for a variety of reasons, both personal and professional. Relevance: Most of what I was posting was clearly not going to make any difference to myself or anyone else. Posts that announce [random software] has [random vulnerability] could just as well have been machine generated. The state…
"The very four digits that Amazon considers unimportant enough to display in the clear on the Web are precisely the same ones that Apple considers secure enough to perform identity verification..." Honan wrote. Four digits, when combined with my home address and bank account number were all it took for me to gain on line access to a dormant checking account at my bank and enable fund transfers. If…
An e-mail from a vendor, somewhat anonymized: From: **** Sent: Wednesday, April 11, 2012 08:22 AM To: **** Subject: MumbleWare Case 123456789 Hello ****, Thank you for contacting MumbleWare Product Support. I am writing to you in reference to case number 123456789 regarding your request to change your SA password. In MumbleWare versions 8.2 and below, the SA password must be set to propq. If a…
A couple of days ago myself and a colleague of mine ran into our Apple account exec. The conversation ended up in the security space, as is probably appropriate considering Apples recent performance in that area. Our account exec quickly followed up with a request for our contact information (good), a press-release style announcement on how much more secure Safari 5.1.7 was going to be…
Aaron Smith posted this story about the kindness of an NYC cab driver. It's a good read, and it reminds me of something vaguely similar that happened to be a few decades ago. I had just moved 400 miles from home to a small town in Minnesota near where my grandfathers sister had moved in the 1930's. He didn't get to see her very often, so when I moved near her farm he had an excuse to make the…
I've been hearing 'OS X is secure' for a decade now. For a decade, I've been challenging that assertion. The challenges to that assertion generally end up with a response of 'because it's Unix' or 'because it's not Microsoft'. I don't recall 'OS X is secure' assertions being backed up by detailed explanations of anything in the kernel, operating system, development tools or coding practices that…
...and 5% of all enterprise 'assets' are infected. From Gunter Ollmann , VP of Research at Damballa in this post on CircleID : "...on average, between 3-7% of assets within enterprise networks are identified as being infected..." "Within the ISP/Telco world that have chosen to deploy the Damballa CSP product, between 18-22% of unique subscriber IP addresses are actively seeking to connect to known…
Microsoft press release on their Zeus botnet server seizure: "This disruption was made possible through a successful pleading before the U.S. District Court for the Eastern District of New York, which allowed Microsoft and its partners to conduct a coordinated seizure of command-and-control servers running some of the worst known Zeus botnets." "As a part of the operation, on March 23, Microsoft…
…maybe not. I’m trying out the Collusion plugin for Firefox and the results are interesting. After a couple evenings of my normal surfing routine, the plugin looks like: Yuk. As expected, Google appears at or near the center of attraction. I use the Google suite for anything related to my profession and I use Google’s competition for anything unrelated to my role as an IT professional. My theory…
Oracle Support is upgrading their web interface from Flash to HTML5. I’m happy. I no longer have to twiddle my thumbs waiting for Flash to load: That was really annoying. The consolation prize was that the Flash UI was still two orders of magnitude faster than the call back from support on a Sev 1, so the Flash interface really didn’t affect MTTR. My major complaints about the Flash interface…